/
githubmirror
/
origin
Обзор
Документация
Войти
/
githubmirror
/
origin
Код
Запросы
0
Пакеты
0
Релизы
0
Аналитика
Безопасность
main
tls/testcase/testcase.json
6 081 строка
322 KB
Vadim Rutkovsky
TLS registry update for August 2025
14 авг 2025, 12:32
14 авг 2025, 12:32
e585c03
Код
Авторство
О чём код?
{ "certificateAuthorityBundles": [ { "InClusterLocation": { "configMapLocation": { "Namespace": "kube-system", "Name": "extension-apiserver-authentication" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-apiserver", "Name": "etcd-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-apiserver", "Name": "image-import-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "openshift-apiserver" } ], "owningJiraComponent": "openshift-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-apiserver", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-apiserver-operator", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-authentication", "Name": "v4-0-config-system-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-authentication-operator", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-catalogd", "Name": "catalogd-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cloud-controller-manager", "Name": "ccm-trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Cloud Compute / Cloud Controller Manager" } ], "owningJiraComponent": "Cloud Compute / Cloud Controller Manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cloud-credential-operator", "Name": "cco-trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cloud-network-config-controller", "Name": "trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "aws-ebs-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "azure-disk-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "azure-file-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "gcp-pd-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "openstack-cinder-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "vmware-vsphere-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "vsphere-csi-driver-operator-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-node-tuning-operator", "Name": "trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-cluster-storage-operator", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config", "Name": "admin-kubeconfig-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "openshift.io/description", "value": "CA for kube-apiserver to recognize the system:master created by the installer." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for kube-apiserver to recognize the system:master created by the installer." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config", "Name": "etcd-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config", "Name": "etcd-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config", "Name": "initial-kube-apiserver-server-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Machine Config Operator" } ], "owningJiraComponent": "Machine Config Operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config", "Name": "user-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "End User" } ], "owningJiraComponent": "End User", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "csr-controller-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" }, { "key": "openshift.io/description", "value": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } ], "owningJiraComponent": "kube-controller-manager", "description": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "default-ingress-cert" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "image-registry-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Image Registry" } ], "owningJiraComponent": "Image Registry", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "kube-apiserver-aggregator-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] oc adm new-project [apigroup:project.openshift.io][apigroup:authorization.openshift.io] [Suite:openshift/conformance/parallel]'" }, { "key": "openshift.io/description", "value": "CA for aggregated apiservers to recognize kube-apiserver as front-proxy." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for aggregated apiservers to recognize kube-apiserver as front-proxy." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "kube-apiserver-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "kube-apiserver-server-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "kubelet-bootstrap-kubeconfig" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "kubelet-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" }, { "key": "openshift.io/description", "value": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } ], "owningJiraComponent": "kube-controller-manager", "description": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "merged-trusted-image-registry-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Machine Config Operator" } ], "owningJiraComponent": "Machine Config Operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "oauth-serving-cert" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "apiserver-auth" } ], "owningJiraComponent": "apiserver-auth", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "service-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Service CA configmap contains the data for the PEM-encoded CA signing bundle which will be injected to resources annotated with 'service.beta.openshift.io/inject-cabundle=true'" } ], "owningJiraComponent": "service-ca", "description": "Service CA configmap contains the data for the PEM-encoded CA signing bundle which will be injected to resources annotated with 'service.beta.openshift.io/inject-cabundle=true'" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-config-managed", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-console", "Name": "default-ingress-cert" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-console", "Name": "oauth-serving-cert" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "apiserver-auth" } ], "owningJiraComponent": "apiserver-auth", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-console", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-console-operator", "Name": "trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-controller-manager", "Name": "client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-controller-manager", "Name": "openshift-global-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-etcd", "Name": "etcd-all-bundles" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Etcd" } ], "owningJiraComponent": "Etcd", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-etcd", "Name": "etcd-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-etcd", "Name": "etcd-metrics-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate Prometheus ServiceMonitors reaching etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate Prometheus ServiceMonitors reaching etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-etcd-operator", "Name": "etcd-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-etcd-operator", "Name": "etcd-metric-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate Prometheus ServiceMonitors reaching etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate Prometheus ServiceMonitors reaching etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-image-registry", "Name": "image-registry-certificates" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Image Registry" } ], "owningJiraComponent": "Image Registry", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-image-registry", "Name": "trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-ingress-operator", "Name": "trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-insights", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver", "Name": "aggregator-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] oc adm new-project [apigroup:project.openshift.io][apigroup:authorization.openshift.io] [Suite:openshift/conformance/parallel]'" }, { "key": "openshift.io/description", "value": "CA for aggregated apiservers to recognize kube-apiserver as front-proxy." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for aggregated apiservers to recognize kube-apiserver as front-proxy." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver", "Name": "client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver", "Name": "etcd-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver", "Name": "kube-apiserver-server-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver", "Name": "kubelet-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" }, { "key": "openshift.io/description", "value": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } ], "owningJiraComponent": "kube-controller-manager", "description": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" }, { "key": "openshift.io/description", "value": "CA used to recognize proxy servers. By default this will contain standard root CAs on the cluster-network-operator pod." } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "CA used to recognize proxy servers. By default this will contain standard root CAs on the cluster-network-operator pod." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "kube-apiserver-to-kubelet-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] Kubectl logs logs should be able to retrieve and filter logs [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "openshift.io/description", "value": "CA for the kubelet to recognize the kube-apiserver client certificate." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for the kubelet to recognize the kube-apiserver client certificate." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "kube-control-plane-signer-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "openshift.io/description", "value": "CA for kube-apiserver to recognize the kube-controller-manager and kube-scheduler client certificates." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for kube-apiserver to recognize the kube-controller-manager and kube-scheduler client certificates." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "loadbalancer-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] kube-apiserver should be accessible via api-int endpoint [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "CA for recognizing the kube-apiserver when connecting via the internal or external load balancers." