What problem does it solve?
Render and orchestrate PKI lifecycles for Splunk deployments, enabling private or public PKI workflows while ensuring CA private keys are never exposed in artifacts.
Core Features & Use Cases
- Render private PKI (Root + Intermediate) leaves and per-host certificates for Splunk Web, splunkd, S2S, HEC, KV Store EKU, and distribution payloads.
- Render public PKI CSRs and operator handoff artifacts for Vault PKI, ACME/cert-manager, AD CS, EJBCA, or other CAs, with accompanying handoff checklists.
- Support optional surfaces (Edge Processor, LDAPS, SAML SP signing certs, replication TLS, SHC/LM/DS/UF) and delegated rotation runbooks.
- Enforce TLS policy presets, FIPS posture, leaf validity day caps, cluster-wide trust distribution, preflight/verify checks, and CLI trust alignment.
- Supports render-first, dry-run, preflight, apply, rotate, and inventory phases, plus a delegated rotation plan.
Quick Start
Render a private PKI for a 3-indexer cluster and 3 SHC, then install per-host leaves and start the rotation plan.