autonomy cert

Manage TLS leaf certificates for edge node identity

Synopsis

Manage TLS leaf certificates for edge node mTLS identity.

Certificates are issued and rotated using the local CA private key.
Only leaf certificates are managed; CA certificates are offline roots.

Lifecycle events (slog):
  edge.cert.rotation_started
  edge.cert.rotation_succeeded
  edge.cert.rotation_failed

Audit trail: certificate issue and rotate also emit unified audit records.

Options inherited from parent commands

      --require-signed-manifest   Refuse to start if the SHA256SUMS release manifest or its cosign signature is missing/invalid (Tier 2 binary-integrity check; default: build-time compile-in via -ldflags -X, build-hardened artifacts=true, all others=false)

Subcommands