The ESP32-S3 example generates the device key on the chip and sends only a CSR to AWS IoT Core. The credential that gets it there is a claim certificate and private key copied into the SPIFFS image every unit shares.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+22
- Incentives30
- Confidence55
The v1.37 GA puts X.509 delivery and refresh inside Kubelet, but the authority that actually signs those certificates is still integration work, which is why no adjacent tooling comes out of the plan this quarter.
Reality
- Evidence60
- Adoption20
- Hype gap+18
- Incentives62
- Confidence55
KEP-3257 adds a ClusterTrustBundle object and a kubelet projected volume source, which lets a signer publish its roots without running a controller that holds create-ConfigMap permission in every namespace.
Publishers:kubernetes.dev
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence62
KEP-4317 pairs a pod-scoped certificate request with a projected volume, so the kubelet provisions the key and kube-apiserver enforces node restriction. What is left for a signer to do is the CA work.
Publishers:kubernetes.dev
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence55
A public proof-of-concept for CVE-2026-54121 shows an Enterprise CA vouching for a forged Domain Controller identity. Microsoft's July 14 fix adds a missing check, not judgement.
Reality
- Evidence42
- Adoption22
- Hype gap+24
- Incentives78
- Confidence46