// the luna field guide

Thales Luna HSM: the field guide

Design decisions, CLI walkthroughs and failure drills for the teams who run Luna HSMs in production — written for Australian government and regulated industries, where the keys protect identity data, defence information and privileged access.

cloning domains · HA groups · key ceremonies · CyberArk integration · PKI on hardware roots

// what the guide covers

An HSM estate is a set of decisions. Most get made by accident.

The Luna Field Guide is Securitribe’s working series on Thales Luna HSM design, configuration and operations — the documentation gap between the vendor manual and what actually happens at 2am during a DR test. Two new chapters publish every week: a design chapter on the decision itself, then a hands-on guide with the lunash and lunacm commands to implement it.

Luna fundamentals

The decisions you can’t undo: cloning domains, HA groups and what silently doesn’t replicate, PED activation, NTLS vs STC, and partition versions.

CyberArk on hardware roots

HSM-protecting the vault server key, HA across a primary/DR pair, the failure drill when the HSM is unreachable, and key ceremonies with real separation of duties.

PKI that survives an assessor

Offline root CAs where the restore is proven, ADCS with the Luna KSP, issuing CAs on HA groups, and code signing after the CA/B hardware mandate.

Architecture for regulated data

Partition strategy, sovereignty and the ISM, DPoD vs on-prem for government workloads, and one HSM serving CyberArk, ADCS, SQL Server and HashiCorp Vault at once.

// the chapters

Read the series

Chapters appear here as they publish, in reading order. Start at chapter zero if you’re designing a new estate; jump straight to the failure drills if you’ve inherited one.

// next step

Own the hardware? We'll help you run it.

Securitribe designs, deploys and operates Luna HSM estates for government and regulated organisations — partitions, ceremonies, DR drills and the CyberArk and PKI integrations on top.