public static final class V1Certificates.CertificateSigningRequestSpec.Builder extends com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder> implements V1Certificates.CertificateSigningRequestSpecOrBuilder
CertificateSigningRequestSpec contains the certificate request.Protobuf type
k8s.io.api.certificates.v1.CertificateSigningRequestSpec| Modifier and Type | Method and Description |
|---|---|
V1Certificates.CertificateSigningRequestSpec.Builder |
addAllGroups(Iterable<String> values)
groups contains group membership of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
addAllUsages(Iterable<String> values)
usages specifies a set of key usages requested in the issued certificate.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
addGroups(String value)
groups contains group membership of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
addGroupsBytes(com.google.protobuf.ByteString value)
groups contains group membership of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
addRepeatedField(com.google.protobuf.Descriptors.FieldDescriptor field,
Object value) |
V1Certificates.CertificateSigningRequestSpec.Builder |
addUsages(String value)
usages specifies a set of key usages requested in the issued certificate.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
addUsagesBytes(com.google.protobuf.ByteString value)
usages specifies a set of key usages requested in the issued certificate.
|
V1Certificates.CertificateSigningRequestSpec |
build() |
V1Certificates.CertificateSigningRequestSpec |
buildPartial() |
V1Certificates.CertificateSigningRequestSpec.Builder |
clear() |
V1Certificates.CertificateSigningRequestSpec.Builder |
clearExpirationSeconds()
expirationSeconds is the requested duration of validity of the issued
certificate.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clearExtra() |
V1Certificates.CertificateSigningRequestSpec.Builder |
clearField(com.google.protobuf.Descriptors.FieldDescriptor field) |
V1Certificates.CertificateSigningRequestSpec.Builder |
clearGroups()
groups contains group membership of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clearOneof(com.google.protobuf.Descriptors.OneofDescriptor oneof) |
V1Certificates.CertificateSigningRequestSpec.Builder |
clearRequest()
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clearSignerName()
signerName indicates the requested signer, and is a qualified name.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clearUid()
uid contains the uid of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clearUsages()
usages specifies a set of key usages requested in the issued certificate.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clearUsername()
username contains the name of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
clone() |
boolean |
containsExtra(String key)
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec |
getDefaultInstanceForType() |
static com.google.protobuf.Descriptors.Descriptor |
getDescriptor() |
com.google.protobuf.Descriptors.Descriptor |
getDescriptorForType() |
int |
getExpirationSeconds()
expirationSeconds is the requested duration of validity of the issued
certificate.
|
Map<String,V1Certificates.ExtraValue> |
getExtra()
Deprecated.
|
int |
getExtraCount()
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
Map<String,V1Certificates.ExtraValue> |
getExtraMap()
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
V1Certificates.ExtraValue |
getExtraOrDefault(String key,
V1Certificates.ExtraValue defaultValue)
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
V1Certificates.ExtraValue |
getExtraOrThrow(String key)
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
String |
getGroups(int index)
groups contains group membership of the user that created the CertificateSigningRequest.
|
com.google.protobuf.ByteString |
getGroupsBytes(int index)
groups contains group membership of the user that created the CertificateSigningRequest.
|
int |
getGroupsCount()
groups contains group membership of the user that created the CertificateSigningRequest.
|
com.google.protobuf.ProtocolStringList |
getGroupsList()
groups contains group membership of the user that created the CertificateSigningRequest.
|
Map<String,V1Certificates.ExtraValue> |
getMutableExtra()
Deprecated.
|
com.google.protobuf.ByteString |
getRequest()
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block.
|
String |
getSignerName()
signerName indicates the requested signer, and is a qualified name.
|
com.google.protobuf.ByteString |
getSignerNameBytes()
signerName indicates the requested signer, and is a qualified name.
|
String |
getUid()
uid contains the uid of the user that created the CertificateSigningRequest.
|
com.google.protobuf.ByteString |
getUidBytes()
uid contains the uid of the user that created the CertificateSigningRequest.
