Skip to main content
PATCH
cURL

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

cluster_id
string
required

cluster_id is the ID of the cluster whose client CA cert is being updated.

Body

application/json
update_mode
enum<string>
  • REPLACE: REPLACE overwrites all existing certs with the provided cert. This matches the behavior of the SetClientCACert (POST) endpoint. This is the default when update_mode is omitted.
  • APPEND: APPEND adds the provided cert to the existing cert bundle. This mode enables no-downtime certificate rotation: append the new cert, roll it out across clients, then REPLACE with only the new cert to drop the old one.
Available options:
REPLACE,
APPEND
x509_pem_cert
string

x509_pem_cert is the PEM-encoded X.509 CA certificate to apply.

Response

A successful response.

status
enum<string>
  • NOT_SET: NOT_SET indicates a client CA cert is not set on the cluster. New clusters won't have a client CA cert set.
  • IS_SET: IS_SET indicates a client CA cert is set on the cluster.
  • PENDING: PENDING indicates a client CA cert update is in flight on the cluster.
  • FAILED: FAILED indicates a client CA cert update was attempted, but failed.
Available options:
NOT_SET,
IS_SET,
PENDING,
FAILED
x509_pem_cert
string