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for recognizing the kube-apiserver when connecting via the internal or external load balancers." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "localhost-recovery-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost-recovery.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "CA for recognizing the kube-apiserver when connecting via the localhost recovery SNI ServerName." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for recognizing the kube-apiserver when connecting via the localhost recovery SNI ServerName." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "localhost-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "CA for recognizing the kube-apiserver when connecting via localhost." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for recognizing the kube-apiserver when connecting via localhost." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "node-system-admin-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost-recovery.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "CA for kube-apiserver to recognize local system:masters rendered to each master." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for kube-apiserver to recognize local system:masters rendered to each master." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "service-network-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] kube-apiserver should be accessible via service network endpoint [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "CA for recognizing the kube-apiserver when connecting via the service network (kuberentes.default.svc)." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for recognizing the kube-apiserver when connecting via the service network (kuberentes.default.svc)." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "aggregator-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] oc adm new-project [apigroup:project.openshift.io][apigroup:authorization.openshift.io] [Suite:openshift/conformance/parallel]'" }, { "key": "openshift.io/description", "value": "CA for aggregated apiservers to recognize kube-apiserver as front-proxy." } ], "owningJiraComponent": "kube-apiserver", "description": "CA for aggregated apiservers to recognize kube-apiserver as front-proxy." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "service-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Service CA configmap contains the data for the PEM-encoded CA signing bundle which will be injected to resources annotated with 'service.beta.openshift.io/inject-cabundle=true'" } ], "owningJiraComponent": "service-ca", "description": "Service CA configmap contains the data for the PEM-encoded CA signing bundle which will be injected to resources annotated with 'service.beta.openshift.io/inject-cabundle=true'" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "serviceaccount-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" } ], "owningJiraComponent": "kube-controller-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager-operator", "Name": "csr-controller-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" }, { "key": "openshift.io/description", "value": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } ], "owningJiraComponent": "kube-controller-manager", "description": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager-operator", "Name": "csr-controller-signer-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" } ], "owningJiraComponent": "kube-controller-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-controller-manager-operator", "Name": "csr-signer-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" } ], "owningJiraComponent": "kube-controller-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-kube-scheduler", "Name": "serviceaccount-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-scheduler" } ], "owningJiraComponent": "kube-scheduler", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-machine-api", "Name": "cbo-trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-machine-api", "Name": "mao-trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-machine-config-operator", "Name": "machine-config-server-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Machine Config Operator" }, { "key": "openshift.io/description", "value": "CA bundle that stores all valid CAs for the MachineConfigServer TLS certificate" } ], "owningJiraComponent": "Machine Config Operator", "description": "CA bundle that stores all valid CAs for the MachineConfigServer TLS certificate" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-manila-csi-driver", "Name": "manila-csi-driver-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-marketplace", "Name": "marketplace-trusted-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-monitoring", "Name": "alertmanager-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-monitoring", "Name": "kubelet-serving-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-monitoring", "Name": "metrics-client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-monitoring", "Name": "prometheus-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-monitoring", "Name": "telemeter-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-network-node-identity", "Name": "network-node-identity-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-oauth-apiserver", "Name": "etcd-serving-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to authenticate clients and peers of etcd." } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-operator-controller", "Name": "operator-controller-trusted-ca-bundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "ovn-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "signer-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-route-controller-manager", "Name": "client-ca" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "configMapLocation": { "Namespace": "openshift-service-ca", "Name": "signing-cabundle" }, "certificateAuthorityBundleInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Service CA configmap contains the data for the PEM-encoded CA signing bundle which will be injected to resources annotated with 'service.beta.openshift.io/inject-cabundle=true'" } ], "owningJiraComponent": "service-ca", "description": "Service CA configmap contains the data for the PEM-encoded CA signing bundle which will be injected to resources annotated with 'service.beta.openshift.io/inject-cabundle=true'" } }, "OnDiskLocation": null }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/docker/certs.d/image-registry.openshift-image-registry.svc.cluster.local:5000/ca.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "Image Registry", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/docker/certs.d/image-registry.openshift-image-registry.svc:5000/ca.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "Image Registry", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/ca.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "Machine Config Operator", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/cni/net.d/whereabouts.d/whereabouts.kubeconfig" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "cluster-network-operator", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/kubeconfig" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "kube-apiserver", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/static-pod-resources/kube-apiserver-certs/configmaps/trusted-ca-bundle/ca-bundle.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "kube-apiserver", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/static-pod-resources/kube-controller-manager-certs/configmaps/trusted-ca-bundle/ca-bundle.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "kube-controller-manager", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/static-pod-resources/kube-controller-manager-certs/secrets/csr-signer/tls.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "kube-controller-manager", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/pki/tls/cert.pem" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "RHCOS", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/pki/tls/certs/ca-bundle.crt" }, "certificateAuthorityBundleInfo": { "owningJiraComponent": "RHCOS", "description": "" } } } ], "certKeyPairs": [ { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-apiserver", "Name": "etcd-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-apiserver", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/api with hostname api.openshift-apiserver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/api with hostname api.openshift-apiserver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-apiserver-operator", "Name": "openshift-apiserver-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-apiserver-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-apiserver-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-apiserver-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-apiserver-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-authentication", "Name": "v4-0-config-system-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/oauth-openshift with hostname oauth-openshift.openshift-authentication.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: v4-0-config-system-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/oauth-openshift with hostname oauth-openshift.openshift-authentication.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: v4-0-config-system-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-authentication-operator", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-authentication-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-authentication-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-catalogd", "Name": "catalogserver-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/catalogd-service with hostname catalogd-service.openshift-catalogd.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: catalogserver-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/catalogd-service with hostname catalogd-service.openshift-catalogd.