PluginBench
Skill
Review
Audit score 70

mtls-configuration

wshobson/agents

Configure mutual TLS for zero-trust service-to-service communication with certificate management.

What is mtls-configuration?

This skill provides guidance for implementing mutual TLS (mTLS) to secure service-to-service communication in zero-trust architectures. Use it when setting up certificate-based authentication, managing certificate rotation, or debugging TLS handshake issues in distributed systems.

  • Configure mTLS handshake between service proxies with client and server certificate verification
  • Establish certificate hierarchy with Root CA, Intermediate CA, and workload certificates
  • Implement gradual migration from PERMISSIVE to STRICT mTLS modes
  • Set up certificate rotation and expiry monitoring for compliance
  • Debug TLS handshake failures and certificate chain validation issues

How to install mtls-configuration

npx skills add https://github.com/wshobson/agents --skill mtls-configuration
Claude Code
Cursor
Windsurf
Cline

How to use mtls-configuration

  1. 1.Review the certificate hierarchy model (Root CA → Intermediate CA → Workload Certs)
  2. 2.Start with PERMISSIVE mTLS mode to test without breaking existing traffic
  3. 3.Configure certificate generation and distribution for each workload
  4. 4.Set up monitoring and alerts for certificate expiry
  5. 5.Gradually migrate services to STRICT mode after validation
  6. 6.Implement automated certificate rotation with short-lived certs (24h or less)
  7. 7.Enable TLS error logging for audit and debugging

Use cases

Good for
  • Implementing zero-trust networking across microservices
  • Securing multi-cluster service communication
  • Meeting compliance requirements (PCI-DSS, HIPAA) for encrypted service communication
  • Automating certificate rotation and lifecycle management
  • Troubleshooting TLS connection failures between services
Who it's for
  • Platform engineers implementing service mesh security
  • DevOps engineers managing certificate infrastructure
  • Security teams enforcing zero-trust policies
  • SREs debugging service-to-service communication issues

mtls-configuration FAQ

What is the difference between PERMISSIVE and STRICT mTLS modes?

PERMISSIVE mode accepts both mTLS and plaintext traffic, allowing gradual migration. STRICT mode enforces mTLS for all connections and rejects plaintext traffic.

How often should certificates be rotated?

Use short-lived certificates (24 hours or less) for workloads to minimize exposure. Plan periodic CA rotation separately based on your security policy.

Can mTLS work across multiple clusters?

Yes, use an Intermediate CA at the multi-cluster level to issue cross-cluster certificates that trust each other's Root CA.

What should I do if certificate expiry causes service outages?

Automate certificate rotation and set up alerts well before expiry. Monitor certificate expiry dates continuously and test rotation procedures.

How do I debug mTLS handshake failures?

Enable TLS error logging on both client and server proxies, verify the full certificate chain, and check that both sides present valid certificates signed by a trusted CA.

Full instructions (SKILL.md)

Source of truth, from wshobson/agents.


name: mtls-configuration description: Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.

mTLS Configuration

Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication.

When to Use This Skill

  • Implementing zero-trust networking
  • Securing service-to-service communication
  • Certificate rotation and management
  • Debugging TLS handshake issues
  • Compliance requirements (PCI-DSS, HIPAA)
  • Multi-cluster secure communication

Core Concepts

1. mTLS Flow

┌─────────┐                              ┌─────────┐
│ Service │                              │ Service │
│    A    │                              │    B    │
└────┬────┘                              └────┬────┘
     │                                        │
┌────┴────┐      TLS Handshake          ┌────┴────┐
│  Proxy  │◄───────────────────────────►│  Proxy  │
│(Sidecar)│  1. ClientHello             │(Sidecar)│
│         │  2. ServerHello + Cert      │         │
│         │  3. Client Cert             │         │
│         │  4. Verify Both Certs       │         │
│         │  5. Encrypted Channel       │         │
└─────────┘                              └─────────┘

2. Certificate Hierarchy

Root CA (Self-signed, long-lived)
    │
    ├── Intermediate CA (Cluster-level)
    │       │
    │       ├── Workload Cert (Service A)
    │       └── Workload Cert (Service B)
    │
    └── Intermediate CA (Multi-cluster)
            │
            └── Cross-cluster certs

Templates and detailed worked examples

Full template library and detailed worked examples live in references/details.md. Read that file when you need the concrete templates.

Best Practices

Do's

  • Start with PERMISSIVE - Migrate gradually to STRICT
  • Monitor certificate expiry - Set up alerts
  • Use short-lived certs - 24h or less for workloads
  • Rotate CA periodically - Plan for CA rotation
  • Log TLS errors - For debugging and audit

Don'ts

  • Don't disable mTLS - For convenience in production
  • Don't ignore cert expiry - Automate rotation
  • Don't use self-signed certs - Use proper CA hierarchy
  • Don't skip verification - Verify the full chain