Skip to main content

Integrations

The Integrations screen is where you turn on the ways certificates reach your workloads and servers: ACME, SPIFFE, NGINX, Apache, Java keystores, HashiCorp Vault, Kubernetes CSR, Microsoft ADCS, EST and Sectigo SCM.

ConsoleIntegrations

What it's for​

You configure desired state in the console: whether an integration is enabled, which Mesh Nodes run it, which profile it uses and which local adapter configuration it points to. An authenticated Mesh Node then validates and applies that state over its outbound channel and reports health back.

Secrets never go into the console. Passwords, tokens and private keys stay on the Mesh Node, in its local credential store or private files. The console stores only a non-secret adapter reference such as local/nginx-production.

What you see​

Integrations screen with a grid of cards for ACME, SPIFFE, NGINX, Apache, Java, Vault, Kubernetes CSR, ADCS, EST and Sectigo SCM, each with a status and Configure and Test actions
Integration cards.

Each card shows the integration name, a one-line description, its status, any last error, where it runs and its revision, plus Configure and (when enabled) Test.

IntegrationCard descriptionRuns onGuide
ACMELocal workload certificate lifecycleMesh NodeACME
SPIFFE identitiesmTLS workload identity bindingMesh NodeSPIFFE / SPIRE
NGINXAtomic TLS deployment, exact-cert health, and rollbackLinux Mesh NodeNGINX
Apache HTTP ServerGraceful TLS rotation, exact-cert health, and rollbackLinux Mesh NodeApache
Java PKCS#12 keystoreAtomic PKCS#12 delivery, application reload, and rollbackMesh NodeJava PKCS#12
HashiCorp Vault KV v2KV v2 delivery with CAS, health check, and rollbackMesh NodeHashiCorp Vault
Kubernetes CSRNative cluster issuance adapterMesh NodeKubernetes CSR
Microsoft ADCSCompatibility and migration adapterWindows Mesh NodeMicrosoft ADCS
ESTDevice enrollment adapterMesh NodeEST
Sectigo SCMManaged CA and protected signingCloudSectigo SCM

Card status​

StatusMeaning
HealthyThe exact current revision was applied and checked.
Awaiting nodeDesired state or a test is waiting for the assigned Mesh Node to acknowledge it.
DegradedThe node rejected the configuration or could not operate the adapter. The card shows the error, for example adapter not configured.
DisabledNot enabled. No authority or workload path is active.

Card details​

The left side of the footer shows where the integration runs:

TextMeaning
Not activeThe integration is disabled.
CloudSectigo SCM, which runs in the cloud rather than on a node.
No node assignedEnabled, but no target node is selected.
n target(s)Number of target Mesh Nodes.

Revision increases every time desired state changes or a test is requested.

Configure an integration​

Configure NGINX dialog with the enable checkbox, target Mesh Nodes, certificate profile, local adapter reference and the configure the local server first guidance
Configuring NGINX.
  1. On the integration's card, select Configure. The Configure dialog opens with INTEGRATION DESIRED STATE and a status of Configured or Not configured.
  2. Under Activation and targets, select Enable this integration. Desired state is reconciled by an authenticated Mesh Node and fails closed until acknowledged.
  3. Under Target Mesh Nodes, select the nodes allowed to run it (not shown for Sectigo SCM).
  4. Under Profile and adapter, enter the Certificate / identity profile, for example prod-service.
  5. Enter or check the Local adapter reference (not shown for Sectigo SCM).
  6. For Sectigo SCM, choose the Active SCM connector. For Microsoft ADCS, choose the ADCS public CA chain.
  7. Read the guidance at the bottom of the dialog and complete any local preparation first.
  8. Select Save desired state.

The console confirms Configuration saved. The assigned Mesh Node will reconcile it over its outbound channel. The card shows Awaiting node until the node acknowledges, then Healthy or Degraded.

To turn an integration off, clear Enable this integration and save. The console confirms Integration disabled and desired state updated.

