logoalt Hacker News

noAnswertoday at 12:39 PM1 replyview on HN

The long-lived credentials life inside a stripped down machine. Cron/lego/Ansible handles the renewal. The machines on the edge can't renew their keys themselves.


Replies

XCSmetoday at 12:45 PM

Oh, this makes sense, so instead of "the app is rotating its keys" is more like "the keys in our app are being rotated by an external service".