Principal/Senior-level cert-manager playbook for certificate lifecycle automation, issuer architecture, trust boundaries, DNS/HTTP challenge strategy, and operating PKI automation on Kubernetes safely.
Use when: designing certificate automation, reviewing issuers and trust, operating cert-manager, or scaling TLS management across clusters and tenants.
Instalação
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Principal/Senior-level cert-manager playbook for certificate lifecycle automation, issuer architecture, trust boundaries, DNS/HTTP challenge strategy, and operating PKI automation on Kubernetes safely.
Use when: designing certificate automation, reviewing issuers and trust, operating cert-manager, or scaling TLS management across clusters and tenants.
cert-manager Mastery (Senior → Principal)
Operate
Start from certificate trust boundaries, issuer ownership, and failure blast radius.
Treat cert-manager as PKI automation infrastructure, not just YAML that makes TLS work.
Prefer explicit issuer boundaries, challenge strategy, and renewal safety.
Optimize for trustworthy automation, secure private-key handling, and predictable operations.
Default Standards
Issuer design must reflect trust and tenancy boundaries.
Renewal and rotation behavior should be tested, not assumed.
DNS and HTTP challenge strategy should match operational ownership.
Secret and key handling require strong discipline.
Shared certificate automation needs governance before scale.