MÓDULO CA.Art¶
Certificate orchestration — persona certs + NGFW CA + mTLS to cloud.
Function¶
cert-manager + persona-ca-issuer + sub-CA tlsstress-fleet-ca. Issues
per-persona TLS certs, manages NGFW CA trust + rotation, mints mTLS
client certs for cloud-side authentication (when Cloud Endpoint
Service is active).
Identity¶
| Element | Value |
|---|---|
| Plane | MGMT-light (cloud-portable) |
| Internal code | cert-manager + persona-ca-issuer + tlsstress-fleet-ca |
| K8s namespace | cert-manager + platform |
| OOBI slot | .80 |
Operator controls¶
/admin/ca— issuance status, rotation schedule- BTO (Bidirectional Trust Orchestration) integration — auto cert rotation when CPOS changes IP/VLAN
- Per-DUT NGFW CA pin (operator uploads, CA.Art tracks expiry)
Key telemetry¶
cert_manager_certificates_total{status}— issued / pending / failedcert_expiry_seconds{persona}— time-to-rotationbto_rotations_total— BTO-triggered rotations
Notes¶
CA.Art was added 2026-05-10 as one of the 5 MÓDULOs that completed the original 28. Patent claim #5 references CA.Art interplay with RELAY/GATEWAY/CPOS.
Related¶
- Memory:
discuss_bto_bidirectional_trust_orchestration_2026_05_10 - CPOS primer — IP/VLAN change triggers BTO