Dialog fields​

FieldShown forNotes
Enable this integrationAll
Target Mesh NodesAll except Sectigo SCMNGINX and Apache require a Linux or container node; other nodes are disabled with requires Linux.
Certificate / identity profileAllAt least two characters.
Active SCM connectorSectigo SCMLists your active SCM CA connectors. See CAs & signing.
Local adapter referenceAll except Sectigo SCMFixed (read-only) for ACME and SPIFFE. Required when enabling Kubernetes CSR, Microsoft ADCS, EST, NGINX, Apache, Java keystore or HashiCorp Vault.
ADCS public CA chainMicrosoft ADCSLists your active bring-your-own CA connectors. The cloud uses this public chain to verify every certificate returned by the Windows node. ADCS credentials stay local.

Default adapter references​

When an integration has no adapter reference yet, the dialog suggests one. It must match a configuration on the Mesh Node.

IntegrationDefault reference
Kubernetes CSRlocal/kubernetes-incluster
Microsoft ADCSlocal/adcs-production
ESTlocal/est-builtin
NGINXlocal/nginx-production
Apache HTTP Serverlocal/apache-production
Java PKCS#12 keystorelocal/java-production
HashiCorp Vault KV v2local/vault-production

Local preparation shown in the dialog​

IntegrationGuidance headingWhat to do first
NGINXConfigure the local server firstAdd the managed include, pin the NGINX executable digest, and import the currently serving key pair.
Apache HTTP ServerConfigure the local server firstInclude the managed TLS snippet in the target virtual host, pin the httpd executable digest, and import the currently serving key pair.
Java PKCS#12 keystorePrepare the local Java runtimePin JDK keytool and the reload executable, create a restricted high-entropy password file, import the serving key pair, and point the application at the managed PKCS#12 path.
HashiCorp Vault KV v2Prepare the local Vault accessStore a narrowly scoped Vault token in a restricted file on the node, enable a KV v2 mount, and grant write access only to the configured base path.
ACMECreate a node-bound external accountGenerate a distinct short-lived EAB credential and ACME account for every named primary or failover node. Never send account traffic through random load balancing.
Microsoft ADCSCA-signed revocation distributionThe Windows node publishes and retrieves each CRL through native ADCS administration APIs.
Configure HashiCorp Vault KV v2 dialog with enablement, target nodes, profile, local adapter reference and the prepare the local Vault access guidance
Configuring HashiCorp Vault KV v2. Vault connection details live on the Mesh Node, not in the console.

Test an integration​

Test appears on enabled integrations. It asks the assigned Mesh Node (or, for Sectigo SCM, the cloud service) to check the integration end to end and report the result.

  1. On an enabled card, select Test.
  2. Read the message that appears.
MessageMeaning
Test queued. The Mesh Node will report the adapter result over its authenticated outbound channel.Node-hosted integrations. The card shows Awaiting node and then the result.
Integration test passed.Sectigo SCM connectivity was verified.
Test recorded, but connectivity was not verified (error code).Sectigo SCM could not be reached or is misconfigured. The error code, if any, is shown in parentheses. Check the connector on CAs & signing.

You can open an integration's configuration directly with the configure query parameter, for example ?view=integrations&configure=nginx. Configure SCM integration in CAs & signing uses the same mechanism.

Permissions​

ActionRoles
View integrationsEvery role
Configure or test node-hosted integrationsPKI Operator, Tenant Admin. Requires MFA within the last ten minutes.
Configure or test Sectigo SCMTenant Admin. Requires MFA within the last ten minutes.

Troubleshooting​

SymptomCause and fix
Save desired state is greyed outThe profile is shorter than two characters; or the integration is enabled but has no target node; or (SCM) no connector is selected; or (ADCS) no CA chain is selected; or a required adapter reference is empty.
A node is greyed out with requires LinuxNGINX and Apache run only on Linux or Linux-container nodes.
Active SCM connector has no optionsNo SCM connector is active. Connect one on CAs & signing, and make sure its enrollment IDs are complete.
Card stays Awaiting nodeThe target node has not picked up the new revision. Check that it is healthy on Mesh nodes.
Card is Degraded with an errorThe node could not apply the configuration. Check the adapter reference matches the node's local configuration and follow the integration guide.
An error appears in the dialog when savingThe message comes from the service. A common cause is MFA older than ten minutes.