|
String |
getUsages(int index)
usages specifies a set of key usages requested in the issued certificate.
|
com.google.protobuf.ByteString |
getUsagesBytes(int index)
usages specifies a set of key usages requested in the issued certificate.
|
int |
getUsagesCount()
usages specifies a set of key usages requested in the issued certificate.
|
com.google.protobuf.ProtocolStringList |
getUsagesList()
usages specifies a set of key usages requested in the issued certificate.
|
String |
getUsername()
username contains the name of the user that created the CertificateSigningRequest.
|
com.google.protobuf.ByteString |
getUsernameBytes()
username contains the name of the user that created the CertificateSigningRequest.
|
boolean |
hasExpirationSeconds()
expirationSeconds is the requested duration of validity of the issued
certificate.
|
boolean |
hasRequest()
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block.
|
boolean |
hasSignerName()
signerName indicates the requested signer, and is a qualified name.
|
boolean |
hasUid()
uid contains the uid of the user that created the CertificateSigningRequest.
|
boolean |
hasUsername()
username contains the name of the user that created the CertificateSigningRequest.
|
protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable |
internalGetFieldAccessorTable() |
protected com.google.protobuf.MapField |
internalGetMapField(int number) |
protected com.google.protobuf.MapField |
internalGetMutableMapField(int number) |
boolean |
isInitialized() |
V1Certificates.CertificateSigningRequestSpec.Builder |
mergeFrom(com.google.protobuf.CodedInputStream input,
com.google.protobuf.ExtensionRegistryLite extensionRegistry) |
V1Certificates.CertificateSigningRequestSpec.Builder |
mergeFrom(com.google.protobuf.Message other) |
V1Certificates.CertificateSigningRequestSpec.Builder |
mergeFrom(V1Certificates.CertificateSigningRequestSpec other) |
V1Certificates.CertificateSigningRequestSpec.Builder |
mergeUnknownFields(com.google.protobuf.UnknownFieldSet unknownFields) |
V1Certificates.CertificateSigningRequestSpec.Builder |
putAllExtra(Map<String,V1Certificates.ExtraValue> values)
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
putExtra(String key,
V1Certificates.ExtraValue value)
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
removeExtra(String key)
extra contains extra attributes of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setExpirationSeconds(int value)
expirationSeconds is the requested duration of validity of the issued
certificate.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setField(com.google.protobuf.Descriptors.FieldDescriptor field,
Object value) |
V1Certificates.CertificateSigningRequestSpec.Builder |
setGroups(int index,
String value)
groups contains group membership of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setRepeatedField(com.google.protobuf.Descriptors.FieldDescriptor field,
int index,
Object value) |
V1Certificates.CertificateSigningRequestSpec.Builder |
setRequest(com.google.protobuf.ByteString value)
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setSignerName(String value)
signerName indicates the requested signer, and is a qualified name.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setSignerNameBytes(com.google.protobuf.ByteString value)
signerName indicates the requested signer, and is a qualified name.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setUid(String value)
uid contains the uid of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setUidBytes(com.google.protobuf.ByteString value)
uid contains the uid of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setUnknownFields(com.google.protobuf.UnknownFieldSet unknownFields) |
V1Certificates.CertificateSigningRequestSpec.Builder |
setUsages(int index,
String value)
usages specifies a set of key usages requested in the issued certificate.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setUsername(String value)
username contains the name of the user that created the CertificateSigningRequest.
|
V1Certificates.CertificateSigningRequestSpec.Builder |
setUsernameBytes(com.google.protobuf.ByteString value)
username contains the name of the user that created the CertificateSigningRequest.
