# Cat2: PKI/CA + Vault Deployment 08/14/2026 HashiCorp Vault deployment, credential migration from ~/.creds/, Bitwarden machine accounts, tsys-ca PKI/SSL with ACME. * Support #342: OAM: PKI/SSL: tsys-ca VM + HSM CA + ACME * Support #370: OAM: Vault - migrate all API keys (HIGH priority) * Support #371: OAM: AWX HTTPS/TLS configuration * Support #406: Integrate Beszel API credentials (PocketBase auth) * Feature #408: Deploy HashiCorp Vault infrastructure for shared secrets * Support #409: Migrate shared credentials from ~/.creds/ to Vault * Feature #410: Configure Bitwarden machine accounts for non-shared secrets * Feature #411: Explore Ansible Vault integration for KNELCredsManager (TBD)