Appendix C: Glossary

Term Definition
AppViewX Modular, low-code automation platform for certificate lifecycle, network automation, and PKI operations.
CLM Certificate Lifecycle Management module: discover, monitor, automate, and govern certificates.
ADC Application Delivery Controller module for load balancer management and traffic automation.
PKI Public Key Infrastructure module for CA management and certificate issuance.
SSH SSH Key/Certificate Lifecycle Management module.
SIGN Code Signing module for certificate enrolment and signing policy management.
KUBE Kubernetes Certificate CLM module.
Interactive UI (IU) Full-screen terminal-based wizard for all lifecycle operations. Launched via ./install.sh.
install.sh Single entry-point for all lifecycle operations: install, upgrade, patch. Launches the IU inside tmux.
appviewx.sh Primary operational CLI for day-to-day platform administration.
appviewx.conf Master configuration file driving all AppViewX deployment and operational behaviour.
Helm Kubernetes package manager. All AppViewX components deployed as Helm charts.
Istio Service mesh providing mTLS, traffic management, circuit-breaking, and observability.
OpenBao / Vault Open-source secret management platform for credentials and encryption keys.
MongoDB Document database used as the primary data store.
Redis In-memory data store for caching and session management.
Terraform / OpenTofu Infrastructure-as-Code tools used to orchestrate Helm chart deployments.
Calico Kubernetes CNI plugin for pod networking and NetworkPolicy enforcement.
mTLS Mutual TLS: zero-trust security model enforced by Istio for all pod-to-pod communication.
HPA Horizontal Pod Autoscaler: adjusts replica counts automatically based on metrics.
KEK Key Encryption Key: additional encryption layer for the database.
tmux Terminal multiplexer. Strongly recommended for install/upgrade to survive SSH disconnections.
Blue-Green Upgrade Migration upgrade to new infrastructure with minimal downtime via data backup/restore.
In-Place Upgrade Upgrade of existing infrastructure in position. Involves planned downtime.
avxinfo Command available on any cluster node to retrieve installation details.
SCEP Simple Certificate Enrolment Protocol (port 30022).
EST Enrollment over Secure Transport (port 30021).
cgroups Linux kernel feature used by Kubernetes for resource isolation. v2 recommended with K8s 1.32+.
KEX Key Exchange: SSH algorithm used during connection establishment.