mTLS Configuration
Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication.
When to Use This Skill
- Implementing zero-trust networking
- Securing service-to-service communication
- Certificate rotation and management
- Debugging TLS handshake issues
- Compliance requirements (PCI-DSS, HIPAA)
- Multi-cluster secure communication
Core Concepts
1. mTLS Flow
โโโโโโโโโโโ โโโโโโโโโโโ
โ Service โ โ Service โ
โ A โ โ B โ
โโโโโโฌโโโโโ โโโโโโฌโโโโโ
โ โ
โโโโโโดโโโโโ TLS Handshake โโโโโโดโโโโโ
โ Proxy โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโบโ Proxy โ
โ(Sidecar)โ 1. ClientHello โ(Sidecar)โ
โ โ 2. ServerHello + Cert โ โ
โ โ 3. Client Cert โ โ
โ โ 4. Verify Both Certs โ โ
โ โ 5. Encrypted Channel โ โ
โโโโโโโโโโโ โโโโโโโโโโโ
2. Certificate Hierarchy
Root CA (Self-signed, long-lived)
โ
โโโ Intermediate CA (Cluster-level)
โ โ
โ โโโ Workload Cert (Service A)
โ โโโ Workload Cert (Service B)
โ
โโโ Intermediate CA (Multi-cluster)
โ
โโโ Cross-cluster certs
Templates and detailed worked examples
Full template library and detailed worked examples live in references/details.md. Read that file when you need the concrete templates.
Best Practices
Do's
- Start with PERMISSIVE - Migrate gradually to STRICT
- Monitor certificate expiry - Set up alerts
- Use short-lived certs - 24h or less for workloads
- Rotate CA periodically - Plan for CA rotation
- Log TLS errors - For debugging and audit
Don'ts
- Don't disable mTLS - For convenience in production
- Don't ignore cert expiry - Automate rotation
- Don't use self-signed certs - Use proper CA hierarchy
- Don't skip verification - Verify the full chain