Certificate.
A TLS certificate issued inside the cluster by cert-manager and kept as a secret
Figure 1Certificatespecified
- kind
- definition
- scope
- platform
- key
- the host names it covers
- store
- vault
- family
- network
Fields#
| field | type | required | note |
|---|---|---|---|
hosts | [text] | yes | |
issuer | text | yes | |
not_before | time | yes | |
not_after | time | yes | |
secret | VaultEntry | yes | where the key is kept; never on disk in a file |
renew_before | duration | yes | the alarm and the renewal fire this long before expiry |
Routes that use it#
No route takes or returns Certificate directly. The record holds it, and the objects that point at it reach it.