|
getAllFields, getField, getFieldBuilder, getOneofFieldDescriptor, getParentForChildren, getRepeatedField, getRepeatedFieldBuilder, getRepeatedFieldCount, getUnknownFields, getUnknownFieldSetBuilder, hasField, hasOneof, isClean, markClean, mergeUnknownLengthDelimitedField, mergeUnknownVarintField, newBuilderForField, onBuilt, onChanged, parseUnknownField, setUnknownFieldSetBuilder, setUnknownFieldsProto3findInitializationErrors, getInitializationErrorString, internalMergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, newUninitializedMessageException, toStringaddAll, addAll, mergeDelimitedFrom, mergeDelimitedFrom, mergeFrom, newUninitializedMessageExceptionequals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, waitfindInitializationErrors, getAllFields, getField, getInitializationErrorString, getOneofFieldDescriptor, getRepeatedField, getRepeatedFieldCount, getUnknownFields, hasField, hasOneofpublic static final com.google.protobuf.Descriptors.Descriptor getDescriptor()
protected com.google.protobuf.MapField internalGetMapField(int number)
internalGetMapField in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>protected com.google.protobuf.MapField internalGetMutableMapField(int number)
internalGetMutableMapField in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable internalGetFieldAccessorTable()
internalGetFieldAccessorTable in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder clear()
clear in interface com.google.protobuf.Message.Builderclear in interface com.google.protobuf.MessageLite.Builderclear in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public com.google.protobuf.Descriptors.Descriptor getDescriptorForType()
getDescriptorForType in interface com.google.protobuf.Message.BuildergetDescriptorForType in interface com.google.protobuf.MessageOrBuildergetDescriptorForType in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec getDefaultInstanceForType()
getDefaultInstanceForType in interface com.google.protobuf.MessageLiteOrBuildergetDefaultInstanceForType in interface com.google.protobuf.MessageOrBuilderpublic V1Certificates.CertificateSigningRequestSpec build()
build in interface com.google.protobuf.Message.Builderbuild in interface com.google.protobuf.MessageLite.Builderpublic V1Certificates.CertificateSigningRequestSpec buildPartial()
buildPartial in interface com.google.protobuf.Message.BuilderbuildPartial in interface com.google.protobuf.MessageLite.Builderpublic V1Certificates.CertificateSigningRequestSpec.Builder clone()
clone in interface com.google.protobuf.Message.Builderclone in interface com.google.protobuf.MessageLite.Builderclone in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder setField(com.google.protobuf.Descriptors.FieldDescriptor field, Object value)
setField in interface com.google.protobuf.Message.BuildersetField in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder clearField(com.google.protobuf.Descriptors.FieldDescriptor field)
clearField in interface com.google.protobuf.Message.BuilderclearField in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder clearOneof(com.google.protobuf.Descriptors.OneofDescriptor oneof)
clearOneof in interface com.google.protobuf.Message.BuilderclearOneof in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder setRepeatedField(com.google.protobuf.Descriptors.FieldDescriptor field, int index, Object value)
setRepeatedField in interface com.google.protobuf.Message.BuildersetRepeatedField in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder addRepeatedField(com.google.protobuf.Descriptors.FieldDescriptor field, Object value)
addRepeatedField in interface com.google.protobuf.Message.BuilderaddRepeatedField in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder mergeFrom(com.google.protobuf.Message other)
mergeFrom in interface com.google.protobuf.Message.BuildermergeFrom in class com.google.protobuf.AbstractMessage.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder mergeFrom(V1Certificates.CertificateSigningRequestSpec other)
public final boolean isInitialized()
isInitialized in interface com.google.protobuf.MessageLiteOrBuilderisInitialized in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public V1Certificates.CertificateSigningRequestSpec.Builder mergeFrom(com.google.protobuf.CodedInputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws IOException
mergeFrom in interface com.google.protobuf.Message.BuildermergeFrom in interface com.google.protobuf.MessageLite.BuildermergeFrom in class com.google.protobuf.AbstractMessage.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>IOExceptionpublic boolean hasRequest()
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block. When serialized as JSON or YAML, the data is additionally base64-encoded. +listType=atomic
