mtls-configuration
Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.
npx skills add sickn33/agentic-awesome-skills --skill mtls-configuration --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# mTLS Configuration Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication. ## Do not use this skill when - The task is unrelated to mtls configuration - You need a different domain or tool outside this scope ## Instructions - Clarify goals, constraints, and required inputs. - Apply relevant best practices and validate outcomes. - Provide actionable steps and verification. - If detailed examples are required, open `resources/implementation-playbook.md`. ## Use this skill when - Implementing zero-trust networking - Securing service-to-service communication - Certificate rotation and management - Debugging TLS handshake issues - Compliance requirements (PCI-DSS, HIPAA) - Multi-cluster secure communication ## Core Concepts ### 1. mTLS Flow ``` ┌─────────┐ ┌─────────┐ │ Service │ │ Service │ │ A │ │ B │ └────┬────┘ └────┬────┘ │ │ ┌────┴────┐ TLS Handshake ┌────┴────┐ │ Proxy │◄───────────────────────────►│ Proxy │ │(Sidecar)│ 1. ClientHello │(Sidecar)│ │ │ 2. ServerHello + Cert │ │ │ │ 3. Client Cert │ │ │ │ 4. Verify Both Certs │ │ │ │ 5. Encrypted Channel │ │ └─────────┘ └─────────┘ ``` ### 2. Certificate Hierarchy ``` Root CA (Self-signed, long-li
- Do not use this skill when
- Instructions
- Use this skill when
- Core Concepts
- 1. mTLS Flow
- 2. Certificate Hierarchy
- Templates
- Template 1: Istio mTLS (Strict Mode)
- Template 2: Istio Destination Rule for mTLS
- Template 3: Cert-Manager with Istio
- Template 4: SPIFFE/SPIRE Integration
- Template 5: Linkerd mTLS (Automatic)
- Certificate Rotation
- Debugging mTLS Issues
Istio - Check certificate expiry istioctl proxy-config secret deploy/my-app -o json | \ jq '.dynamicActiveSecrets[0].secret.tlsCertificate.certificateChain.inlineBytes' | \ tr -d '"' | base64 -d | openssl x509 -text -noout # security-allowlist: local certificate inspection Force certificate rotation kubectl rollout restart deployment/my-app Check Linkerd identity linkerd identity -n my-namespace Istio - Check if mTLS is enabled istioctl authn tls-check my-service.my-namespace.svc.cluster.local
What does the mtls-configuration skill do?
Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.
How do I install it?
Run `npx skills add sickn33/agentic-awesome-skills --skill mtls-configuration --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From sickn33/agentic-awesome-skills, a repository with 44,414 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.