- TLS replaced SSL (SSL is technically dead but the name persists)
- TLS 1.2 is the current minimum; TLS 1.3 is preferred
- Handshake: client hello → server hello + cert → key exchange → encrypted communication
- Certificates — chain of trust from your cert up to a root CA. Browsers and OSes ship with trusted root CAs.
- Let's Encrypt — free, automated CA via ACME protocol. Standard for modern deployments.
- cert-manager (Kubernetes) — automates Let's Encrypt cert provisioning in K8s