optional bytes request = 1;hasRequest in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic com.google.protobuf.ByteString getRequest()
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block. When serialized as JSON or YAML, the data is additionally base64-encoded. +listType=atomic
optional bytes request = 1;getRequest in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setRequest(com.google.protobuf.ByteString value)
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block. When serialized as JSON or YAML, the data is additionally base64-encoded. +listType=atomic
optional bytes request = 1;public V1Certificates.CertificateSigningRequestSpec.Builder clearRequest()
request contains an x509 certificate signing request encoded in a "CERTIFICATE REQUEST" PEM block. When serialized as JSON or YAML, the data is additionally base64-encoded. +listType=atomic
optional bytes request = 1;public boolean hasSignerName()
signerName indicates the requested signer, and is a qualified name. List/watch requests for CertificateSigningRequests can filter on this field using a "spec.signerName=NAME" fieldSelector. Well-known Kubernetes signers are: 1. "kubernetes.io/kube-apiserver-client": issues client certificates that can be used to authenticate to kube-apiserver. Requests for this signer are never auto-approved by kube-controller-manager, can be issued by the "csrsigning" controller in kube-controller-manager. 2. "kubernetes.io/kube-apiserver-client-kubelet": issues client certificates that kubelets use to authenticate to kube-apiserver. Requests for this signer can be auto-approved by the "csrapproving" controller in kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. 3. "kubernetes.io/kubelet-serving" issues serving certificates that kubelets use to serve TLS endpoints, which kube-apiserver can connect to securely. Requests for this signer are never auto-approved by kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. More details are available at https://k8s.io/docs/reference/access-authn-authz/certificate-signing-requests/#kubernetes-signers Custom signerNames can also be specified. The signer defines: 1. Trust distribution: how trust (CA bundles) are distributed. 2. Permitted subjects: and behavior when a disallowed subject is requested. 3. Required, permitted, or forbidden x509 extensions in the request (including whether subjectAltNames are allowed, which types, restrictions on allowed values) and behavior when a disallowed extension is requested. 4. Required, permitted, or forbidden key usages / extended key usages. 5. Expiration/certificate lifetime: whether it is fixed by the signer, configurable by the admin. 6. Whether or not requests for CA certificates are allowed.
optional string signerName = 7;hasSignerName in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic String getSignerName()
signerName indicates the requested signer, and is a qualified name. List/watch requests for CertificateSigningRequests can filter on this field using a "spec.signerName=NAME" fieldSelector. Well-known Kubernetes signers are: 1. "kubernetes.io/kube-apiserver-client": issues client certificates that can be used to authenticate to kube-apiserver. Requests for this signer are never auto-approved by kube-controller-manager, can be issued by the "csrsigning" controller in kube-controller-manager. 2. "kubernetes.io/kube-apiserver-client-kubelet": issues client certificates that kubelets use to authenticate to kube-apiserver. Requests for this signer can be auto-approved by the "csrapproving" controller in kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. 3. "kubernetes.io/kubelet-serving" issues serving certificates that kubelets use to serve TLS endpoints, which kube-apiserver can connect to securely. Requests for this signer are never auto-approved by kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. More details are available at https://k8s.io/docs/reference/access-authn-authz/certificate-signing-requests/#kubernetes-signers Custom signerNames can also be specified. The signer defines: 1. Trust distribution: how trust (CA bundles) are distributed. 2. Permitted subjects: and behavior when a disallowed subject is requested. 3. Required, permitted, or forbidden x509 extensions in the request (including whether subjectAltNames are allowed, which types, restrictions on allowed values) and behavior when a disallowed extension is requested. 4. Required, permitted, or forbidden key usages / extended key usages. 5. Expiration/certificate lifetime: whether it is fixed by the signer, configurable by the admin. 6. Whether or not requests for CA certificates are allowed.
