Skip to content

docs(decisions): add ADR-0005 internal PKI hierarchy - #28

Merged
jmgilman merged 1 commit into
masterfrom
docs/adr-0005-pki-hierarchy
Aug 29, 2026
Merged

docs(decisions): add ADR-0005 internal PKI hierarchy#28
jmgilman merged 1 commit into
masterfrom
docs/adr-0005-pki-hierarchy

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

Records the accepted internal-PKI shape: the existing offline-by-policy KMS root as the single trust anchor, with the Vault PKI and SPIRE upstream intermediates as siblings signed directly by the root, and the root certificate re-minted without a path-length constraint.

Supersedes the linear hierarchy sketched in the GilmanLab/aws root-ca README, which predated the nested-SPIRE topology (chain depth exceeds pathlen:2) and stacked SPIRE under Vault (bootstrap/rebuild cycle). A companion PR in GilmanLab/aws updates that README and the root-cert template.

Validation

moon run docs:build (strict) passes.

@jmgilman
jmgilman merged commit bad64c7 into master Aug 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant