Skip to main content
Version: v3.9.0

Certificates

A certificate is a leaf TLS certificate in the namespace PKI catalog. An existing certificate authority signs it, or the leaf sets ca.type: self-signed.

Fields are on Certificate fields.

Router and NATS site CAs on control plane deploy are a different path. See Securing the cluster.

When to use it​

Deploy a CA first when the leaf should chain to a named authority. get certificates shows CA rows. Use ca.type: self-signed on the leaf when the Controller should issue that one certificate without a named CA.

There is no update. If the name exists, deploy fails. Delete the certificate and deploy again to rotate it.

What deploy does​

potctl deploy -f cert.yaml -n my-ecn

Deploy sends subject, SAN hosts, expiration, and the issuing ca block. A new name creates the leaf.

cert.yaml
apiVersion: datasance.com/v3
kind: Certificate
metadata:
name: api-tls
namespace: my-ecn
spec:
subject: "CN=api.example.com,O=Example"
hosts: "api.example.com,api.internal"
expiration: 365
ca:
type: direct
secretName: ecn-root-ca

ca.secretName is the certificate authority metadata.name.

How a workload uses it​

A microservice does not name kind: Certificate. Describe prints the leaf cert and private key. When a container needs those files on disk, store them in a Secret and publish that secret with a volume mount. Env and volume shapes are on Microservice fields.

CLI​

potctl get certificates -n my-ecn
potctl describe certificate api-tls -n my-ecn
potctl delete certificate api-tls -n my-ecn

describe certificate includes the private key in data. Keep that file private. delete certificate removes a leaf directly. The same command prompts when the name is a CA. There is no attach.

Console​

Config → Certificates lists CAs and issued certificates. See Configuration.

Group 3See anything wrong with the document? Help us improve it!