This is very much a WIP and should not be relied upon whatsoever right now.
- generate the certificates necessary for mtls
- do so by running
build-a-pki.shand moving the output artifacts into a directory calledservice_name_mtlswhereservice_nameis the name of the service thats serving routes. That is if you have a binary serving multiple service controllers, your binary has a single service name and you would useservice_name_mtlsfor your service and when deployed it would look up its service certificates in the expected place on the deployed instance.
- do so by running
export CA_CERT_BUNDLE=/etc/ssl/certs/ca-bundle.crtexport CERTIFICATE_ROOT=$(pwd)