Definition. With regular TLS, only the server proves its identity. With mTLS (Mutual TLS), the client presents a certificate as well. Both sides check it against a trusted certificate authority, usually an internal CA. Only then is the connection established.
Why it matters. Inside a cluster many services talk to each other: PHP application, database, cache, reverse proxy. Without mTLS every service trusts whatever reaches it on the network. With mTLS identity counts, not the IP address. That is a core building block of zero trust. The effort lies in certificate management, meaning short lifetimes and automatic rotation.
Example. A TYPO3 pod connects to MariaDB and Valkey only with client certificates from an internal Step CA. The certificates are valid for 24 hours and renew automatically.
Related. Kubernetes, IT-Grundschutz, Supply chain attack