<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Certificate Management - Tag - Shengxu · Cloud Architecture &amp; DevOps</title><link>https://shengxu.pages.dev/en/tags/certificate-management/</link><description>Cloud architecture &amp; DevOps notes by Shengxu: Kubernetes, Cilium, observability, LLM infra, AI agents.</description><generator>Hugo 0.153.2 &amp; FixIt v0.4.0-alpha.3-20251225101113-8ffb9a95</generator><language>en</language><lastBuildDate>Sat, 03 Jan 2026 19:00:00 +0800</lastBuildDate><atom:link href="https://shengxu.pages.dev/en/tags/certificate-management/index.xml" rel="self" type="application/rss+xml"/><item><title>Kubernetes 1.34/1.35 Certificate Revolution: From Manual Hell to Zero-Trust Heaven</title><link>https://shengxu.pages.dev/en/posts/kubernetes-1-34-1-35-certificates/</link><pubDate>Sat, 03 Jan 2026 19:00:00 +0800</pubDate><guid>https://shengxu.pages.dev/en/posts/kubernetes-1-34-1-35-certificates/</guid><category domain="https://shengxu.pages.dev/en/categories/kubernetes/">Kubernetes</category><category domain="https://shengxu.pages.dev/en/categories/cloud/">Cloud</category><category domain="https://shengxu.pages.dev/en/categories/security/">Security</category><description>&lt;p&gt;Recently upgraded to 1.35 and discovered that &lt;strong&gt;certificate management&lt;/strong&gt; changes are nothing short of revolutionary—especially for self-managed K8s users, where operational overhead has been cut in half.&lt;/p&gt;
&lt;p&gt;In the past, certificate issues were the &amp;ldquo;silent killer&amp;rdquo; of security incidents: expired certificates causing outages, token leaks, and manual rotation consuming 30% of ops time. Versions 1.34/1.35 introduce &lt;strong&gt;native automated mTLS&lt;/strong&gt;, making zero trust no longer exclusive to Istio. Today, let&amp;rsquo;s dive into these new features and compare them in a &lt;strong&gt;self-managed K8s vs. cloud K8s&lt;/strong&gt; hands-on scenario.&lt;/p&gt;</description></item></channel></rss>