Class BackendTLSPolicyValidation
- java.lang.Object
-
- io.fabric8.kubernetes.api.model.gatewayapi.v1alpha3.BackendTLSPolicyValidation
-
- All Implemented Interfaces:
io.fabric8.kubernetes.api.builder.Editable<BackendTLSPolicyValidationBuilder>
,io.fabric8.kubernetes.api.model.KubernetesResource
,Serializable
@Generated("io.fabric8.kubernetes.schema.generator.model.ModelGenerator") public class BackendTLSPolicyValidation extends Object implements io.fabric8.kubernetes.api.builder.Editable<BackendTLSPolicyValidationBuilder>, io.fabric8.kubernetes.api.model.KubernetesResource
BackendTLSPolicyValidation contains backend TLS validation configuration.- See Also:
- Serialized Form
-
-
Constructor Summary
Constructors Constructor Description BackendTLSPolicyValidation()
No args constructor for use in serializationBackendTLSPolicyValidation(List<LocalObjectReference> caCertificateRefs, String hostname, List<SubjectAltName> subjectAltNames, String wellKnownCACertificates)
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description BackendTLSPolicyValidationBuilder
edit()
Map<String,Object>
getAdditionalProperties()
List<LocalObjectReference>
getCaCertificateRefs()
CACertificateRefs contains one or more references to Kubernetes objects that contain a PEM-encoded TLS CA certificate bundle, which is used to validate a TLS handshake between the Gateway and backend Pod.String
getHostname()
Hostname is used for two purposes in the connection between Gateways and backends:List<SubjectAltName>
getSubjectAltNames()
SubjectAltNames contains one or more Subject Alternative Names.String
getWellKnownCACertificates()
WellKnownCACertificates specifies whether system CA certificates may be used in the TLS handshake between the gateway and backend pod.void
setAdditionalProperties(Map<String,Object> additionalProperties)
void
setAdditionalProperty(String name, Object value)
void
setCaCertificateRefs(List<LocalObjectReference> caCertificateRefs)
CACertificateRefs contains one or more references to Kubernetes objects that contain a PEM-encoded TLS CA certificate bundle, which is used to validate a TLS handshake between the Gateway and backend Pod.void
setHostname(String hostname)
Hostname is used for two purposes in the connection between Gateways and backends:void
setSubjectAltNames(List<SubjectAltName> subjectAltNames)
SubjectAltNames contains one or more Subject Alternative Names.void
setWellKnownCACertificates(String wellKnownCACertificates)
WellKnownCACertificates specifies whether system CA certificates may be used in the TLS handshake between the gateway and backend pod.BackendTLSPolicyValidationBuilder
toBuilder()
-
-
-
Constructor Detail
-
BackendTLSPolicyValidation
public BackendTLSPolicyValidation()
No args constructor for use in serialization
-
BackendTLSPolicyValidation
public BackendTLSPolicyValidation(List<LocalObjectReference> caCertificateRefs, String hostname, List<SubjectAltName> subjectAltNames, String wellKnownCACertificates)
-
-
Method Detail
-
getCaCertificateRefs
public List<LocalObjectReference> getCaCertificateRefs()
CACertificateRefs contains one or more references to Kubernetes objects that contain a PEM-encoded TLS CA certificate bundle, which is used to validate a TLS handshake between the Gateway and backend Pod.If CACertificateRefs is empty or unspecified, then WellKnownCACertificates must be specified. Only one of CACertificateRefs or WellKnownCACertificates may be specified, not both. If CACertifcateRefs is empty or unspecified, the configuration for WellKnownCACertificates MUST be honored instead if supported by the implementation.
References to a resource in a different namespace are invalid for the moment, although we will revisit this in the future.
A single CACertificateRef to a Kubernetes ConfigMap kind has "Core" support. Implementations MAY choose to support attaching multiple certificates to a backend, but this behavior is implementation-specific.
