Certificates as inventory, not as lore.
Wildcard TLS used to live in a folder, a chart, and whoever last renewed it. This repo is the inventory. Infisical is how clusters get the live material. Git never sees a plaintext key.
The problem
A commercial wildcard arrives as a leaf, a chain, and a private key. The leaf and chain are public. The key is not. Baking the key into a Helm chart, checking it into Git, or SSHing it onto a node all work once — then you have three copies, no rotation story, and a git history that never forgets.
The other failure is a secrets UI with no Git trail. Then you cannot rebuild a cluster from the repo, and renewal is tribal knowledge.
The model
One Git repo per set of wildcards. Public certs are committed. Private keys are committed only as SOPS files sealed with GCP KMS. CI on the LAN decrypts, concatenates the chain in the right order, and publishes three values per domain into self-hosted Infisical. Workloads never read Git for TLS. They pull from Infisical.
Git
The inventory. Leaf, CA files, SOPS-wrapped keys. Reviewable diffs when a cert renews.
SOPS + KMS
Decrypt is an IAM grant, not a passphrase. The runner unwraps tls.key; Git never stores it raw.
Infisical
The runtime store. Folders per domain. Secrets Operator and cert-manager consume it.
What gets published
Each wildcard is a folder. Same three names every time, so a consumer cares which domain — not which filename the CA used.
CRT
The standalone leaf. Enough when the client already trusts the public CA.
BUNDLE
Leaf plus intermediates plus root, in chain order. What nginx and Kubernetes TLS want.
KEY
The private key, decrypted in CI, pushed to Infisical, never written back to Git.
Delivery
Merge the public certs and the encrypted key. An ARC runner authenticates to GCP, decrypts with KMS, bakes the bundle, and upserts Infisical over the LAN. Operators already running on the clusters sync the secret into the namespace. Renewal is a Git change, not a Helm chart with a new base64 blob.
Why this shape
SSL management is the project. Infisical is the store it publishes into — the same way this lab uses Zot without calling the registry the product. Git stays auditable. Keys stay sealed. Clusters get a stable CRT / BUNDLE / KEY contract they can pull without caring how the CA packaged the zip.
← Projects