optional string signerName = 7;getSignerName in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic com.google.protobuf.ByteString getSignerNameBytes()
signerName indicates the requested signer, and is a qualified name. List/watch requests for CertificateSigningRequests can filter on this field using a "spec.signerName=NAME" fieldSelector. Well-known Kubernetes signers are: 1. "kubernetes.io/kube-apiserver-client": issues client certificates that can be used to authenticate to kube-apiserver. Requests for this signer are never auto-approved by kube-controller-manager, can be issued by the "csrsigning" controller in kube-controller-manager. 2. "kubernetes.io/kube-apiserver-client-kubelet": issues client certificates that kubelets use to authenticate to kube-apiserver. Requests for this signer can be auto-approved by the "csrapproving" controller in kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. 3. "kubernetes.io/kubelet-serving" issues serving certificates that kubelets use to serve TLS endpoints, which kube-apiserver can connect to securely. Requests for this signer are never auto-approved by kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. More details are available at https://k8s.io/docs/reference/access-authn-authz/certificate-signing-requests/#kubernetes-signers Custom signerNames can also be specified. The signer defines: 1. Trust distribution: how trust (CA bundles) are distributed. 2. Permitted subjects: and behavior when a disallowed subject is requested. 3. Required, permitted, or forbidden x509 extensions in the request (including whether subjectAltNames are allowed, which types, restrictions on allowed values) and behavior when a disallowed extension is requested. 4. Required, permitted, or forbidden key usages / extended key usages. 5. Expiration/certificate lifetime: whether it is fixed by the signer, configurable by the admin. 6. Whether or not requests for CA certificates are allowed.
optional string signerName = 7;getSignerNameBytes in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setSignerName(String value)
signerName indicates the requested signer, and is a qualified name. List/watch requests for CertificateSigningRequests can filter on this field using a "spec.signerName=NAME" fieldSelector. Well-known Kubernetes signers are: 1. "kubernetes.io/kube-apiserver-client": issues client certificates that can be used to authenticate to kube-apiserver. Requests for this signer are never auto-approved by kube-controller-manager, can be issued by the "csrsigning" controller in kube-controller-manager. 2. "kubernetes.io/kube-apiserver-client-kubelet": issues client certificates that kubelets use to authenticate to kube-apiserver. Requests for this signer can be auto-approved by the "csrapproving" controller in kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. 3. "kubernetes.io/kubelet-serving" issues serving certificates that kubelets use to serve TLS endpoints, which kube-apiserver can connect to securely. Requests for this signer are never auto-approved by kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. More details are available at https://k8s.io/docs/reference/access-authn-authz/certificate-signing-requests/#kubernetes-signers Custom signerNames can also be specified. The signer defines: 1. Trust distribution: how trust (CA bundles) are distributed. 2. Permitted subjects: and behavior when a disallowed subject is requested. 3. Required, permitted, or forbidden x509 extensions in the request (including whether subjectAltNames are allowed, which types, restrictions on allowed values) and behavior when a disallowed extension is requested. 4. Required, permitted, or forbidden key usages / extended key usages. 5. Expiration/certificate lifetime: whether it is fixed by the signer, configurable by the admin. 6. Whether or not requests for CA certificates are allowed.
optional string signerName = 7;public V1Certificates.CertificateSigningRequestSpec.Builder clearSignerName()
signerName indicates the requested signer, and is a qualified name. List/watch requests for CertificateSigningRequests can filter on this field using a "spec.signerName=NAME" fieldSelector. Well-known Kubernetes signers are: 1. "kubernetes.io/kube-apiserver-client": issues client certificates that can be used to authenticate to kube-apiserver. Requests for this signer are never auto-approved by kube-controller-manager, can be issued by the "csrsigning" controller in kube-controller-manager. 2. "kubernetes.io/kube-apiserver-client-kubelet": issues client certificates that kubelets use to authenticate to kube-apiserver. Requests for this signer can be auto-approved by the "csrapproving" controller in kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. 3. "kubernetes.io/kubelet-serving" issues serving certificates that kubelets use to serve TLS endpoints, which kube-apiserver can connect to securely. Requests for this signer are never auto-approved by kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. More details are available at https://k8s.io/docs/reference/access-authn-authz/certificate-signing-requests/#kubernetes-signers Custom signerNames can also be specified. The signer defines: 1. Trust distribution: how trust (CA bundles) are distributed. 2. Permitted subjects: and behavior when a disallowed subject is requested. 3. Required, permitted, or forbidden x509 extensions in the request (including whether subjectAltNames are allowed, which types, restrictions on allowed values) and behavior when a disallowed extension is requested. 4. Required, permitted, or forbidden key usages / extended key usages. 5. Expiration/certificate lifetime: whether it is fixed by the signer, configurable by the admin. 6. Whether or not requests for CA certificates are allowed.
