Consul + CyberArk WIM: External CA for the service mesh
Curated from HashiCorp Blog
Organizations often face friction when adopting service meshes because security teams prefer centralized, auditable PKI over decentralized certificate management. This integration addresses that specific operational gap by allowing Consul to delegate certificate issuance to CyberArk Workload Identity Manager. Instead of maintaining separate trust anchors, you anchor the mesh in the PKI infrastructure your security team already governs. This reduces the cognitive load on platform engineers who no longer need to manage certificate rotation logic within the mesh itself. It also ensures that compliance requirements are met through existing organizational controls rather than creating shadow IT processes. For teams struggling to align infrastructure automation with strict security policies, this approach offers a pragmatic path forward. The key benefit is simplifying trust establishment without sacrificing the granular control required for enterprise environments. Leverage this integration to streamline your mesh deployment while keeping security operations centralized and consistent.
Consul Enterprise 2. 0 lets you use CyberArk Workload Identity Manager as an external CA for the mesh, anchoring trust in PKI your security team already governs.
— HashiCorp Blog