PodCertificateRequestStatus

io.k8s.api.certificates.v1beta1.PodCertificateRequestStatus source ↗

PodCertificateRequestStatus describes the status of the request, and holds the certificate data if the request is issued.

beginRefreshAtTimebeginRefreshAt is the time at which the kubelet should begin trying to refresh the certificate. This field is set via the /status subresource, and must be set at the same time as certificateChain. Once populated, this field is immutable.This field is only a hint. Kubelet may start refreshing before or after this time if necessary.
certificateChainstringcertificateChain is populated with an issued certificate by the signer. This field is set via the /status subresource. Once populated, this field is immutable.If the certificate signing request is denied, a condition of type "Denied" is added and this field remains empty. If the signer cannot issue the certificate, a condition of type "Failed" is added and this field remains empty.Validation requirements: 1. certificateChain must consist of one or more PEM-formatted certificates. 2. Each entry must be a valid PEM-wrapped, DER-encoded ASN.1 Certificate as described in section 4 of RFC5280.If more than one block is present, and the definition of the requested spec.signerName does not indicate otherwise, the first block is the issued certificate, and subsequent blocks should be treated as intermediate certificates and presented in TLS handshakes. When projecting the chain into a pod volume, kubelet will drop any data in-between the PEM blocks, as well as any PEM block headers.
conditions[]Conditionconditions applied to the request.The types "Issued", "Denied", and "Failed" have special handling. At most one of these conditions may be present, and they must have status "True".If the request is denied with `Reason=UnsupportedKeyType`, the signer may suggest a key type that will work in the message field.
lastTransitionTimeTime requiredlastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
messagestring requiredmessage is a human readable message indicating details about the transition. This may be an empty string.
observedGenerationinteger (int64)observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
reasonstring requiredreason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
statusstring requiredstatus of the condition, one of True, False, Unknown.
typestring requiredtype of condition in CamelCase or in foo.example.com/CamelCase.
notAfterTimenotAfter is the time at which the certificate expires. The value must be the same as the notAfter value in the leaf certificate in certificateChain. This field is set via the /status subresource. Once populated, it is immutable. The signer must set this field at the same time it sets certificateChain.
notBeforeTimenotBefore is the time at which the certificate becomes valid. The value must be the same as the notBefore value in the leaf certificate in certificateChain. This field is set via the /status subresource. Once populated, it is immutable. The signer must set this field at the same time it sets certificateChain.