optional string signerName = 7;public V1Certificates.CertificateSigningRequestSpec.Builder setSignerNameBytes(com.google.protobuf.ByteString value)
signerName indicates the requested signer, and is a qualified name. List/watch requests for CertificateSigningRequests can filter on this field using a "spec.signerName=NAME" fieldSelector. Well-known Kubernetes signers are: 1. "kubernetes.io/kube-apiserver-client": issues client certificates that can be used to authenticate to kube-apiserver. Requests for this signer are never auto-approved by kube-controller-manager, can be issued by the "csrsigning" controller in kube-controller-manager. 2. "kubernetes.io/kube-apiserver-client-kubelet": issues client certificates that kubelets use to authenticate to kube-apiserver. Requests for this signer can be auto-approved by the "csrapproving" controller in kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. 3. "kubernetes.io/kubelet-serving" issues serving certificates that kubelets use to serve TLS endpoints, which kube-apiserver can connect to securely. Requests for this signer are never auto-approved by kube-controller-manager, and can be issued by the "csrsigning" controller in kube-controller-manager. More details are available at https://k8s.io/docs/reference/access-authn-authz/certificate-signing-requests/#kubernetes-signers Custom signerNames can also be specified. The signer defines: 1. Trust distribution: how trust (CA bundles) are distributed. 2. Permitted subjects: and behavior when a disallowed subject is requested. 3. Required, permitted, or forbidden x509 extensions in the request (including whether subjectAltNames are allowed, which types, restrictions on allowed values) and behavior when a disallowed extension is requested. 4. Required, permitted, or forbidden key usages / extended key usages. 5. Expiration/certificate lifetime: whether it is fixed by the signer, configurable by the admin. 6. Whether or not requests for CA certificates are allowed.
optional string signerName = 7;public boolean hasExpirationSeconds()
expirationSeconds is the requested duration of validity of the issued
certificate. The certificate signer may issue a certificate with a different
validity duration so a client must check the delta between the notBefore and
and notAfter fields in the issued certificate to determine the actual duration.
The v1.22+ in-tree implementations of the well-known Kubernetes signers will
honor this field as long as the requested duration is not greater than the
maximum duration they will honor per the --cluster-signing-duration CLI
flag to the Kubernetes controller manager.
Certificate signers may not honor this field for various reasons:
1. Old signer that is unaware of the field (such as the in-tree
implementations prior to v1.22)
2. Signer whose configured maximum is shorter than the requested duration
3. Signer whose configured minimum is longer than the requested duration
The minimum valid value for expirationSeconds is 600, i.e. 10 minutes.
As of v1.22, this field is beta and is controlled via the CSRDuration feature gate.
+optional
optional int32 expirationSeconds = 8;hasExpirationSeconds in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic int getExpirationSeconds()
expirationSeconds is the requested duration of validity of the issued
certificate. The certificate signer may issue a certificate with a different
validity duration so a client must check the delta between the notBefore and
and notAfter fields in the issued certificate to determine the actual duration.
The v1.22+ in-tree implementations of the well-known Kubernetes signers will
honor this field as long as the requested duration is not greater than the
maximum duration they will honor per the --cluster-signing-duration CLI
flag to the Kubernetes controller manager.
