Operator · Why goca

It Runs Its Own PKI

Frame 1 of 104

Ask a CA vendor how their own admin console gets its TLS certificate. The honest answers are usually a self-signed certificate you're told to click through forever, or a reverse proxy someone else has to feed.

goca answers by being a CA. At first boot it stands up its own internal hierarchy — goca-infra-rootica-infra — and issues every listener a real certificate before it does anything else. From then on an in-process loop renews and hot-swaps those certificates on its own: no cron job, no restart, no reverse proxy.

You'll watch this happen in First Run, then put your own hierarchy behind the console in Your Own Certificate, right after it.