← Permission Reference
T2
sign signers
Writing a signed certificate into a CSR's status for a named signer requires this permission.
Without it, update on certificatesigningrequests/status fails with "not permitted to sign requests".
It is inert alone, since it does not confer the signer's CA key.
Requires these verbs, still T2:
Certificate bytes published for a named signer, without that signer's CA key
The pair permits the write.
Issuing a certificate that authenticates still requires the named signer's actual private key, normally held only by the built-in signing controller.
- API Group
- certificates.k8s.io
- Scope
- cluster
- Audit Level
- RequestResponse
