NAME

IO::K8s::CertManager::V1::CertificateRequestSpec - Specification of the desired state of the CertificateRequest resource.

VERSION

version 1.108

duration

Requested 'duration' (i.e. lifetime) of the Certificate. Note that the issuer may choose to ignore the requested duration, just like any other requested attribute.

extra

Extra contains extra attributes of the user that created the CertificateRequest. Populated by the cert-manager webhook on creation and immutable.

groups

Groups contains group membership of the user that created the CertificateRequest. Populated by the cert-manager webhook on creation and immutable.

isCA

Requested basic constraints isCA value. Note that the issuer may choose to ignore the requested isCA value, just like any other requested attribute.

NOTE: If the CSR in the `Request` field has a BasicConstraints extension, it must have the same isCA value as specified here.

If true, this will automatically add the `cert sign` usage to the list of requested `usages`.

issuerRef

Reference to the issuer responsible for issuing the certificate. If the issuer is namespace-scoped, it must be in the same namespace as the Certificate. If the issuer is cluster-scoped, it can be used from any namespace.

The `name` field of the reference must always be specified.

request

The PEM-encoded X.509 certificate signing request to be submitted to the issuer for signing.

If the CSR has a BasicConstraints extension, its isCA attribute must match the `isCA` value of this CertificateRequest. If the CSR has a KeyUsage extension, its key usages must match the key usages in the `usages` field of this CertificateRequest. If the CSR has a ExtKeyUsage extension, its extended key usages must match the extended key usages in the `usages` field of this CertificateRequest.

uid

UID contains the uid of the user that created the CertificateRequest. Populated by the cert-manager webhook on creation and immutable.

usages

Requested key usages and extended key usages.

NOTE: If the CSR in the `Request` field has uses the KeyUsage or ExtKeyUsage extension, these extensions must have the same values as specified here without any additional values.

If unset, defaults to `digital signature` and `key encipherment`.

username

Username contains the name of the user that created the CertificateRequest. Populated by the cert-manager webhook on creation and immutable.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/pplu/io-k8s-p5/issues.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHORS

  • Torsten Raudssus <getty@cpan.org>

  • Jose Luis Martinez Torres <jlmartin@cpan.org>

COPYRIGHT AND LICENSE

This software is Copyright (c) 2018-2026 by Jose Luis Martinez Torres <jlmartin@cpan.org>.

This is free software, licensed under:

The Apache License, Version 2.0, January 2004