Certificate signers may not honor this field for various reasons:
1. Old signer that is unaware of the field (such as the in-tree
implementations prior to v1.22)
2. Signer whose configured maximum is shorter than the requested duration
3. Signer whose configured minimum is longer than the requested duration
The minimum valid value for expirationSeconds is 600, i.e. 10 minutes.
As of v1.22, this field is beta and is controlled via the CSRDuration feature gate.
+optional
optional int32 expirationSeconds = 8;getExpirationSeconds in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setExpirationSeconds(int value)
expirationSeconds is the requested duration of validity of the issued
certificate. The certificate signer may issue a certificate with a different
validity duration so a client must check the delta between the notBefore and
and notAfter fields in the issued certificate to determine the actual duration.
The v1.22+ in-tree implementations of the well-known Kubernetes signers will
honor this field as long as the requested duration is not greater than the
maximum duration they will honor per the --cluster-signing-duration CLI
flag to the Kubernetes controller manager.
Certificate signers may not honor this field for various reasons:
1. Old signer that is unaware of the field (such as the in-tree
implementations prior to v1.22)
2. Signer whose configured maximum is shorter than the requested duration
3. Signer whose configured minimum is longer than the requested duration
The minimum valid value for expirationSeconds is 600, i.e. 10 minutes.
As of v1.22, this field is beta and is controlled via the CSRDuration feature gate.
+optional
optional int32 expirationSeconds = 8;public V1Certificates.CertificateSigningRequestSpec.Builder clearExpirationSeconds()
expirationSeconds is the requested duration of validity of the issued
certificate. The certificate signer may issue a certificate with a different
validity duration so a client must check the delta between the notBefore and
and notAfter fields in the issued certificate to determine the actual duration.
The v1.22+ in-tree implementations of the well-known Kubernetes signers will
honor this field as long as the requested duration is not greater than the
maximum duration they will honor per the --cluster-signing-duration CLI
flag to the Kubernetes controller manager.
Certificate signers may not honor this field for various reasons:
1. Old signer that is unaware of the field (such as the in-tree
implementations prior to v1.22)
2. Signer whose configured maximum is shorter than the requested duration
3. Signer whose configured minimum is longer than the requested duration
The minimum valid value for expirationSeconds is 600, i.e. 10 minutes.
As of v1.22, this field is beta and is controlled via the CSRDuration feature gate.
+optional
optional int32 expirationSeconds = 8;public com.google.protobuf.ProtocolStringList getUsagesList()
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;getUsagesList in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic int getUsagesCount()
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;getUsagesCount in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic String getUsages(int index)
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;getUsages in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic com.google.protobuf.ByteString getUsagesBytes(int index)
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;getUsagesBytes in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setUsages(int index, String value)
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;public V1Certificates.CertificateSigningRequestSpec.Builder addUsages(String value)
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;public V1Certificates.CertificateSigningRequestSpec.Builder addAllUsages(Iterable<String> values)
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;public V1Certificates.CertificateSigningRequestSpec.Builder clearUsages()
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;public V1Certificates.CertificateSigningRequestSpec.Builder addUsagesBytes(com.google.protobuf.ByteString value)
usages specifies a set of key usages requested in the issued certificate. Requests for TLS client certificates typically request: "digital signature", "key encipherment", "client auth". Requests for TLS serving certificates typically request: "key encipherment", "digital signature", "server auth". Valid values are: "signing", "digital signature", "content commitment", "key encipherment", "key agreement", "data encipherment", "cert sign", "crl sign", "encipher only", "decipher only", "any", "server auth", "client auth", "code signing", "email protection", "s/mime", "ipsec end system", "ipsec tunnel", "ipsec user", "timestamping", "ocsp signing", "microsoft sgc", "netscape sgc" +listType=atomic
repeated string usages = 5;public boolean hasUsername()
username contains the name of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string username = 2;hasUsername in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic String getUsername()
username contains the name of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string username = 2;getUsername in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic com.google.protobuf.ByteString getUsernameBytes()
username contains the name of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string username = 2;getUsernameBytes in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setUsername(String value)
