← Permission Reference
T2
sign signers
Writing a signed certificate into a CSR's status for a named signer requires this permission.
Without it, update on certificatesigningrequests/status fails with "not permitted to sign requests".
It does nothing alone, since it does not hand over the signer's CA key.
Additional rights needed:
Certificate bytes published for a named signer, without that signer's CA key
The pair permits the write.
Issuing a certificate that authenticates still requires the named signer's actual private key, normally held only by the built-in signing controller.
- API Group
- certificates.k8s.io
- Scope
- cluster
- Audit Level
- RequestResponse