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: catalogserver-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cloud-controller-manager-operator", "Name": "cloud-controller-manager-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cloud-controller-manager-operator with hostname cloud-controller-manager-operator.openshift-cloud-controller-manager-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cloud-controller-manager-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cloud-controller-manager-operator with hostname cloud-controller-manager-operator.openshift-cloud-controller-manager-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cloud-controller-manager-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cloud-credential-operator", "Name": "cloud-credential-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cco-metrics with hostname cco-metrics.openshift-cloud-credential-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cloud-credential-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cco-metrics with hostname cco-metrics.openshift-cloud-credential-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cloud-credential-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cloud-credential-operator", "Name": "pod-identity-webhook" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/pod-identity-webhook with hostname pod-identity-webhook.openshift-cloud-credential-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: pod-identity-webhook'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/pod-identity-webhook with hostname pod-identity-webhook.openshift-cloud-credential-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: pod-identity-webhook'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "capa-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capa-webhook-service with hostname capa-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capa-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capa-webhook-service with hostname capa-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capa-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "capg-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capg-webhook-service with hostname capg-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capg-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capg-webhook-service with hostname capg-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capg-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "capi-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capi-webhook-service with hostname capi-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capi-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capi-webhook-service with hostname capi-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capi-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "capm3-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capm3-webhook-service with hostname capm3-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capm3-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capm3-webhook-service with hostname capm3-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capm3-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "capv-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capv-webhook-service with hostname capv-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capv-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capv-webhook-service with hostname capv-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capv-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "capz-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capz-webhook-service with hostname capz-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capz-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/capz-webhook-service with hostname capz-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: capz-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "cluster-capi-operator-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-capi-operator-webhook-service with hostname cluster-capi-operator-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-capi-operator-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-capi-operator-webhook-service with hostname cluster-capi-operator-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-capi-operator-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-api", "Name": "ipam-webhook-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ipam-webhook-service with hostname ipam-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: ipam-webhook-service-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ipam-webhook-service with hostname ipam-webhook-service.openshift-cluster-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: ipam-webhook-service-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "aws-ebs-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/aws-ebs-csi-driver-controller-metrics with hostname aws-ebs-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: aws-ebs-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/aws-ebs-csi-driver-controller-metrics with hostname aws-ebs-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: aws-ebs-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "azure-disk-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/azure-disk-csi-driver-controller-metrics with hostname azure-disk-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: azure-disk-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/azure-disk-csi-driver-controller-metrics with hostname azure-disk-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: azure-disk-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "azure-disk-csi-driver-node-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/azure-disk-csi-driver-node-metrics with hostname azure-disk-csi-driver-node-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: azure-disk-csi-driver-node-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/azure-disk-csi-driver-node-metrics with hostname azure-disk-csi-driver-node-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: azure-disk-csi-driver-node-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "azure-file-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/azure-file-csi-driver-controller-metrics with hostname azure-file-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: azure-file-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/azure-file-csi-driver-controller-metrics with hostname azure-file-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: azure-file-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "gcp-pd-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/gcp-pd-csi-driver-controller-metrics with hostname gcp-pd-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: gcp-pd-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/gcp-pd-csi-driver-controller-metrics with hostname gcp-pd-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: gcp-pd-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "openstack-cinder-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/openstack-cinder-csi-driver-controller-metrics with hostname openstack-cinder-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openstack-cinder-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/openstack-cinder-csi-driver-controller-metrics with hostname openstack-cinder-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openstack-cinder-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "vmware-vsphere-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vmware-vsphere-csi-driver-controller-metrics with hostname vmware-vsphere-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vmware-vsphere-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vmware-vsphere-csi-driver-controller-metrics with hostname vmware-vsphere-csi-driver-controller-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vmware-vsphere-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "vmware-vsphere-csi-driver-operator-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vmware-vsphere-csi-driver-operator-metrics with hostname vmware-vsphere-csi-driver-operator-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vmware-vsphere-csi-driver-operator-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vmware-vsphere-csi-driver-operator-metrics with hostname vmware-vsphere-csi-driver-operator-metrics.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vmware-vsphere-csi-driver-operator-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-csi-drivers", "Name": "vmware-vsphere-csi-driver-webhook-secret" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vmware-vsphere-csi-driver-webhook-svc with hostname vmware-vsphere-csi-driver-webhook-svc.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vmware-vsphere-csi-driver-webhook-secret'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vmware-vsphere-csi-driver-webhook-svc with hostname vmware-vsphere-csi-driver-webhook-svc.openshift-cluster-csi-drivers.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vmware-vsphere-csi-driver-webhook-secret'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-machine-approver", "Name": "machine-approver-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-approver with hostname machine-approver.openshift-cluster-machine-approver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-approver-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-approver with hostname machine-approver.openshift-cluster-machine-approver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-approver-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-node-tuning-operator", "Name": "node-tuning-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/node-tuning-operator with hostname node-tuning-operator.openshift-cluster-node-tuning-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: node-tuning-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/node-tuning-operator with hostname node-tuning-operator.openshift-cluster-node-tuning-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: node-tuning-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-node-tuning-operator", "Name": "performance-addon-operator-webhook-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/performance-addon-operator-service with hostname performance-addon-operator-service.openshift-cluster-node-tuning-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: performance-addon-operator-webhook-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/performance-addon-operator-service with hostname performance-addon-operator-service.openshift-cluster-node-tuning-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: