-
Notifications
You must be signed in to change notification settings - Fork 147
Open
Labels
area/controllerarea/mtlsarea/traefikkind/enhancementa new or improved feature.a new or improved feature.
Milestone
Description
Feature Request
Proposal
In order to implement end-to-end encryption between nodes, Maesh should implement an Identity Provider. This IdP will be responsible to issue trusted certificates for proxies to allow mTLS communications The IdP should at least:
- Issue trusted certificates compliant with the SPIFFE spec.
- Provide a Trust Bundle needed to secure communications.
- Attest mesh proxies to only issue certificates for trusted proxies.
To negotiate a certificate, a proxy should also have a sidecar which will implement the negotiation and the renewal routine needed for mTLS communications between nodes.
Those features will be provided as separate commands which will be used by Helm resources.
Metadata
Metadata
Assignees
Labels
area/controllerarea/mtlsarea/traefikkind/enhancementa new or improved feature.a new or improved feature.