Consul + CyberArk WIM: External CA for the service mesh
Every service in a Consul service mesh gets a short-lived TLS certificate that proves its identity. By default, Consul runs its own certificate authority to issue those certificates. That is convenient, but it also means the trust anchor for your entire mesh lives inside Consul rather than inside the PKI your security team already operates and audits. Consul Enterprise already supports Vault and AWS Certificate Manager as external certificate authorities (CAs) for Connect, its service mesh. Org

