All skills
wshobson avatar

/mtls-configuration

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.

Use this Skill: https://skilld.dev/gh/wshobson/agents/mtls-configuration

This session only. Nothing lands on disk.

SKILL.md

โ‰ˆ52 tokens always: the name and description. โ‰ˆ615 when used: this file. โ‰ˆ1.5k more on demand in 1 file.

mTLS Configuration

Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication.

When to Use This Skill

  • Implementing zero-trust networking
  • Securing service-to-service communication
  • Certificate rotation and management
  • Debugging TLS handshake issues
  • Compliance requirements (PCI-DSS, HIPAA)
  • Multi-cluster secure communication

Core Concepts

1. mTLS Flow

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                              โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Service โ”‚                              โ”‚ Service โ”‚
โ”‚    A    โ”‚                              โ”‚    B    โ”‚
โ””โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”˜                              โ””โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”˜
     โ”‚                                        โ”‚
โ”Œโ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”      TLS Handshake          โ”Œโ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”
โ”‚  Proxy  โ”‚โ—„โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บโ”‚  Proxy  โ”‚
โ”‚(Sidecar)โ”‚  1. ClientHello             โ”‚(Sidecar)โ”‚
โ”‚         โ”‚  2. ServerHello + Cert      โ”‚         โ”‚
โ”‚         โ”‚  3. Client Cert             โ”‚         โ”‚
โ”‚         โ”‚  4. Verify Both Certs       โ”‚         โ”‚
โ”‚         โ”‚  5. Encrypted Channel       โ”‚         โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                              โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

2. Certificate Hierarchy

Root CA (Self-signed, long-lived)
    โ”‚
    โ”œโ”€โ”€ Intermediate CA (Cluster-level)
    โ”‚       โ”‚
    โ”‚       โ”œโ”€โ”€ Workload Cert (Service A)
    โ”‚       โ””โ”€โ”€ Workload Cert (Service B)
    โ”‚
    โ””โ”€โ”€ Intermediate CA (Multi-cluster)
            โ”‚
            โ””โ”€โ”€ Cross-cluster certs

Templates and detailed worked examples

Full template library and detailed worked examples live in references/details.md. Read that file when you need the concrete templates.

Best Practices

Do's

  • Start with PERMISSIVE - Migrate gradually to STRICT
  • Monitor certificate expiry - Set up alerts
  • Use short-lived certs - 24h or less for workloads
  • Rotate CA periodically - Plan for CA rotation
  • Log TLS errors - For debugging and audit

Don'ts

  • Don't disable mTLS - For convenience in production
  • Don't ignore cert expiry - Automate rotation
  • Don't use self-signed certs - Use proper CA hierarchy
  • Don't skip verification - Verify the full chain

Source: SKILL.md on GitHub

No alerts16d5 checks ยท Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides configuration templates and documentation for implementing mutual TLS (mTLS) in zero-trust service mesh environments. It contains no executable scripts or dangerous code.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW ยท No issues

  • Runlayer6mo

    1 file scanned ยท No issues

  • ZeroLeaks5mo

    2 findings ยท Score: 80/100

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • Security
  • mtls
  • zero-trust
  • tls
  • certificate-management
  • service-mesh
  • kubernetes
  • networking
  • pki

README badge

README badge for wshobson/agents/mtls-configuration

Configures mutual TLS for zero-trust service-to-service communication using sidecar proxies and certificate hierarchies. Covers TLS handshakes, certificate rotation, multi-cluster setups, and debugging strategies for services behind proxies.

Generated from the current SKILL.md.

Does this skill cover certificate rotation and expiry management?
Yes. It includes monitoring certificate expiry, setting up alerts, and automating rotation with short-lived certs (24h or less for workloads) and periodic CA rotation.
What service mesh platforms does this skill target?
The skill provides general mTLS concepts and best practices applicable across service mesh implementations, with references to sidecar proxy patterns and workload certificates, but does not specify a particular platform like Istio or Linkerd.
Does this include multi-cluster mTLS setup?
Yes. The certificate hierarchy covers multi-cluster intermediate CAs and cross-cluster certificate configuration for securing communication across clusters.
What's the recommended approach for enabling mTLS in existing systems?
The skill recommends starting with PERMISSIVE mode and migrating gradually to STRICT, rather than enabling strict mTLS immediately in production.

Generated from the current SKILL.md. These answers refresh after source changes.