performance-addon-operator-webhook-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-olm-operator", "Name": "cluster-olm-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-olm-operator-metrics with hostname cluster-olm-operator-metrics.openshift-cluster-olm-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-olm-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-olm-operator-metrics with hostname cluster-olm-operator-metrics.openshift-cluster-olm-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-olm-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-samples-operator", "Name": "samples-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-cluster-samples-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: samples-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-cluster-samples-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: samples-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-storage-operator", "Name": "cluster-storage-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-storage-operator-metrics with hostname cluster-storage-operator-metrics.openshift-cluster-storage-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-storage-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-storage-operator-metrics with hostname cluster-storage-operator-metrics.openshift-cluster-storage-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-storage-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-storage-operator", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/csi-snapshot-controller-operator-metrics with hostname csi-snapshot-controller-operator-metrics.openshift-cluster-storage-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/csi-snapshot-controller-operator-metrics with hostname csi-snapshot-controller-operator-metrics.openshift-cluster-storage-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-storage-operator", "Name": "vsphere-problem-detector-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vsphere-problem-detector-metrics with hostname vsphere-problem-detector-metrics.openshift-cluster-storage-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vsphere-problem-detector-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/vsphere-problem-detector-metrics with hostname vsphere-problem-detector-metrics.openshift-cluster-storage-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: vsphere-problem-detector-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-cluster-version", "Name": "cluster-version-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-version-operator with hostname cluster-version-operator.openshift-cluster-version.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-version-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-version-operator with hostname cluster-version-operator.openshift-cluster-version.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-version-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-config", "Name": "etcd-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-config", "Name": "webhook-authentication-integrated-oauth" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "apiserver-auth" } ], "owningJiraComponent": "apiserver-auth", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-config-managed", "Name": "kube-controller-manager-client-cert-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the kube-controller-manager to authenticate to the kube-apiserver." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the kube-controller-manager to authenticate to the kube-apiserver." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-config-managed", "Name": "kube-scheduler-client-cert-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the kube-scheduler to authenticate to the kube-apiserver." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the kube-scheduler to authenticate to the kube-apiserver." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-config-operator", "Name": "config-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: config-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: config-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-console", "Name": "console-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/console with hostname console.openshift-console.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: console-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/console with hostname console.openshift-console.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: console-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-console-operator", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-console-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-console-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-controller-manager", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/controller-manager with hostname controller-manager.openshift-controller-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/controller-manager with hostname controller-manager.openshift-controller-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-controller-manager-operator", "Name": "openshift-controller-manager-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-controller-manager-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-controller-manager-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-controller-manager-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-controller-manager-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-dns", "Name": "dns-default-metrics-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/dns-default with hostname dns-default.openshift-dns.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: dns-default-metrics-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/dns-default with hostname dns-default.openshift-dns.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: dns-default-metrics-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-dns-operator", "Name": "metrics-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-dns-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-dns-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-e2e-loki", "Name": "proxy-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/promtail with hostname promtail.openshift-e2e-loki.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: proxy-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/promtail with hostname promtail.openshift-e2e-loki.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: proxy-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-metric-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for Prometheus ServiceMonitors to reach etcd grpc-proxy to retrieve metrics. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for Prometheus ServiceMonitors to reach etcd grpc-proxy to retrieve metrics. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-metric-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to sign peer, server and client certificates for Prometheus ServiceMonitors. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to sign peer, server and client certificates for Prometheus ServiceMonitors. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-peer-2r9n12ip-92bf1-s62z8bootstrap" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Peer (client and server) certificate for node 2r9n12ip-92bf1-s62z8bootstrap, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Peer (client and server) certificate for node 2r9n12ip-92bf1-s62z8bootstrap, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-peer-\u003cbootstrap\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Peer (client and server) certificate for node \u003cbootstrap\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Peer (client and server) certificate for node \u003cbootstrap\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-peer-\u003cmaster-0\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Peer (client and server) certificate for node \u003cmaster-0\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Peer (client and server) certificate for node \u003cmaster-0\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-peer-\u003cmaster-1\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Peer (client and server) certificate for node \u003cmaster-1\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Peer (client and server) certificate for node \u003cmaster-1\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-peer-\u003cmaster-2\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Peer (client and server) certificate for node \u003cmaster-2\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Peer (client and server) certificate for node \u003cmaster-2\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-2r9n12ip-92bf1-s62z8bootstrap" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node 2r9n12ip-92bf1-s62z8bootstrap, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node 2r9n12ip-92bf1-s62z8bootstrap, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-\u003cbootstrap\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cbootstrap\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cbootstrap\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-\u003cmaster-0\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cmaster-0\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cmaster-0\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-\u003cmaster-1\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cmaster-1\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cmaster-1\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-\u003cmaster-2\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cmaster-2\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cmaster-2\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-metrics-2r9n12ip-92bf1-s62z8bootstrap" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node 2r9n12ip-92bf1-s62z8bootstrap, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node 2r9n12ip-92bf1-s62z8bootstrap, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-metrics-\u003cbootstrap\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cbootstrap\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cbootstrap\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-metrics-\u003cmaster-0\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cmaster-0\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cmaster-0\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-metrics-\u003cmaster-1\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cmaster-1\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cmaster-1\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-serving-metrics-\u003cmaster-2\u003e" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Serving (client and server) certificate for node \u003cmaster-2\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Serving (client and server) certificate for node \u003cmaster-2\u003e, generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "etcd-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Generated by cluster-etcd-operator for etcd and is used to sign peer, server and client certificates. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Generated by cluster-etcd-operator for etcd and is used to sign peer, server and client certificates. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/etcd with hostname etcd.openshift-etcd.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/etcd with hostname etcd.openshift-etcd.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd-operator", "Name": "etcd-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd-operator", "Name": "etcd-metric-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for Prometheus ServiceMonitors to reach etcd grpc-proxy to retrieve metrics. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for Prometheus ServiceMonitors to reach etcd grpc-proxy to retrieve metrics. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-etcd-operator", "Name": "etcd-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-etcd-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: etcd-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-etcd-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: etcd-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-image-registry", "Name": "image-registry-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/image-registry-operator with hostname image-registry-operator.openshift-image-registry.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: image-registry-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/image-registry-operator with hostname image-registry-operator.openshift-image-registry.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: image-registry-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-image-registry", "Name": "image-registry-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/image-registry with hostname image-registry.openshift-image-registry.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: image-registry-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/image-registry with hostname image-registry.openshift-image-registry.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: image-registry-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ingress", "Name": "router-certs-default" }, "certKeyInfo": { "owningJiraComponent": "", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ingress", "Name": "router-metrics-certs-default" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/router-internal-default with hostname router-internal-default.openshift-ingress.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: router-metrics-certs-default'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/router-internal-default with hostname router-internal-default.openshift-ingress.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: router-metrics-certs-default'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ingress-canary", "Name": "canary-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ingress-canary with hostname ingress-canary.openshift-ingress-canary.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: canary-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ingress-canary with hostname ingress-canary.openshift-ingress-canary.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: canary-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ingress-operator", "Name": "metrics-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-ingress-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-ingress-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ingress-operator", "Name": "router-ca" }, "certKeyInfo": { "owningJiraComponent": "", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-insights", "Name": "insights-runtime-extractor-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/exporter with hostname exporter.openshift-insights.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: insights-runtime-extractor-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/exporter with hostname exporter.openshift-insights.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: insights-runtime-extractor-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-insights", "Name": "openshift-insights-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-insights.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-insights-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-insights.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-insights-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "aggregator-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] oc adm new-project [apigroup:project.openshift.io][apigroup:authorization.openshift.io] [Suite:openshift/conformance/parallel]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the kube-apiserver to communicate to aggregated apiservers." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the kube-apiserver to communicate to aggregated apiservers." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "check-endpoints-client-cert-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"check-endpoints.kubeconfig\" should be present in all kube-apiserver containers [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the network connectivity checker of the kube-apiserver." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the network connectivity checker of the kube-apiserver." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "control-plane-node-admin-client-cert-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"control-plane-node.kubeconfig\" should be present in all kube-apiserver containers [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "etcd-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "external-loadbalancer-serving-certkey" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Serving certificate used by the kube-apiserver to terminate requests via the external load balancer." } ], "owningJiraComponent": "kube-apiserver", "description": "Serving certificate used by the kube-apiserver to terminate requests via the external load balancer." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "internal-loadbalancer-serving-certkey" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] kube-apiserver should be accessible via api-int endpoint [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Serving certificate used by the kube-apiserver to terminate requests via the internal load balancer." } ], "owningJiraComponent": "kube-apiserver", "description": "Serving certificate used by the kube-apiserver to terminate requests via the internal load balancer." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "kubelet-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] Kubectl logs logs should be able to retrieve and filter logs [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the kube-apiserver to authenticate to the kubelet for requests like exec and logs." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the kube-apiserver to authenticate to the kubelet for requests like exec and logs." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "localhost-recovery-serving-certkey" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost-recovery.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "70080h0m0s" }, { "key": "openshift.io/description", "value": "Serving certificate used by the kube-apiserver to terminate requests via the localhost recovery SNI ServerName." } ], "owningJiraComponent": "kube-apiserver", "description": "Serving certificate used by the kube-apiserver to terminate requests via the localhost recovery SNI ServerName." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "localhost-serving-cert-certkey" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Serving certificate used by the kube-apiserver to terminate requests via localhost." } ], "owningJiraComponent": "kube-apiserver", "description": "Serving certificate used by the kube-apiserver to terminate requests via localhost." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "node-kubeconfigs" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" } ], "owningJiraComponent": "kube-apiserver", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "service-network-serving-certkey" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] kube-apiserver should be accessible via service network endpoint [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Serving certificate used by the kube-apiserver to terminate requests via the service network." } ], "owningJiraComponent": "kube-apiserver", "description": "Serving certificate used by the kube-apiserver to terminate requests via the service network." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver", "Name": "webhook-authenticator" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "apiserver-auth" } ], "owningJiraComponent": "apiserver-auth", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "aggregator-client-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] oc adm new-project [apigroup:project.openshift.io][apigroup:authorization.openshift.io] [Suite:openshift/conformance/parallel]'" }, { "key": "openshift.io/description", "value": "Signer for the kube-apiserver to create client certificates for aggregated apiservers to recognize as a front-proxy" } ], "owningJiraComponent": "kube-apiserver", "description": "Signer for the kube-apiserver to create client certificates for aggregated apiservers to recognize as a front-proxy" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "kube-apiserver-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-apiserver-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-apiserver-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-apiserver-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-apiserver-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "kube-apiserver-to-kubelet-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-cli] Kubectl logs logs should be able to retrieve and filter logs [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "openshift.io/description", "value": "Signer for the kube-apiserver-to-kubelet-client so kubelets can recognize the kube-apiserver." