Habr•October 6, 2026•🇷🇺Translated from Russian

PKI Storm: Managing 100,000 Simultaneous Certificate Requests in Kubernetes Recovery Scenarios

In large enterprises, TLS certificates are required everywhere: for services, workstations, containers, internal APIs, and system integrations. When thousands of consumers exist, PKI must handle massive request flows rather than individual certificates. One organization processed approximately 320 million certificate issuance requests per year.

Automation relied on the ESAUS central management system, which validates requests against security policies and forwards them to external certificate authorities without issuing certificates itself. For Kubernetes with Istio, the Citadel component of ESAUS was configured as the certificate source instead of Istio’s built-in CA. Citadel validates requests and context before passing them through ESAUS to corporate CAs, integrating Kubernetes into the enterprise PKI.

This created a dependency: Kubernetes recovery speed became tied to external CA performance. After a data center outage, dozens of thousands of pods restarted simultaneously. Because services used mTLS, each pod needed its own certificate and private key. In normal operation requests were spread over time, but during recovery roughly 100,000 requests arrived in a short window.

At 70 RPS the theoretical processing time reached almost 24 minutes. Timeouts triggered retries, amplifying load in a thundering herd effect. The infrastructure recovered faster than the CA could issue certificates, revealing that average load figures (10–11 RPS) did not predict burst behavior.

Vertical or horizontal CA scaling was evaluated. Reaching 1,050 RPS would theoretically cut storm time to 1.5 minutes, yet such capacity would remain idle more than 99 % of the time. The team instead decoupled issuance from consumption by pre-generating certificates and keys during normal operation and storing them in a secure reserve.

The reserve resides in the new Unified Secret Storage (ЕХС) layer, which provides centralized protected storage, strict authentication, access controls, auditing, high read throughput, and object lifecycle management. In performance mode, ЕХС delivers up to 14,000 RPS for existing secrets from standby nodes, allowing the burst to be served from reads rather than real-time CA operations.

The approach also addressed Key Recovery Agent (KRA) protection by keeping the KRA private key outside the CA and releasing it only for approved recovery operations. Over time the same storage layer absorbed additional operational secrets beyond the emergency reserve, evolving into a broader corporate secret management platform.

Key lessons include recognizing that average load poorly predicts disaster behavior, that some bottlenecks are better solved by separating production and consumption than by scaling, and that every architectural mitigation transfers complexity rather than eliminating it.

Related articles

AntiMalware•Other

MinTsifry Considers Annual 10 Billion Rubles Support Package for Russian AI Development

Russia's Ministry of Digital Development is discussing a state support package worth up to 10 billion rubles per year aimed at local AI developers. The proposed funding would cover technology development, pilot launches, and compensation for computing resources. According to Kommersant, 8 billion rubles are planned for development and implementation while 2 billion would offset computational costs. Mechanisms under consideration include subsidized loans through authorized banks and grants covering up to 80 percent of pilot project costs in priority sectors. The initiative remains in discussion with no final parameters or launch timelines confirmed yet. Industry experts note that clear selection criteria and transparent reporting will be essential to prevent intermediaries and ensure fair access for independent teams.

AntiMalware•Other

Indid Reports Russian Identity Security Market Reaches 17 Billion Rubles Amid High Incident Rates

According to Indid, the Russian Identity Security market reached 17 billion rubles by the end of 2025. The assessment highlights that organizations continue to allocate significant budgets to access protection while account-related problems persist. Survey data shows that 87.5 percent of companies experienced incidents involving user accounts and access rights during the period. Identity Security solutions focus on managing digital identities, controlling permissions, and preventing unauthorized access across corporate systems. The findings indicate ongoing challenges in maintaining secure access despite growing investments in specialized tools and platforms.

Habr•Other

How a Node.js Bridge Connects MAX and VK Messengers to Chatwoot with Secure Bidirectional Sync

A detailed technical case study describes building a lightweight Node.js service that links the MAX messenger and VK communities to Chatwoot without scraping or using personal accounts. The bridge uses official bot APIs and community callbacks, separate API inboxes, and persistent state stored in a Docker volume to maintain conversation mappings across restarts. Security measures include webhook secret validation, deduplication of events using ring buffers, SSRF protections when handling images, and strict filtering to prevent loops or private notes from leaking externally. The implementation covers contact and conversation creation via Chatwoot Application API, image transfer for VK, and graceful recovery after partial failures. Limitations such as lack of exactly-once delivery and absence of a durable queue are acknowledged, with recommendations for production use including SQLite, retries, and structured logging. The author provides configuration examples, health checks, and a capability matrix showing current support for text and media in each direction.

AntiMalware•Other

NtechLab AI Video Analytics Helps Locate 250 Missing Children in Novosibirsk Region

NtechLab has reported that its generative AI-powered video analytics platform assisted Russian law enforcement in finding 250 missing children in the Novosibirsk region in less than 18 months. The FindFace Multi system operates as part of the Safe City complex and processes live video feeds from cameras installed at transport hubs, streets, squares, and government buildings. Facial recognition capabilities for locating children became available to regional authorities in April 2025. The same technology has also been used to identify more than 3,000 offenders throughout 2025. NtechLab states that its solutions are deployed across more than 70 Russian regions and 34 countries, although the company provided no detailed breakdown of individual cases or average search times. All final decisions and physical searches remain the responsibility of human police officers.