AuthentikCertificateKeyPair
goauthentik.io / v1alpha1
apiVersion: goauthentik.io/v1alpha1
kind: AuthentikCertificateKeyPair
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object
AuthentikCertificateKeyPairSpec defines the desired state of AuthentikCertificateKeyPair
certificateData
string required
CertificateData is the PEM-encoded certificate data
generate object
Certificate generation parameters (alternative to providing CertificateData/KeyData)
commonName
string required
CommonName is the common name for the generated certificate
keyAlgorithm
string
KeyAlgorithm is the key algorithm to use (RSA, ECDSA)
enum:
RSA, ECDSA
keySize
integer
KeySize is the key size in bits (for RSA)
format:
int32minimum:
2048
subjectAlternativeNames
[]string
SubjectAlternativeNames is a list of SANs for the certificate
validDays
integer
ValidDays is the validity period in days
format:
int32minimum:
1
keyData
string
KeyData is the optional PEM-encoded private key data
If set, the keypair can be used for encryption
name
string required
Name is the display name of the certificate key pair
minLength:
1status object
AuthentikCertificateKeyPairStatus defines the observed state of AuthentikCertificateKeyPair
certExpiry
string
CertExpiry is the certificate expiry date
format:
date-time
certSubject
string
CertSubject is the certificate subject as RFC4514 string
certificateKeyPairUid
string
CertificateKeyPairUID is the unique identifier in authentik
conditions []object
Conditions represent the latest available observations of the object's state
lastTransitionTime
string required
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format:
date-time
message
string required
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength:
32768
observedGeneration
integer
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64minimum:
0
reason
string required
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
pattern:
^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$minLength:
1maxLength:
1024
status
string required
status of the condition, one of True, False, Unknown.
enum:
True, False, Unknown
type
string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern:
^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$maxLength:
316
fingerprintSHA1
string
FingerprintSHA1 is the SHA1 fingerprint of the certificate
fingerprintSHA256
string
FingerprintSHA256 is the SHA256 fingerprint of the certificate
keyType
string
KeyType is the key algorithm type detected from the certificate's public key
observedGeneration
integer
ObservedGeneration is the generation observed by the controller
format:
int64
privateKeyAvailable
boolean
PrivateKeyAvailable indicates if a private key is configured
No matches. Try .spec.certificateData for an exact path