Skip to main content
GET
cURL

Headers

Authorization
string
default:cid <CID>
required

Controller ID in the format: cid .

Example:

"cid <CID>"

Path Parameters

service
enum<string>
required

The service to retrieve PKI status for.

Available options:
internal,
uservpn

Response

Successfully retrieved the service PKI status

pki_bundle_deployment_status
object
required

Key-value mapping of node names to their PKI bundle deployment status.

  • unknown: The PKI bundle deployment status could not be determined for the node, possibly due to network issues or the node being offline.
  • in_sync:
    • For control-plane connection dependent services, the node PKI bundle is in sync with the source of truth on the controller.
    • For control-plane connection independent service (SPIRE), the node's SPIRE agent successfully attested to the SPIRE server, and it has the current PKI bundle.
  • out_of_sync:
    • For control-plane connection dependent services, the node PKI bundle is out of sync with the source of truth on the controller.
    • For control-plane connection independent service (SPIRE), the node's SPIRE agent has not yet attested to the SPIRE server, and it doesn't have the current PKI bundle. If in_sync, users can proceed to move to the next phase of CA rotation process. Otherwise, users should image upgrade the gateway as the fix.