Automate Server and Infrastructure Certificates with Puppet and Dynamic PKI
Eliminate manual certificate management for servers, services, and infrastructure. SecureW2 issues and renews certificates automatically via ACME and SCEP, enforcing enrollment policy at issuance so every certificate is bound to a verified identity before it reaches your infrastructure.
Overview
Automate Device Compliance via Cloud-Native Certificate Lifecycles
SecureW2’s integration with Puppet automates X.509 certificate management for servers and infrastructure, replacing manual processes with policy-driven automation. Certificates are issued via ACME or SCEP from SecureW2’s Dynamic PKI, validated against enrollment policies. Puppet handles infrastructure management, while SecureW2 enforces enrollment, issues certificates, tracks lifecycle, and renews them automatically. This coordination ensures certificates are issued only to verified workloads, never expired silently, or manually renewed, bridging infrastructure automation and certificate management.
Use Cases
Workload Identity and mTLS Between Services
Server Certificate Automation via ACME
How It Works
From Certificate Request to Automated Lifecycle
Certificate Issuance Flow ACME
SecureW2’s ACME endpoints automate certificate issuance for servers and workloads using External Account Binding to ensure only authorized systems can enroll. Certificates are issued, renewed, and suspended automatically or by admin decision through any ACME-compatible client, eliminating manual provisioning for dev and IT teams without requiring custom tooling.
REST API Certificate Enrollment
SecureW2’s REST APIs give automation tooling full programmatic control over certificate enrollment for non-human identity servers, IoT devices, and containers, with certificate types and lifespans configurable per workload or team through policy. Enrollment is triggered directly by the pipeline at deployment time, so certificate issuance becomes a step in the automation process rather than a separate manual workflow.
Deployment & Architecture Detail
Workload Identity and mTLS Between Services
Service-to-service communication in microservice environments needs verifiable identity, not just network trust. Mutual TLS (mTLS) demands both client and server present certificates from a trusted CA before data exchange. SecureW2 acts as this CA, issuing certificates with verified workload identities. During connection, services verify certificates against the SecureW2 root. If a certificate is expired, revoked, or untrusted, the handshake rejects the connection automatically.
Server Certificate Automation via ACME
Manual certificate management—tracking expiry, submitting CSRs, and installing certificates manually—causes operational risk, with certificates expiring unexpectedly, audit issues, and emergency maintenance. ACME automates issuance and renewal directly from infrastructure. SecureW2 is the ACME authority; servers request certificates via their ACME client (cert-manager, acme.sh, Certbot, native tools) pointing to SecureW2. Requests are validated against enrollment policies before signing, with certificates issued containing the validated server identity in the SAN and automatically renewed before expiry. Policy controls include allowed domains, SANs, key types, sizes, maximum lifetime, and requester verification; any non-compliant request is rejected.
Frequently Asked Questions
Puppet Integration — Common Questions
Does SecureW2 replace Puppet's existing PKI or work alongside it?
What ACME clients are compatible with the SecureW2 ACME endpoint?
How are certificate renewal attempts handled if the renewal policy check fails?
Can SecureW2 issue certificates for internal hostnames and private IPs?
Does this integration support short-lived certificates for workload identity?
What certificate attributes can be embedded in issued certificates?
How does certificate revocation work for server and service certificates?
How is Puppet configured to request certificates from SecureW2?
Ready to Connect Puppet to SecureW2?
Connect with our integration specialists to implement this solution in your environment and transform your security posture.