username contains the name of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string username = 2;public V1Certificates.CertificateSigningRequestSpec.Builder clearUsername()
username contains the name of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string username = 2;public V1Certificates.CertificateSigningRequestSpec.Builder setUsernameBytes(com.google.protobuf.ByteString value)
username contains the name of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string username = 2;public boolean hasUid()
uid contains the uid of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string uid = 3;hasUid in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic String getUid()
uid contains the uid of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string uid = 3;getUid in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic com.google.protobuf.ByteString getUidBytes()
uid contains the uid of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string uid = 3;getUidBytes in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setUid(String value)
uid contains the uid of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string uid = 3;public V1Certificates.CertificateSigningRequestSpec.Builder clearUid()
uid contains the uid of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string uid = 3;public V1Certificates.CertificateSigningRequestSpec.Builder setUidBytes(com.google.protobuf.ByteString value)
uid contains the uid of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
optional string uid = 3;public com.google.protobuf.ProtocolStringList getGroupsList()
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;getGroupsList in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic int getGroupsCount()
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;getGroupsCount in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic String getGroups(int index)
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;getGroups in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic com.google.protobuf.ByteString getGroupsBytes(int index)
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;getGroupsBytes in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder setGroups(int index, String value)
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;public V1Certificates.CertificateSigningRequestSpec.Builder addGroups(String value)
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;public V1Certificates.CertificateSigningRequestSpec.Builder addAllGroups(Iterable<String> values)
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;public V1Certificates.CertificateSigningRequestSpec.Builder clearGroups()
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;public V1Certificates.CertificateSigningRequestSpec.Builder addGroupsBytes(com.google.protobuf.ByteString value)
groups contains group membership of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +listType=atomic +optional
repeated string groups = 4;public int getExtraCount()
V1Certificates.CertificateSigningRequestSpecOrBuilderextra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;getExtraCount in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic boolean containsExtra(String key)
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;containsExtra in interface V1Certificates.CertificateSigningRequestSpecOrBuilder@Deprecated public Map<String,V1Certificates.ExtraValue> getExtra()
getExtraMap() instead.getExtra in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic Map<String,V1Certificates.ExtraValue> getExtraMap()
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;getExtraMap in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.ExtraValue getExtraOrDefault(String key, V1Certificates.ExtraValue defaultValue)
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;getExtraOrDefault in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.ExtraValue getExtraOrThrow(String key)
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;getExtraOrThrow in interface V1Certificates.CertificateSigningRequestSpecOrBuilderpublic V1Certificates.CertificateSigningRequestSpec.Builder clearExtra()
public V1Certificates.CertificateSigningRequestSpec.Builder removeExtra(String key)
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;@Deprecated public Map<String,V1Certificates.ExtraValue> getMutableExtra()
public V1Certificates.CertificateSigningRequestSpec.Builder putExtra(String key, V1Certificates.ExtraValue value)
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;public V1Certificates.CertificateSigningRequestSpec.Builder putAllExtra(Map<String,V1Certificates.ExtraValue> values)
extra contains extra attributes of the user that created the CertificateSigningRequest. Populated by the API server on creation and immutable. +optional
map<string, .k8s.io.api.certificates.v1.ExtraValue> extra = 6;public final V1Certificates.CertificateSigningRequestSpec.Builder setUnknownFields(com.google.protobuf.UnknownFieldSet unknownFields)
setUnknownFields in interface com.google.protobuf.Message.BuildersetUnknownFields in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>public final V1Certificates.CertificateSigningRequestSpec.Builder mergeUnknownFields(com.google.protobuf.UnknownFieldSet unknownFields)
mergeUnknownFields in interface com.google.protobuf.Message.BuildermergeUnknownFields in class com.google.protobuf.GeneratedMessageV3.Builder<V1Certificates.CertificateSigningRequestSpec.Builder>Copyright © 2023. All rights reserved.