Events/CND 2025
Gold sponsor·Hands-on workshop
Metaminds at
CND 2025.
The second edition of Cloud Native Days Romania, and the first with a dedicated workshop day. We were there as Gold sponsor — and on the workshop day, running ninety minutes on the least glamorous thing that quietly takes clusters down: certificates.
Why we were there
CND Romania 2025 was the second edition — the event that grew out of Kubernetes Community Days Romania and, that year, added a full workshop day in front of the conference. Two days, three parallel tracks, and a room full of people who run Kubernetes in production rather than read about it.
We came in as Gold sponsor. Almost every platform we design and operate runs on software this community writes and maintains, so backing the event that brings it together in Bucharest is the least we can do.
But a logo on a banner is not participation. Sponsoring meant showing up with engineers and something they had actually debugged at 3 a.m. — which is how two of our platform people ended up teaching a 90-minute workshop on the first day.
The workshop
Escape from Certificate Hell.
Managing trust in your Kubernetes cluster.
Vlad Mocanu and Răzvan Vâlceanu on the part of a platform nobody owns until it breaks — and on how to hand it over to software. Ninety minutes, laptops open, one cluster per participant. Vlad is also a volunteer in the Cloud Native Days Bucharest organising team — so for two days he was both running a room and helping run the event.

What we covered
The boring thing
that breaks everything.
Every service in a cluster talks to every other service over an encrypted connection, and every one of those connections depends on a certificate that eventually expires. Most of them are created once, by hand, and then forgotten — until one of them runs out on a Saturday and takes something important down with it. The workshop was about handing that job to software instead.
- 01What problem we are actually solvingWhy a cluster needs its own internal certificate authority at all, what it secures, and why “we’ll just renew it manually” stops working the moment you have more than a handful of services.
- 02The manual way, in fullWe walked through it once by hand — create a CA, sign a certificate, wire it into the application, remember to do it all again next year. It works. It just does not scale, and it puts the whole thing in one person’s head.
- 03Three tools that take it off your handscert-manager issues and renews certificates automatically. trust-manager makes sure every part of the cluster knows which authority to trust. Kyverno enforces it, so new workloads get the right configuration without anyone remembering to add it.
- 04Building it, liveThe second half was hands-on: everyone spun up a local cluster and worked through the whole chain themselves, ending with the same test failing before the setup and passing after it. The full repository is public, so anyone can still run it.
Why it matters
Four ways this goes wrong.
All four are avoidable.
The takeaway
None of this is hard cryptography. It is an ownership problem: a manual step that worked, was never written down, and outlived the person who used to run it. Make the renewals automatic, make the trust explicit, and let your monitoring tell you months ahead — and the whole category of problem quietly goes away.
The slides
The workshop, slide by slide.
Use the arrows, or swipe.
From the floor
Two days,
in sixty seconds.
The future of digital services
Digital services are going cloud-native. Metaminds is ready.
Marius Marinescu (CTO) and Cristian Gal (Chief of Professional Services) spoke at Cloud Native Days Romania about the part cloud-native infrastructure plays in digital transformation, and where Metaminds fits in it.
We were glad to be part of the event, and of a community that thinks long term.
We think in systems. We deliver solutions. We stay connected to what matters.Marius Marinescu, CTO · Cristian Gal, Chief of Professional Services
Events




























