This is why / CD put so much emphasis on tools & strategies to “bring the pain forward”
Envoy – Cindy Sridharan – Medium
Great summary, covering whys, pros / cons, comparisons vs. HAProxy, Nginx, & tradeoffs.
Vault by HashiCorp
Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Vault handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more.
CFSSL - Cloudflare's PKI and TLS toolkit
CloudFlare's PKI/TLS swiss army knife. It is both a command line tool and an HTTP API server for signing, verifying, and bundling TLS certificates.
