Cloud & data centres · Platform SRE · Service Mesh · PKI
Make service-mesh certificate rotation measurable before PQC change
Can every workload receive, activate, validate, and retire new trust without hidden static certificates?
Operational pain
Automated issuance creates a false sense of agility when sidecars, batch jobs, appliances, bootstrap credentials, and offline workers escape normal rotation.
Trigger
Mesh migration, CA replacement, certificate outage, or post-quantum transport experiment.
QNSI contribution
Connect the decision to a controlled security path
Inventory workload identities, issuers, algorithms, TTLs, exceptions, and last-observed rotation in QNSI.
Decision artifact
A mesh crypto-agility scorecard with stale identity owners, rotation SLOs, and blocked migration cohorts.
What still requires validation
Platform teams test live rotation, failure modes, time skew, control-plane outage, and cryptographic negotiation.
External problem context
Primary sources
These sources establish the external requirement or risk context. They do not endorse HEOSSI or prove that QNSI completed this scenario.
Evidence boundary
What this page does—and does not—prove
This is a product evaluation pattern, not a customer case study, certification, legal opinion, regulator endorsement, or claim that a production deployment completed the described work.