managing-certificates-and-encryption

Installation
SKILL.md

Managing Certificates and Encryption

Manages TLS certificate and encryption key lifecycle across all deployment tiers. Before providing procedures, this skill gathers context to determine whether the operator manages certificates directly (Self-Hosted), manages CMEK encryption keys (Advanced/BYOC), or has fully managed encryption (Standard/Basic).

When to Use This Skill

  • Monitoring certificate expiration (Self-Hosted)
  • Performing scheduled certificate rotation (Self-Hosted)
  • Managing CMEK encryption keys (Advanced/BYOC)
  • Responding to key compromise (Self-Hosted, CMEK)
  • Auditing encryption posture for compliance (all tiers)
  • Adding DNS names or IPs to node certificates (Self-Hosted)

For daily health checks: Use reviewing-cluster-health.


Step 1: Gather Context

Related skills

More from cockroachlabs/cockroachdb-skills

Installs
26
GitHub Stars
9
First Seen
Mar 23, 2026