Support: Core - An optional single reference to a Kubernetes ConfigMap, with the CA certificate in a key named `ca.crt`.
Support: Implementation-specific (More than one reference, or other kinds of resources).
-
setCaCertificateRefs
public void setCaCertificateRefs(List<LocalObjectReference> caCertificateRefs)
CACertificateRefs contains one or more references to Kubernetes objects that contain a PEM-encoded TLS CA certificate bundle, which is used to validate a TLS handshake between the Gateway and backend Pod.If CACertificateRefs is empty or unspecified, then WellKnownCACertificates must be specified. Only one of CACertificateRefs or WellKnownCACertificates may be specified, not both. If CACertifcateRefs is empty or unspecified, the configuration for WellKnownCACertificates MUST be honored instead if supported by the implementation.
References to a resource in a different namespace are invalid for the moment, although we will revisit this in the future.
A single CACertificateRef to a Kubernetes ConfigMap kind has "Core" support. Implementations MAY choose to support attaching multiple certificates to a backend, but this behavior is implementation-specific.
Support: Core - An optional single reference to a Kubernetes ConfigMap, with the CA certificate in a key named `ca.crt`.
Support: Implementation-specific (More than one reference, or other kinds of resources).
-
getHostname
public String getHostname()
Hostname is used for two purposes in the connection between Gateways and backends:1. Hostname MUST be used as the SNI to connect to the backend (RFC 6066). 2. If SubjectAltNames is not specified, Hostname MUST be used for
authentication and MUST match the certificate served by the matching
backend.
Support: Core
-
setHostname
public void setHostname(String hostname)
Hostname is used for two purposes in the connection between Gateways and backends:1. Hostname MUST be used as the SNI to connect to the backend (RFC 6066). 2. If SubjectAltNames is not specified, Hostname MUST be used for
authentication and MUST match the certificate served by the matching
backend.
Support: Core
-
getSubjectAltNames
public List<SubjectAltName> getSubjectAltNames()
SubjectAltNames contains one or more Subject Alternative Names. When specified, the certificate served from the backend MUST have at least one Subject Alternate Name matching one of the specified SubjectAltNames.Support: Core
-
setSubjectAltNames
public void setSubjectAltNames(List<SubjectAltName> subjectAltNames)
SubjectAltNames contains one or more Subject Alternative Names. When specified, the certificate served from the backend MUST have at least one Subject Alternate Name matching one of the specified SubjectAltNames.Support: Core
-
getWellKnownCACertificates
public String getWellKnownCACertificates()
WellKnownCACertificates specifies whether system CA certificates may be used in the TLS handshake between the gateway and backend pod.If WellKnownCACertificates is unspecified or empty (""), then CACertificateRefs must be specified with at least one entry for a valid configuration. Only one of CACertificateRefs or WellKnownCACertificates may be specified, not both. If an implementation does not support the WellKnownCACertificates field or the value supplied is not supported, the Status Conditions on the Policy MUST be updated to include an Accepted: False Condition with Reason: Invalid.
Support: Implementation-specific
-
setWellKnownCACertificates
public void setWellKnownCACertificates(String wellKnownCACertificates)
WellKnownCACertificates specifies whether system CA certificates may be used in the TLS handshake between the gateway and backend pod.If WellKnownCACertificates is unspecified or empty (""), then CACertificateRefs must be specified with at least one entry for a valid configuration. Only one of CACertificateRefs or WellKnownCACertificates may be specified, not both. If an implementation does not support the WellKnownCACertificates field or the value supplied is not supported, the Status Conditions on the Policy MUST be updated to include an Accepted: False Condition with Reason: Invalid.
Support: Implementation-specific
-
edit
public BackendTLSPolicyValidationBuilder edit()
- Specified by:
edit
in interfaceio.fabric8.kubernetes.api.builder.Editable<BackendTLSPolicyValidationBuilder>
-
toBuilder
public BackendTLSPolicyValidationBuilder toBuilder()
-
-