mrcharles af7c0f3478 feat: port legacy TSYS-CA (admin-code PKI + tsys-bits) [#769][#783]
Excluded admin-code/*SECRETS.inc (real Nitrokey HSM PINs in the public
source repo) — SECRETS.inc.example template added in their place.
Rotation/history-purge ruling pending in #783. legacy-* trees exempt
from lint/pointer checks (historical verbatim code).

https://projects.knownelement.com/issues/769#note-4152
2026-09-04 07:01:46 -05:00

ca

Docs live on Discourse — this repo is the executable source of truth. Topic: https://community.turnsys.com/t/327 Redmine: https://projects.knownelement.com/issues/697 · Split from KNEL/PFVCluster@041d311 per #769

Fleet CA on tsys-ca: init/issue/selftest, fleet TLS rollout, HTTP artifact mirror (pinned wazuh-agent debs + SHA256SUMS). Roadmap: ACME endpoint, k8s CA integration, SSH certificates. [#697]

Layout

  • scripts/ — rule engine + hooks (see bash scripts/check-rules.sh --fast)
  • (imported content at repo root, mirroring its PFVCluster path layout)

Provenance

Code imported from KNEL/PFVCluster (041d311); full git history retained in PFVCluster. Enforcement layer copied per ADOPTING.md. IaC consumers: KNEL/KNELIAC references this repo.

S
Description
Fleet CA: tsys-ca issuance, fleet TLS, artifact mirror; ACME + SSH-cert roadmap [#697]
Readme AGPL-3.0
27 MiB
Languages
Shell 96.5%
Makefile 3.5%