Skip to main content

service-mesh-mtls-rollout

Plan and execute progressive service-mesh mTLS rollouts on owned clusters: baseline inventory, PERMISSIVE then STRICT, canary namespaces, DestinationRule / peer policy alignment, plaintext exception budgets, and evidence-based cutover. Use when enabling mesh mTLS (Istio PeerAuthentication, Linkerd automatic mTLS, Consul Connect, similar), migrating east-west from plaintext to mutual TLS, debugging mode mismatch 503s, or staging STRICT without breaking legacy clients — not for AuthorizationPolicy design, L3 NetworkPolicy, or non-mesh app client-cert design alone.

Jump to install

Source facts

Repository
tomysh1337/openstarry-code
Last source activity
August 17, 2026 at 13:35
Detected SKILL.md language
English
Stars
3
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.