CSR API isn't guaranteed to use the cluster CA. The CA used to sign certs using the CSR API depends on the specific cluster stup. Admins can use a separate CA if they choose to. Users shouldn't rely on verifying those certs using the CA bundle mounted with service account secrets. The doc page is reworded to remove most mentions of cluster CA and instead focus on API usage specifics. |
||
---|---|---|
.. | ||
_index.md | ||
certificate-rotation.md | ||
managing-tls-in-a-cluster.md |