Certificates
A certificate is a leaf TLS certificate in the namespace PKI catalog. An existing certificate authority signs it, or the leaf sets ca.type: self-signed.
Fields are on Certificate fields.
Router and NATS site CAs on control plane deploy are a different path. See Securing the cluster.
When to use it
Deploy a CA first when the leaf should chain to a named authority. get certificates shows CA rows. Use ca.type: self-signed on the leaf when the Controller should issue that one certificate without a named CA.
There is no update. If the name exists, deploy fails. Delete the certificate and deploy again to rotate it.
What deploy does
potctl deploy -f cert.yaml -n my-ecn
Deploy sends subject, SAN hosts, expiration, and the issuing ca block. A new name creates the leaf.
apiVersion: datasance.com/v3
kind: Certificate
metadata:
name: api-tls
namespace: my-ecn
spec:
subject: "CN=api.example.com,O=Example"
hosts: "api.example.com,api.internal"
expiration: 365
ca:
type: direct
secretName: ecn-root-ca
ca.secretName is the certificate authority metadata.name.
How a workload uses it
A microservice does not name kind: Certificate. Describe prints the leaf cert and private key. When a container needs those files on disk, store them in a Secret and publish that secret with a volume mount. Env and volume shapes are on Microservice fields.
CLI
potctl get certificates -n my-ecn
potctl describe certificate api-tls -n my-ecn
potctl delete certificate api-tls -n my-ecn
describe certificate includes the private key in data. Keep that file private. delete certificate removes a leaf directly. The same command prompts when the name is a CA. There is no attach.
Console
Config → Certificates lists CAs and issued certificates. See Configuration.