Production PKI/TLS platform
Built a shared certificate platform that replaced direct, service-by-service CA integrations with policy-controlled issuance, renewal, and migration.
Production scope
Kubernetes · internal platforms · databases · legacy infrastructure
My ownership
- Designed the service-facing platform and certificate lifecycle.
- Built Go-based ACME/PKI automation and migration tooling.
- Supported production rollout, operation, and CA migration.
Operating model
Services integrated with internal CAs directly
One shared service-facing platform
Renewal logic varied between environments
Automated renewal before expiry
Access and exceptions required manual coordination
Central policy, audit, observability, and CA routing
Private keys remain on service hosts.
Production effect
Reduced expiry-related incidents and repetitive certificate operations.
Go · step-ca · Vault · Kubernetes · cert-manager · PostgreSQL