Mtls Configuration

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.

AI 產生的概覽

指導實作零信任服務間通訊的雙向 TLS,涵蓋憑證、輪換與握手偵錯。

功能
此技能提供設定雙向 TLS(mTLS)以實現零信任服務間通訊的指引。內容說明 mTLS 握手流程、包含根 CA 與中繼 CA 的憑證階層,以及憑證輪換、到期監控與 TLS 錯誤記錄的最佳實務。它會指向一份內含範本與詳細範例的參考檔案。
適用情境
適合在實作零信任網路、保護內部服務間通訊、管理或輪換憑證、偵錯 TLS 握手問題,或滿足 PCI-DSS、HIPAA 等合規要求時使用。
執行需求
沒有指令碼,僅為說明文件。需要閱讀隨附的參考檔案 references/details.md 以取得範本與詳細範例。

mTLS Configuration

Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication.

When to Use This Skill

  • Implementing zero-trust networking
  • Securing service-to-service communication
  • Certificate rotation and management
  • Debugging TLS handshake issues
  • Compliance requirements (PCI-DSS, HIPAA)
  • Multi-cluster secure communication

Core Concepts

1. mTLS Flow

┌─────────┐                              ┌─────────┐│ Service │                              │ Service ││    A    │                              │    B    │└────┬────┘                              └────┬────┘     │                                        │┌────┴────┐      TLS Handshake          ┌────┴────┐│  Proxy  │◄───────────────────────────►│  Proxy  ││(Sidecar)│  1. ClientHello             │(Sidecar)││         │  2. ServerHello + Cert      │         ││         │  3. Client Cert             │         ││         │  4. Verify Both Certs       │         ││         │  5. Encrypted Channel       │         │└─────────┘                              └─────────┘

2. Certificate Hierarchy

Root CA (Self-signed, long-lived)    │    ├── Intermediate CA (Cluster-level)    │       │    │       ├── Workload Cert (Service A)    │       └── Workload Cert (Service B)    │    └── Intermediate CA (Multi-cluster)            │            └── Cross-cluster certs

Templates and detailed worked examples

Full template library and detailed worked examples live in references/details.md. Read that file when you need the concrete templates.

Best Practices

Do's

  • Start with PERMISSIVE - Migrate gradually to STRICT
  • Monitor certificate expiry - Set up alerts
  • Use short-lived certs - 24h or less for workloads
  • Rotate CA periodically - Plan for CA rotation
  • Log TLS errors - For debugging and audit

Don'ts

  • Don't disable mTLS - For convenience in production
  • Don't ignore cert expiry - Automate rotation
  • Don't use self-signed certs - Use proper CA hierarchy
  • Don't skip verification - Verify the full chain

來源與署名

來源:wshobson/agents位於plugins/cloud-infrastructure/skills/mtls-configuration提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架