Skip to main content
Version: v3.9.0

CertificateAuthority fields

Reference for kind: CertificateAuthority. Deploy and the control-plane CA split are on Certificate authorities.

The CLI sets the API name from metadata.name. A spec.name in the file is overwritten.

Deploy
apiVersion: datasance.com/v3 # required, string
kind: CertificateAuthority # required, string
metadata:
name: ecn-root-ca # required, string. For direct and k8s-secret this must match the secret name
namespace: my-ecn # no, string
spec:
subject: "CN=ECN Root CA,O=Example" # recommended, string. Set it for self-signed
type: self-signed # required, string. self-signed, direct, or k8s-secret
expiration: 3650 # no, int. Days. Common on self-signed
secretName: ecn-root-ca # import types, string. Unused for self-signed. Defaults to metadata.name

Fields​

FieldRequiredDescription
subjectRecommendedX.509 subject DN. Set it for self-signed.
typeYesself-signed, direct, or k8s-secret. Other strings return 400.
expirationNoValidity in days. Common on self-signed.
secretNameImport typesSecret that holds the cert and key. If omitted, the CLI uses metadata.name.

secretName is unused for self-signed.

Types​

typePrerequisites
self-signedController generates the key pair. No backing Secret.
directA kind: Secret with spec.type: tls and base64 PEM in data is already deployed. metadata.name matches that secret name.
k8s-secretA Kubernetes Secret exists on the control plane cluster. Set secretName when that name differs from metadata.name.

For direct and k8s-secret, metadata.name must equal the effective secret name. The error is Name must match Secret name. An existing CA fails with an update-not-allowed error. There is no CA update.

type: direct secret keys are tls.crt, tls.key, and optional ca.crt. See Secret fields.

kind: CertificateAuthority
metadata:
name: my-import-ca
spec:
subject: "CN=Imported CA,O=Example"
type: direct

Describe and delete​

describe certificate NAME for a CA returns kind: CertificateAuthority and data with certificate, privateKey, validity, and serial. That output is sensitive.

delete certificate NAME sees IsCA and prompts before deleting the CA.

A leaf that should be signed by this CA sets ca.secretName to metadata.name. See Certificate fields.

Group 3See anything wrong with the document? Help us improve it!