Certificates
Show the service PKI status
This API shows the PKI status of the service.
GET
cURL
Headers
Controller ID in the format: cid .
Example:
"cid <CID>"
Path Parameters
The service to retrieve PKI status for.
Available options:
internal, uservpn Response
Successfully retrieved the service PKI status
Key-value mapping of node names to their PKI bundle deployment status.
- unknown: The PKI bundle deployment status could not be determined for the node, possibly due to network issues or the node being offline.
- in_sync:
- For control-plane connection dependent services, the node PKI bundle is in sync with the source of truth on the controller.
- For control-plane connection independent service (SPIRE), the node's SPIRE agent successfully attested to the SPIRE server, and it has the current PKI bundle.
- out_of_sync:
- For control-plane connection dependent services, the node PKI bundle is out of sync with the source of truth on the controller.
- For control-plane connection independent service (SPIRE), the node's SPIRE agent has not yet attested to the SPIRE server, and it doesn't have the current PKI bundle. If in_sync, users can proceed to move to the next phase of CA rotation process. Otherwise, users should image upgrade the gateway as the fix.