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer for the kube-apiserver-to-kubelet-client so kubelets can recognize the kube-apiserver." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "kube-control-plane-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "openshift.io/description", "value": "Signer for kube-controller-manager and kube-scheduler client certificates." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer for kube-controller-manager and kube-scheduler client certificates." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "loadbalancer-serving-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] kube-apiserver should be accessible via api-int endpoint [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "Signer used by the kube-apiserver operator to create serving certificates for the kube-apiserver via internal and external load balancers." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer used by the kube-apiserver operator to create serving certificates for the kube-apiserver via internal and external load balancers." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "localhost-recovery-serving-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost-recovery.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "70080h0m0s" }, { "key": "openshift.io/description", "value": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via the service network." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via the service network." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "localhost-serving-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via localhost." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via localhost." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "node-system-admin-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost-recovery.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "12h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate (system:masters) placed on each master to allow communication to kube-apiserver for debugging." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate (system:masters) placed on each master to allow communication to kube-apiserver for debugging." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "node-system-admin-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig \"localhost-recovery.kubeconfig\" should be present on all masters and work [apigroup:config.openshift.io] [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "21024h0m0s" }, { "key": "openshift.io/description", "value": "Signer for the per-master-debugging-client." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer for the per-master-debugging-client." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-apiserver-operator", "Name": "service-network-serving-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[Conformance][sig-api-machinery][Feature:APIServer] kube-apiserver should be accessible via service network endpoint [Suite:openshift/conformance/parallel/minimal]'" }, { "key": "openshift.io/description", "value": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via the service network." } ], "owningJiraComponent": "kube-apiserver", "description": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via the service network." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "csr-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" } ], "owningJiraComponent": "kube-controller-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "kube-controller-manager-client-cert-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the kube-controller-manager to authenticate to the kube-apiserver." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the kube-controller-manager to authenticate to the kube-apiserver." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-controller-manager", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/kube-controller-manager with hostname kube-controller-manager.openshift-kube-controller-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/kube-controller-manager with hostname kube-controller-manager.openshift-kube-controller-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-controller-manager-operator", "Name": "csr-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" } ], "owningJiraComponent": "kube-controller-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-controller-manager-operator", "Name": "csr-signer-signer" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-controller-manager" } ], "owningJiraComponent": "kube-controller-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-controller-manager-operator", "Name": "kube-controller-manager-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-controller-manager-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-controller-manager-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-controller-manager-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-controller-manager-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-scheduler", "Name": "kube-scheduler-client-cert-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "kube-apiserver" }, { "key": "certificates.openshift.io/auto-regenerate-after-offline-expiry", "value": "https://github.com/openshift/cluster-kube-apiserver-operator/pull/1631,'[sig-apps] Deployment RollingUpdateDeployment should delete old pods and create new ones [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]'" }, { "key": "certificates.openshift.io/refresh-period", "value": "6h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate used by the kube-scheduler to authenticate to the kube-apiserver." } ], "owningJiraComponent": "kube-apiserver", "description": "Client certificate used by the kube-scheduler to authenticate to the kube-apiserver." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-scheduler", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/scheduler with hostname scheduler.openshift-kube-scheduler.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/scheduler with hostname scheduler.openshift-kube-scheduler.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-scheduler-operator", "Name": "kube-scheduler-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-scheduler-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-scheduler-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-scheduler-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-scheduler-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-kube-storage-version-migrator-operator", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-storage-version-migrator-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-kube-storage-version-migrator-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "baremetal-operator-webhook-server-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/baremetal-operator-webhook-service with hostname baremetal-operator-webhook-service.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: baremetal-operator-webhook-server-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/baremetal-operator-webhook-service with hostname baremetal-operator-webhook-service.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: baremetal-operator-webhook-server-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "cluster-autoscaler-operator-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-autoscaler-operator with hostname cluster-autoscaler-operator.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-autoscaler-operator-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-autoscaler-operator with hostname cluster-autoscaler-operator.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-autoscaler-operator-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "cluster-baremetal-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-baremetal-operator-service with hostname cluster-baremetal-operator-service.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-baremetal-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-baremetal-operator-service with hostname cluster-baremetal-operator-service.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-baremetal-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "cluster-baremetal-webhook-server-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-baremetal-webhook-service with hostname cluster-baremetal-webhook-service.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-baremetal-webhook-server-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-baremetal-webhook-service with hostname cluster-baremetal-webhook-service.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-baremetal-webhook-server-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "control-plane-machine-set-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/control-plane-machine-set-operator with hostname control-plane-machine-set-operator.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: control-plane-machine-set-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/control-plane-machine-set-operator with hostname control-plane-machine-set-operator.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: control-plane-machine-set-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "machine-api-controllers-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-controllers with hostname machine-api-controllers.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-controllers-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-controllers with hostname machine-api-controllers.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-controllers-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "machine-api-operator-machine-webhook-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-operator-machine-webhook with hostname machine-api-operator-machine-webhook.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-operator-machine-webhook-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-operator-machine-webhook with hostname machine-api-operator-machine-webhook.