Kubetier
← Permission Reference
T2

sign signers

Writing a signed certificate into a CSR's status for a named signer requires this permission.

Without it, update on certificatesigningrequests/status fails with "not permitted to sign requests".

It is inert alone, since it does not confer the signer's CA key.

Requires these verbs, still T2:

Certificate bytes published for a named signer, without that signer's CA key

The pair permits the write.

Issuing a certificate that authenticates still requires the named signer's actual private key, normally held only by the built-in signing controller.

API Group
certificates.k8s.io
Scope
cluster
Audit Level
RequestResponse
K8s docs ↗