Skip to content

Latest commit

 

History

History
24 lines (20 loc) · 2.56 KB

File metadata and controls

24 lines (20 loc) · 2.56 KB

GetKubeExecCreds

getKubeExecCreds is a command that gets credentials for authentication with Kubernetes cluster based on a PKI cert issuer.

Properties

Name Type Description Notes
alt_names str The Subject Alternative Names to be included in the PKI certificate (in a comma-separated list) (if CSR is supplied this flag is ignored and any DNS.* names are taken from it) [optional]
api_version str Client authentication API version [optional] [default to 'v1']
cert_issuer_name str The name of the PKI certificate issuer
common_name str The common name to be included in the PKI certificate (if CSR is supplied this flag is ignored and the CSR subject CN is taken) [optional]
csr_data_base64 str Certificate Signing Request contents encoded in base64 to generate the certificate with [optional]
extended_key_usage str A comma-separated list of extended key usage requests which will be used for certificate issuance. Supported values: 'clientauth', 'serverauth', 'codesigning'. If critical is present the extension will be marked as critical [optional]
extra_extensions str A json string that defines the requested extra extensions for the certificate [optional]
json bool Set output format to JSON [optional] [default to False]
key_data_base64 str PKI key file contents. If this option is used, the certificate will be printed to stdout [optional]
max_path_len int The maximum path length for the generated certificate. -1, means unlimited unless the signing certificate has a maximum path length set [optional] [default to -1]
token str Authentication token (see `/auth` and `/configure`) [optional]
ttl str Updated certificate lifetime in seconds (must be less than the Certificate Issuer default TTL). Ignored for Let's Encrypt public CA issuers, which always use the CA default lifetime (about 90 days). [optional]
uid_token str The universal identity token, Required only for universal_identity authentication [optional]
uri_sans str The URI Subject Alternative Names to be included in the PKI certificate (in a comma-separated list) (if CSR is supplied this flag is ignored and any URI.* names are taken from it) [optional]

[Back to Model list] [Back to API list] [Back to README]