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-operator-machine-webhook-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "machine-api-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-operator with hostname machine-api-operator.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-operator with hostname machine-api-operator.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "machine-api-operator-webhook-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-operator-webhook with hostname machine-api-operator-webhook.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-operator-webhook-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-api-operator-webhook with hostname machine-api-operator-webhook.openshift-machine-api.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: machine-api-operator-webhook-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-api", "Name": "metal3-ironic-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Bare Metal Hardware Provisioning / cluster-baremetal-operator" } ], "owningJiraComponent": "Bare Metal Hardware Provisioning / cluster-baremetal-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-config-operator", "Name": "machine-config-server-ca" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Machine Config Operator" }, { "key": "openshift.io/description", "value": "CA used to sign the MachineConfigServer TLS certificate" } ], "owningJiraComponent": "Machine Config Operator", "description": "CA used to sign the MachineConfigServer TLS certificate" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-config-operator", "Name": "machine-config-server-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Machine Config Operator" }, { "key": "openshift.io/description", "value": "Secret containing the MachineConfigServer TLS certificate and key" } ], "owningJiraComponent": "Machine Config Operator", "description": "Secret containing the MachineConfigServer TLS certificate and key" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-config-operator", "Name": "mcc-proxy-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-config-controller with hostname machine-config-controller.openshift-machine-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: mcc-proxy-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-config-controller with hostname machine-config-controller.openshift-machine-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: mcc-proxy-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-config-operator", "Name": "mco-proxy-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-config-operator with hostname machine-config-operator.openshift-machine-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: mco-proxy-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-config-operator with hostname machine-config-operator.openshift-machine-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: mco-proxy-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-machine-config-operator", "Name": "proxy-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-config-daemon with hostname machine-config-daemon.openshift-machine-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: proxy-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/machine-config-daemon with hostname machine-config-daemon.openshift-machine-config-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: proxy-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-manila-csi-driver", "Name": "manila-csi-driver-controller-metrics-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/manila-csi-driver-controller-metrics with hostname manila-csi-driver-controller-metrics.openshift-manila-csi-driver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: manila-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/manila-csi-driver-controller-metrics with hostname manila-csi-driver-controller-metrics.openshift-manila-csi-driver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: manila-csi-driver-controller-metrics-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-marketplace", "Name": "marketplace-operator-metrics" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/marketplace-operator-metrics with hostname marketplace-operator-metrics.openshift-marketplace.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: marketplace-operator-metrics'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/marketplace-operator-metrics with hostname marketplace-operator-metrics.openshift-marketplace.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: marketplace-operator-metrics'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "alertmanager-main-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/alertmanager-main with hostname alertmanager-main.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: alertmanager-main-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/alertmanager-main with hostname alertmanager-main.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: alertmanager-main-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "cluster-monitoring-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-monitoring-operator with hostname cluster-monitoring-operator.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-monitoring-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/cluster-monitoring-operator with hostname cluster-monitoring-operator.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: cluster-monitoring-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "federate-client-certs" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "kube-state-metrics-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/kube-state-metrics with hostname kube-state-metrics.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-state-metrics-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/kube-state-metrics with hostname kube-state-metrics.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: kube-state-metrics-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "metrics-client-certs" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "metrics-server-client-certs" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Monitoring" } ], "owningJiraComponent": "Monitoring", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "metrics-server-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics-server with hostname metrics-server.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-server-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics-server with hostname metrics-server.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-server-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "monitoring-plugin-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/monitoring-plugin with hostname monitoring-plugin.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: monitoring-plugin-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/monitoring-plugin with hostname monitoring-plugin.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: monitoring-plugin-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "node-exporter-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/node-exporter with hostname node-exporter.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: node-exporter-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/node-exporter with hostname node-exporter.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: node-exporter-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "openshift-state-metrics-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/openshift-state-metrics with hostname openshift-state-metrics.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-state-metrics-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/openshift-state-metrics with hostname openshift-state-metrics.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: openshift-state-metrics-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "prometheus-k8s-thanos-sidecar-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-k8s-thanos-sidecar with hostname prometheus-k8s-thanos-sidecar.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-k8s-thanos-sidecar-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-k8s-thanos-sidecar with hostname prometheus-k8s-thanos-sidecar.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-k8s-thanos-sidecar-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "prometheus-k8s-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-k8s with hostname prometheus-k8s.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-k8s-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-k8s with hostname prometheus-k8s.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-k8s-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "prometheus-operator-admission-webhook-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-operator-admission-webhook with hostname prometheus-operator-admission-webhook.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-operator-admission-webhook-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-operator-admission-webhook with hostname prometheus-operator-admission-webhook.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-operator-admission-webhook-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "prometheus-operator-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-operator with hostname prometheus-operator.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-operator-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/prometheus-operator with hostname prometheus-operator.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: prometheus-operator-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "telemeter-client-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/telemeter-client with hostname telemeter-client.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: telemeter-client-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/telemeter-client with hostname telemeter-client.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: telemeter-client-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-monitoring", "Name": "thanos-querier-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/thanos-querier with hostname thanos-querier.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: thanos-querier-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/thanos-querier with hostname thanos-querier.openshift-monitoring.