mtls-configuration
wshobson/agents
Configure mutual TLS for zero-trust service-to-service communication with certificate management.
What is mtls-configuration?
This skill provides guidance for implementing mutual TLS (mTLS) to secure service-to-service communication in zero-trust architectures. Use it when setting up certificate-based authentication, managing certificate rotation, or debugging TLS handshake issues in distributed systems.
- Configure mTLS handshake between service proxies with client and server certificate verification
- Establish certificate hierarchy with Root CA, Intermediate CA, and workload certificates
- Implement gradual migration from PERMISSIVE to STRICT mTLS modes
- Set up certificate rotation and expiry monitoring for compliance
- Debug TLS handshake failures and certificate chain validation issues
How to install mtls-configuration
npx skills add https://github.com/wshobson/agents --skill mtls-configurationHow to use mtls-configuration
- 1.Review the certificate hierarchy model (Root CA → Intermediate CA → Workload Certs)
- 2.Start with PERMISSIVE mTLS mode to test without breaking existing traffic
- 3.Configure certificate generation and distribution for each workload
- 4.Set up monitoring and alerts for certificate expiry
- 5.Gradually migrate services to STRICT mode after validation
- 6.Implement automated certificate rotation with short-lived certs (24h or less)
- 7.Enable TLS error logging for audit and debugging
Use cases
- Implementing zero-trust networking across microservices
- Securing multi-cluster service communication
- Meeting compliance requirements (PCI-DSS, HIPAA) for encrypted service communication
- Automating certificate rotation and lifecycle management
- Troubleshooting TLS connection failures between services
- Platform engineers implementing service mesh security
- DevOps engineers managing certificate infrastructure
- Security teams enforcing zero-trust policies
- SREs debugging service-to-service communication issues
mtls-configuration FAQ
PERMISSIVE mode accepts both mTLS and plaintext traffic, allowing gradual migration. STRICT mode enforces mTLS for all connections and rejects plaintext traffic.
Use short-lived certificates (24 hours or less) for workloads to minimize exposure. Plan periodic CA rotation separately based on your security policy.
Yes, use an Intermediate CA at the multi-cluster level to issue cross-cluster certificates that trust each other's Root CA.
Automate certificate rotation and set up alerts well before expiry. Monitor certificate expiry dates continuously and test rotation procedures.
Enable TLS error logging on both client and server proxies, verify the full certificate chain, and check that both sides present valid certificates signed by a trusted CA.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: mtls-configuration description: Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.
mTLS Configuration
Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication.
When to Use This Skill
- Implementing zero-trust networking
- Securing service-to-service communication
- Certificate rotation and management
- Debugging TLS handshake issues
- Compliance requirements (PCI-DSS, HIPAA)
- Multi-cluster secure communication
Core Concepts
1. mTLS Flow
┌─────────┐ ┌─────────┐
│ Service │ │ Service │
│ A │ │ B │
└────┬────┘ └────┬────┘
│ │
┌────┴────┐ TLS Handshake ┌────┴────┐
│ Proxy │◄───────────────────────────►│ Proxy │
│(Sidecar)│ 1. ClientHello │(Sidecar)│
│ │ 2. ServerHello + Cert │ │
│ │ 3. Client Cert │ │
│ │ 4. Verify Both Certs │ │
│ │ 5. Encrypted Channel │ │
└─────────┘ └─────────┘
2. Certificate Hierarchy
Root CA (Self-signed, long-lived)
│
├── Intermediate CA (Cluster-level)
│ │
│ ├── Workload Cert (Service A)
│ └── Workload Cert (Service B)
│
└── Intermediate CA (Multi-cluster)
│
└── Cross-cluster certs
Templates and detailed worked examples
Full template library and detailed worked examples live in references/details.md. Read that file when you need the concrete templates.
Best Practices
Do's
- Start with PERMISSIVE - Migrate gradually to STRICT
- Monitor certificate expiry - Set up alerts
- Use short-lived certs - 24h or less for workloads
- Rotate CA periodically - Plan for CA rotation
- Log TLS errors - For debugging and audit
Don'ts
- Don't disable mTLS - For convenience in production
- Don't ignore cert expiry - Automate rotation
- Don't use self-signed certs - Use proper CA hierarchy
- Don't skip verification - Verify the full chain
Related skills
More from wshobson/agents and the wider catalog.

multi-cloud-architecture
Design multi-cloud architectures across AWS, Azure, GCP, and OCI with decision frameworks and service selection patterns.

multi-reviewer-patterns
Coordinate parallel code reviews across multiple dimensions with deduplication, severity calibration, and consolidated reporting.

nextjs-app-router-patterns
Master Next.js 14+ App Router with Server Components, streaming, and advanced patterns.

nft-standards
Implement ERC-721 and ERC-1155 NFT standards with metadata, minting, royalties, and marketplace integration.

nodejs-backend-patterns
Build production-ready Node.js backends with Express/Fastify, middleware patterns, authentication, and database integration.

nx-workspace-patterns
Configure and optimize Nx monorepo workspaces with production patterns for project boundaries, caching, and affected commands.