Push and Revoke CERT

KUBE enables a self-service feature of managing KUBE related kubernetes resources in the clusters directly from the KUBE control plane.

Cluster administrators or DevOps team can Push the Cert and CertLoad resources used for generating certificate signing requests directly from the inventory into the respective cluster, this enables to reduce the efforts of manually downloading the Resources as YAML, copying it to the cluster and deploying it.

Similarly, the cluster administrators or DevOps team can also Revoke (Delete) the Cert and CertLoad Resources deployed in the specific cluster instead of executing the delete commands manually in the cluster.

Pushing the Cert CRD

To push the Cert or CertLoad Resources created,

  1. Go to menu > KUBE > CLUSTER SECURITY > Secure Apps.
  2. Select a Cert or CertLoad from the inventory that is in a deployed state.
  3. Click PUSH.
  4. Type your comments in the Comments field.
  5. Click Push.

Revoking the Cert CRD

To revoke the Cert or CertLoad Resources created:

  1. Go to menu > KUBE > CLUSTER SECURITY > Secure Apps.
  2. Select a Cert or CertLoad from the inventory that is in a deployed state.
  3. Click Revoke.
  4. On Certificate Revoke popup window, under Trigger Revoke Certificate, select one of the following options:
    • Yes (default) - Revokes the certificate in the certificate inventory and delete it in the cluster.
    • No - Deletes the certificate only in the cluster.
  5. Type your comments in the Comments field.
  6. Click Revoke.

Handle Uniqueness for Secure Apps Usages

Use the certificate name, cluster name, and namespace combination as the unique identity while working with Secure Apps resources and actions.

  1. Go to menu > KUBE > CLUSTER SECURITY > Secure Apps.
  2. Before performing actions such as Push, Revoke, Delete, Status Update, or tag updates, verify that the selected record matches the expected certificate name, cluster name, and namespace.
  3. Open certificate details and confirm the same unique combination before saving any changes.
  4. When deleting a secure app entry or cluster-linked record, verify association with cluster policy first; proceed only when policy association checks are satisfied.
  5. For cluster cleanup flows, validate that only records matching the selected cluster and namespace are targeted for cleanup.
  6. When using YAML generation and view actions, confirm that generated YAML reflects the intended certificate, cluster, and namespace mapping.
  7. After completing the action, review audit logs and verify entries include certificate name, cluster name, and secret/namespace context.

Secure Apps operations consistently apply uniqueness checks, helping prevent incorrect updates across similarly named certificates in different cluster-namespace scopes.

Handle Uniqueness in kube-add-cert-crd-instance Action ID

Use the certificate name, cluster name, and namespace combination when the kube-add-cert-crd-instance action creates or updates Secure Apps YAML-backed resources.

  1. Ensure the backend action resolves the Secure Apps record using the certificate name, cluster name, and namespace together with the action identifier.
  2. When the request is processed, verify that the cert-orchestrator cache contains the latest certificate YAML for the same unique combination.
  3. If an older cert-orchestrator deployment exists and its cache is not yet synchronized, restart cert-orchestrator so the missing Secure Apps entries are synchronized.
  4. After restart or synchronization, recheck the action response and confirm that duplicate records are not created for the same certificate, cluster, and namespace scope.

Backend handling uses the combined certificate, cluster, and namespace identity for kube-add-cert-crd-instance and keeps cert-orchestrator data synchronized.