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: thanos-querier-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-multus", "Name": "metrics-daemon-secret" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/network-metrics-service with hostname network-metrics-service.openshift-multus.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-daemon-secret'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/network-metrics-service with hostname network-metrics-service.openshift-multus.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-daemon-secret'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-multus", "Name": "multus-admission-controller-secret" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/multus-admission-controller with hostname multus-admission-controller.openshift-multus.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: multus-admission-controller-secret'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/multus-admission-controller with hostname multus-admission-controller.openshift-multus.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: multus-admission-controller-secret'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-network-console", "Name": "networking-console-plugin-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/networking-console-plugin with hostname networking-console-plugin.openshift-network-console.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: networking-console-plugin-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/networking-console-plugin with hostname networking-console-plugin.openshift-network-console.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: networking-console-plugin-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-network-node-identity", "Name": "network-node-identity-ca" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-network-node-identity", "Name": "network-node-identity-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-network-operator", "Name": "metrics-tls" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-network-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-tls'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-network-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: metrics-tls'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-oauth-apiserver", "Name": "etcd-client" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "etcd" }, { "key": "certificates.openshift.io/refresh-period", "value": "36792h0m0s" }, { "key": "openshift.io/description", "value": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } ], "owningJiraComponent": "etcd", "description": "Client certificate for apiserver, cluster-etcd-operator and etcdctl to reach etcd. Generated by cluster-etcd-operator for etcd. This certificate is valid for 1825 days and starts refreshing after 1533 days." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-oauth-apiserver", "Name": "openshift-authenticator-certs" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "apiserver-auth" } ], "owningJiraComponent": "apiserver-auth", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-oauth-apiserver", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/api with hostname api.openshift-oauth-apiserver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/api with hostname api.openshift-oauth-apiserver.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-operator-controller", "Name": "operator-controller-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/operator-controller-service with hostname operator-controller-service.openshift-operator-controller.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: operator-controller-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/operator-controller-service with hostname operator-controller-service.openshift-operator-controller.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: operator-controller-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-operator-lifecycle-manager", "Name": "catalog-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/catalog-operator-metrics with hostname catalog-operator-metrics.openshift-operator-lifecycle-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: catalog-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/catalog-operator-metrics with hostname catalog-operator-metrics.openshift-operator-lifecycle-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: catalog-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-operator-lifecycle-manager", "Name": "olm-operator-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/olm-operator-metrics with hostname olm-operator-metrics.openshift-operator-lifecycle-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: olm-operator-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/olm-operator-metrics with hostname olm-operator-metrics.openshift-operator-lifecycle-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: olm-operator-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-operator-lifecycle-manager", "Name": "package-server-manager-serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/package-server-manager-metrics with hostname package-server-manager-metrics.openshift-operator-lifecycle-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: package-server-manager-serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/package-server-manager-metrics with hostname package-server-manager-metrics.openshift-operator-lifecycle-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: package-server-manager-serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-operator-lifecycle-manager", "Name": "packageserver-service-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Operator Framework / operator-lifecycle-manager" } ], "owningJiraComponent": "Operator Framework / operator-lifecycle-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-operator-lifecycle-manager", "Name": "pprof-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Operator Framework / operator-lifecycle-manager" } ], "owningJiraComponent": "Operator Framework / operator-lifecycle-manager", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "ovn-ca" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "ovn-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "ovn-control-plane-metrics-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ovn-kubernetes-control-plane with hostname ovn-kubernetes-control-plane.openshift-ovn-kubernetes.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: ovn-control-plane-metrics-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ovn-kubernetes-control-plane with hostname ovn-kubernetes-control-plane.openshift-ovn-kubernetes.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: ovn-control-plane-metrics-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "ovn-node-metrics-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ovn-kubernetes-node with hostname ovn-kubernetes-node.openshift-ovn-kubernetes.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: ovn-node-metrics-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/ovn-kubernetes-node with hostname ovn-kubernetes-node.openshift-ovn-kubernetes.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: ovn-node-metrics-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "signer-ca" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-ovn-kubernetes", "Name": "signer-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "Networking / cluster-network-operator" } ], "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-route-controller-manager", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/route-controller-manager with hostname route-controller-manager.openshift-route-controller-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/route-controller-manager with hostname route-controller-manager.openshift-route-controller-manager.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-service-ca", "Name": "signing-key" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Service CA secret contains a signing key that will be used to issue a signed serving certificate/key pair to services annotated with 'service.beta.openshift.io/serving-cert-secret-name'" } ], "owningJiraComponent": "service-ca", "description": "Service CA secret contains a signing key that will be used to issue a signed serving certificate/key pair to services annotated with 'service.beta.openshift.io/serving-cert-secret-name'" } }, "OnDiskLocation": null }, { "InClusterLocation": { "secretLocation": { "Namespace": "openshift-service-ca-operator", "Name": "serving-cert" }, "certKeyInfo": { "selectedCertMetadataAnnotations": [ { "key": "openshift.io/owning-component", "value": "service-ca" }, { "key": "openshift.io/description", "value": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-service-ca-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } ], "owningJiraComponent": "service-ca", "description": "Secret contains a pair signed serving certificate/key that is generated by Service CA operator for service/metrics with hostname metrics.openshift-service-ca-operator.svc and is annotated to the service with annotating a service resource with 'service.beta.openshift.io/serving-cert-secret-name: serving-cert'. The certificate is valid for 2 years." } }, "OnDiskLocation": null }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/cni/multus/certs/multus-client-\u003ctimestamp\u003e.pem" }, "certKeyInfo": { "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/kubeconfig" }, "certKeyInfo": { "owningJiraComponent": "kube-apiserver", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/etc/kubernetes/static-pod-resources/kube-apiserver-certs/secrets/bound-service-account-signing-key/service-account.key" }, "certKeyInfo": { "owningJiraComponent": "kube-apiserver", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/var/lib/kubelet/pki/kubelet-client-\u003ctimestamp\u003e.pem" }, "certKeyInfo": { "owningJiraComponent": "Node / Kubelet", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/var/lib/kubelet/pki/kubelet-server-\u003ctimestamp\u003e.pem" }, "certKeyInfo": { "owningJiraComponent": "Node / Kubelet", "description": "" } } }, { "InClusterLocation": null, "OnDiskLocation": { "onDiskLocation": { "Path": "/var/lib/ovn-ic/etc/ovnkube-node-certs/ovnkube-client-\u003ctimestamp\u003e.pem" }, "certKeyInfo": { "owningJiraComponent": "Networking / cluster-network-operator", "description": "" } } } ] }