Design decisions, CLI walkthroughs and failure drills for the teams who run Luna HSMs in production — written for Australian government and regulated industries, where the keys protect identity data, defence information and privileged access.
cloning domains · HA groups · key ceremonies · CyberArk integration · PKI on hardware roots
The Luna Field Guide is Securitribe’s working series on Thales Luna HSM design, configuration and operations — the documentation gap between the vendor manual and what actually happens at 2am during a DR test. Two new chapters publish every week: a design chapter on the decision itself, then a hands-on guide with the lunash and lunacm commands to implement it.
The decisions you can’t undo: cloning domains, HA groups and what silently doesn’t replicate, PED activation, NTLS vs STC, and partition versions.
HSM-protecting the vault server key, HA across a primary/DR pair, the failure drill when the HSM is unreachable, and key ceremonies with real separation of duties.
Offline root CAs where the restore is proven, ADCS with the Luna KSP, issuing CAs on HA groups, and code signing after the CA/B hardware mandate.
Partition strategy, sovereignty and the ISM, DPoD vs on-prem for government workloads, and one HSM serving CyberArk, ADCS, SQL Server and HashiCorp Vault at once.
Chapters appear here as they publish, in reading order. Start at chapter zero if you’re designing a new estate; jump straight to the failure drills if you’ve inherited one.
Securitribe designs, deploys and operates Luna HSM estates for government and regulated organisations — partitions, ceremonies, DR drills and the CyberArk and PKI integrations on top.