<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tls on Pim Widdershoven</title><link>/tags/tls/</link><description>Recent content in Tls on Pim Widdershoven</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 26 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="/tags/tls/index.xml" rel="self" type="application/rss+xml"/><item><title>Bootstrapping trust in a Kubernetes cluster: cert-manager, an internal CA, and kubelet TLS</title><link>/entry/bootstrapping-trust-in-a-kubernetes-cluster-with-cert-manager/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>/entry/bootstrapping-trust-in-a-kubernetes-cluster-with-cert-manager/</guid><description>A cluster with networking and storage still serves most of its TLS endpoints with self-signed certificates. This post wires up the trust layer: cert-manager with a bootstrapped internal CA, trust-manager to distribute the bundle to every namespace, Let&amp;rsquo;s Encrypt over Gateway API for the public edge, and a CSR approver so the kubelet finally gets a serving cert that something can verify.</description></item></channel></rss>