Certificates, TLS and DNS

This guide covers what a new Axual Platform installation needs before the first chart runs: the DNS names to register, the certificates an installation needs and where each ends up, the Kubernetes Secret formats the charts read, and how to point a component at its Secrets.

Type

Reference

Goal

Find the DNS name or certificate page you need while planning or preparing an installation.

Audience

Platform Operators and infrastructure engineers who register DNS names, request certificates, create Secrets, or configure a component’s TLS settings.

When to use

Start here at the beginning of an installation, once the infrastructure requirements are agreed.

Every connection between Axual components is authenticated with mutual TLS, so certificates are a prerequisite rather than a hardening step. Nothing starts without them, which is why this group sits early in the installation flow. DNS is part of the same prerequisite: a certificate is issued for the hostname a client resolves, so the DNS names below have to exist before the matching certificate does.

The pages here cover platform TLS and DNS only. Certificate rotation, replacing the root Certificate Authority, and reading a certificate back off a running platform are recurring maintenance rather than installation work, and live in Certificate Management instead. Credentials a connector uses to reach a third-party system are a separate subject too, held in the Connector Vault and documented under How to Set Up the Connector Vault for Kafka Connect.

Contents

The sections below group the pages by the job they serve:

Plan and understand

Work through these before requesting a single certificate. The inventory tells the infrastructure team what to register and issue, and the explanation makes clear which of the four stores each certificate ends up in.

  • DNS and Certificate Inventory Reference lists the DNS names each exposed component needs, the two certificate authorities the platform expects, and the certificates to request from each.

  • Mutual TLS in Axual Platform explains why every connection is authenticated in both directions, and what each keystore and truststore is responsible for.

Prepare and configure

These three pages take the inventory from a plan to a running component, in order.

The Axual Keystore Provider init container is what turns those Secrets into the keystore and truststore files a component reads at startup.

  • Certificate Management covers reading, rotating and replacing a certificate once the platform is running.

  • Troubleshooting covers what to check when a component fails to start or a connection is refused.