Rootconf 2019

Rootconf 2019

On infrastructure security, DevOps and distributed systems.

Tickets

Loading…

Tasdik Rahman

@tasdikrahmangojek

Kingsly - The Cert Manager

Submitted Jun 8, 2019

Problem Statement

Manage SSL/TLS certificate lifecycle for various backends which would include but not limited to

  • IPSec VPNs
  • HAProxy/envoy proxy

Existing Solutions

Generate certs using openssl(error prone) or use managed solution(expensive)

Solution

  • We built kingsly, which would act as broker between clients and letsencrypt, serving the clients with SSL certs.
  • It takes care of renewal of certs before their expiry dates.
  • extensible by writing custom clients to automate the whole manual process of updating certs with an example client.

Outline

Will go over the problem statement of how managing certs was a difficult problem for us and then how we went ahead solving it using kingsly.

Speaker bio

Product Engineer @ Gojek, Contributor to @oVirt, Backpacker, Weekend chef, theatre enthusiast.

Comments

{{ gettext('Login to leave a comment') }}

{{ gettext('Post a comment…') }}
{{ gettext('New comment') }}
{{ formTitle }}

{{ errorMsg }}

{{ gettext('No comments posted yet') }}

Hybrid access (members only)

Hosted by

We care about site reliability, cloud costs, security and data privacy