johna.kiwi · acm-public-vs-private-ca-walkthrough
ACM and Private CA
Public TLS and private TLS are different jobs. This lab runs both in one VPC: ACM on an ALB for internet trust, AWS Private CA via ACM on an internal ALB for intranet PKI (optional nginx export), and S3 + SSM so a Linux fleet learns your CA without hand-copying PEMs.
Two paths, one trust story
Browsers already trust Amazon’s public CA. Terminate HTTPS on the load balancer; the backend stays HTTP.
PrivateSame ALB pattern as public. Clients trust it only after the CA PEM is in the system store.
TrustPublish the CA PEM once. State Manager installs it on tagged hosts; unmanaged clients fail on purpose.
What this covers
Complementary, not rivals. Use ACM public for anything the internet must trust. Use Private CA when names and hosts stay inside your estate and you control the trust anchor.
What the lab proves. Public URL works in a default browser. Managed Linux client
opens the private URL without --cacert. Unmanaged client gets an untrusted-issuer failure.
What you still own in production. CA lifecycle, renewal automation for private leaves, and a fleet trust channel that matches how you already configure hosts.
Start with Concepts if you want the trust-model split first, or jump to Walkthrough if you already know ACM vs Private CA and want to apply the stack.
Read in this order
Learn — the trust model before you build.
Deploy — stand up the lab and prove both paths.
Operate — run it well, then decide when to use which.
Private CA bills monthly while the CA exists — charged from creation until deletion, so destroy when finished. Public ACM certificates add no charge beyond the AWS resources that use them; ALB and EC2 still cost while running. Detail: Cost.
Prerequisites in brief
- Terraform >= 1.5, AWS CLI v2, Session Manager plugin
- Route 53 hosted zone for
johna.kiwi(or override hostnames interraform.tfvars) - Region default
ap-southeast-2 - Four Terraform stages under
terraform/01-network…04-trust(not one monolith apply)
Full steps: Walkthrough.