Skip to content
Back to skills

Cert Tls

ASecurity

Expert knowledge for TLS/SSL operations. Use when configuring certificates, debugging cert-manager, or managing Ingress TLS.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
code-qualitybashkubernetesdebuggingapibackend

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill cert-tls --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cert Tls?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cert Tls
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-cert-tls/badge)](https://www.skillsdirectory.com/skills/david-li0406-cert-tls)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cert-tls
description: Expert knowledge for TLS/SSL operations. Use when configuring certificates, debugging cert-manager, or managing Ingress TLS.
allowed-tools: Bash, Read, Grep, Glob, Edit, Write
---

# TLS & Certificate Operations

## Architecture
- **Issuer**: Let's Encrypt (Production & Staging)
- **Challenge**: DNS-01 via Cloudflare API
- **Domain**: `*.lab.mtgibbs.dev` (Wildcard)

## Configuration

### Components
- **Namespace**: `cert-manager`
- **ClusterIssuers**: `letsencrypt-prod`, `letsencrypt-staging`
- **Secret**: `cloudflare-api-token` (Synced from 1Password)

### Cloudflare Setup
- **Token Permissions**: Zone:DNS:Edit
- **Zone Resources**: Include `mtgibbs.dev`
- **DNS Record**: A record `*.lab` -> `192.168.1.55` (Proxy OFF/Grey Cloud)

### Ingress Annotations
For internal HTTPS services (like Unifi) that need re-encryption:
```yaml
annotations:
  nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
  nginx.ingress.kubernetes.io/proxy-ssl-verify: "false"
```

## Troubleshooting

### Debug Flow
1. **Check Certificate Resource**:
   ```bash
   kubectl get certificate -n <namespace>
   kubectl describe certificate <name> -n <namespace>
   ```
   Look for "Ready" status or error messages.

2. **Check Challenge**:
   ```bash
   kubectl get challengerequest -A
   ```

3. **Check Cert-Manager Logs**:
   ```bash
   kubectl logs -n cert-manager -l app=cert-manager
   ```

### Common Issues
- **"403 Forbidden"**: Cloudflare API token has wrong permissions.
- **"Waiting for DNS propagation"**: Normal, but if stuck >10m, check Cloudflare logs.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…