Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
This conference talk explores how Shopify automates mutual TLS (mTLS) across thousands of services to implement zero trust architecture at scale. Learn how the Shopify team addresses critical certificate management challenges including rotation without interruption, renewal failures, and cross-cluster distribution. The presenters share their evolution from custom admission controllers to versatile patterns that work across both Kubernetes and non-Kubernetes environments, including techniques for mounting CA certificates at container startup with periodic Cronjob renewals. Discover practical code examples for implementing resilient rotation mechanisms, graceful certificate rollover, and proper RBAC configurations. Gain valuable insights into monitoring certificate lifecycles and troubleshooting common failure modes that will help you scale mTLS in your own environment.