johna.kiwi · acm-public-vs-private-ca-walkthrough

ACM and Private CA

Public TLS and private TLS are different jobs. This lab runs both in one VPC: ACM on an ALB for internet trust, AWS Private CA via ACM on an internal ALB for intranet PKI (optional nginx export), and S3 + SSM so a Linux fleet learns your CA without hand-copying PEMs.

Two paths, one trust story

Public · browser trust
Internet any browser
→
ALB + ACM public public subnet · demo.johna.kiwi
→
public-web private subnet · nginx :80
Private · you operate trust (default alb_acm)
Private CA ROOT
→
internal ALB + ACM private subnets · app.internal.johna.kiwi
→
private-web private subnet · nginx :80
Trust distribution · CA PEM only (never the CA key)
CA PEM
→
S3 bucket
→
SSM
→
client-managed TrustCA=intranet · trusts leaf
client-unmanaged no CA · TLS fails (expected)
ALB in public subnets; internal ALB, app, and clients in private subnets (NAT egress). Public path is trusted out of the box. Private path works only after the CA PEM lands in the client trust store via S3 and SSM; the unmanaged client fails on purpose.

What this covers

Complementary, not rivals. Use ACM public for anything the internet must trust. Use Private CA when names and hosts stay inside your estate and you control the trust anchor.

What the lab proves. Public URL works in a default browser. Managed Linux client opens the private URL without --cacert. Unmanaged client gets an untrusted-issuer failure.

What you still own in production. CA lifecycle, renewal automation for private leaves, and a fleet trust channel that matches how you already configure hosts.

Start with Concepts if you want the trust-model split first, or jump to Walkthrough if you already know ACM vs Private CA and want to apply the stack.

Read in this order

Learn — the trust model before you build.

Deploy — stand up the lab and prove both paths.

Operate — run it well, then decide when to use which.

Private CA bills monthly while the CA exists — charged from creation until deletion, so destroy when finished. Public ACM certificates add no charge beyond the AWS resources that use them; ALB and EC2 still cost while running. Detail: Cost.

Prerequisites in brief

  • Terraform >= 1.5, AWS CLI v2, Session Manager plugin
  • Route 53 hosted zone for johna.kiwi (or override hostnames in terraform.tfvars)
  • Region default ap-southeast-2
  • Four Terraform stages under terraform/01-network … 04-trust (not one monolith apply)

Full steps: Walkthrough.


Back to top

Lab repository. Tear down the Private CA when finished — it bills monthly.

ACM + Private CA lab docs