Secrets and Certificates
This guide lists the pages for the sensitive material Axual components hold: the credentials they read from a Kubernetes Secret instead of the values file, and the TLS certificates of a running platform.
Type |
Reference |
Goal |
Find the page for keeping credentials out of the values file, or for maintaining the platform’s certificates. |
Audience |
Platform Operators who manage the Secrets and certificates of an Axual installation. |
When to use |
When preparing the values file for a new installation, when a security review flags credentials in Git, or when a certificate needs reading or replacing. |
Pages in this section
The pages in this section cover credentials first, then certificates:
-
How to Store Component Credentials in a Kubernetes Secret moves the credentials of Platform Manager, API Gateway, Metrics Exposer, Rest Proxy and the Apicurio Registry Auth Proxy out of the values file, for a new installation or an existing one.
-
Certificate Management covers inspecting, rotating and replacing the certificates of a running platform.
Getting certificates in place before a first installation is a separate step, covered in Certificates, TLS and DNS.