01197dd7614cf28d92f937aa59dd1ef33339ee7f
ci / audit (push) Failing after 39s
ED25519 user/host CA keys generated; enableSSHCA on JWK provisioner; 24h root principal cert issued and used to ssh into sectestbed 5104 (passwordless, no static key). Host onboarding = 1 file + reload. Rollout role queued in KNELIAC. Public CA key committed (private keys never leave tsys-ca). https://projects.knownelement.com/issues/385
ca
Docs live on Discourse — this repo is the executable source of truth. Topic: https://community.turnsys.com/t/327 Redmine: https://projects.knownelement.com/issues/697 · Split from KNEL/PFVCluster@041d311 per #769
Fleet CA on tsys-ca: init/issue/selftest, fleet TLS rollout, HTTP artifact mirror (pinned wazuh-agent debs + SHA256SUMS). Roadmap: ACME endpoint, k8s CA integration, SSH certificates. [#697]
Layout
scripts/— rule engine + hooks (seebash scripts/check-rules.sh --fast)- (imported content at repo root, mirroring its PFVCluster path layout)
Provenance
Code imported from KNEL/PFVCluster (041d311); full git history retained in PFVCluster. Enforcement layer copied per ADOPTING.md. IaC consumers: KNEL/KNELIAC references this repo.
Languages
Shell
96.5%
Makefile
3.5%