Ssl Certificate Management

aj-geddes/useful-ai-prompts/skills/ssl-certificate-management

作者 aj-geddes3f5182cfd739無授權條款355 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 個月前更新

Manage SSL/TLS certificates with automated provisioning, renewal, and monitoring using Let's Encrypt, ACM, or Vault.

AI 產生的概覽

指導跨基礎架構的 SSL/TLS 憑證自動簽發、續期、監控與安全分發。

功能
提供參考指南與入門設定,用於管理 SSL/TLS 憑證,涵蓋 cert-manager 搭配 Let's Encrypt、AWS ACM、自動續期、監控以及憑證釘選。內含 YAML 設定範本與一支用於檢查設定的驗證指令碼。內容屬於指導性文件,而非可執行的憑證管理工具。
適用情境
適用於啟用 HTTPS/TLS、自動化憑證續期、管理多網域或萬用字元憑證、監控到期情形,或規劃零停機輪換與內部 PKI 的情境。
執行需求
需要能讀取參考文件與範本的代理;隨附的 shell 指令碼需要 shell 環境。依指南操作需具備 cert-manager、Let's Encrypt、AWS ACM 或 Vault 等憑證工具,以及對應的雲端或 DNS 認證資訊與網路存取。

SSL Certificate Management

Table of Contents

Overview

Implement automated SSL/TLS certificate management across infrastructure, including provisioning, renewal, monitoring, and secure distribution to services.

When to Use

  • HTTPS/TLS enablement
  • Certificate renewal automation
  • Multi-domain certificate management
  • Wildcard certificate handling
  • Certificate monitoring and alerts
  • Zero-downtime certificate rotation
  • Internal PKI management

Quick Start

Minimal working example:

yaml
# cert-manager-setup.yamlapiVersion: cert-manager.io/v1kind: ClusterIssuermetadata:  name: letsencrypt-prodspec:  acme:    server: https://acme-v02.api.letsencrypt.org/directory    email: [email protected]    privateKeySecretRef:      name: letsencrypt-prod    solvers:      # HTTP-01 solver for standard domains      - http01:          ingress:            class: nginx        selector:          dnsNames:            - "myapp.com"            - "www.myapp.com"
      # DNS-01 solver for wildcard domains      - dns01:          route53:            region: us-east-1// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
Let's Encrypt with Cert-Manager [blocked]Let's Encrypt with Cert-Manager
AWS ACM Certificate Management [blocked]AWS ACM Certificate Management
Certificate Monitoring and Renewal [blocked]Certificate Monitoring and Renewal
Automated Certificate Renewal [blocked]Automated Certificate Renewal
Certificate Pinning [blocked]Certificate Pinning

Best Practices

✅ DO

  • Automate certificate renewal
  • Use Let's Encrypt for public certs
  • Monitor certificate expiration
  • Use wildcard certs strategically
  • Implement certificate pinning
  • Rotate certificates regularly
  • Store keys securely
  • Use strong key sizes (2048+ RSA, 256+ ECDSA)

❌ DON'T

  • Manual certificate management
  • Self-signed certs in production
  • Share private keys
  • Ignore expiration warnings
  • Use weak key sizes
  • Mix dev and prod certs
  • Commit certs to git
  • Disable certificate validation

來源與署名

來源:aj-geddes/useful-ai-prompts位於skills/ssl-certificate-management提交3f5182c

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架