Format:
Export:

Architecture & setup diagrams

PKI — CA HIERARCHY AND AUTOMATED ISSUANCE Root CA — mount pki/ CN=example.com · TTL 87600h (10 y) sign intermediates only — never leaf certs signs CSR Intermediate CA — mount pki_int/ TTL 43800h (5 y) · set-signed does the day-to-day issuing · PKI-001 Role: example-dot-com allowed_domains + allow_subdomains max_ttl 720h — guard-rail for issuance Leaf certificate CN=myapp.example.com · TTL 24h short-lived by design — rotation is normal cert-manager ( PKI-002 / UC-001 · PRE-11 ) ClusterIssuer (Vault type) server: https://openbao…:8200 k8s auth role: cert-manager Certificate CR myapp.example.com renewBefore: … TLS Secret: app-tls tls.crt · tls.key · ca.crt chain: leaf → intermediate → root Route / pod TLS consumes the Secret picked up on renewal issues + renews sign via pki_int role Cross-signing ( PKI-003 ): external corporate root CA signs the CSR of a second intermediate (mount pki_cross/) → OpenBao-issued certs are trusted by clients that only trust the company PKI. Import needs Basic Constraints CA:TRUE — sign with the v3_intermediate_ca extension.

Search test plan

Type at least 2 characters to search

Keyboard shortcuts

P
Go to prerequisites
T
Go to test cases
G
Go to glossary
D
Go to diagrams
J
Next card
K
Previous card
Enter
Open / close focused card
/
Open search
CtrlK
Open search modal
?
Show shortcuts
Esc
Close panel / blur search