コンテンツにスキップ

Mint a new bus certificate covering the given names.

POST
/api/v1/settings/bus/certificate
curl --request POST \
--url https://example.com/api/v1/settings/bus/certificate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "names": [ "example" ] }'
Media typeapplication/json

Which names a regenerated bus certificate should cover.

object
names

Hostnames and IP addresses remote pollers will dial, added to the deployment’s internal defaults. A poller’s connection fails unless the exact address it dials is present, so this is the field that decides whether a new site can connect.

Array<string>
Examplegenerated
{
"names": [
"example"
]
}

Generated and written; the body is the new certificate’s details

Media typeapplication/json

The bus, as Settings ▸ Pollers shows it.

object
can_switch
required

Whether the switch below can be operated. false means the updater sidecar that performs it is not deployed, is switched off, or has stopped reporting — the certificate is still readable, but turning remote acceptance on or off needs a shell on the host.

boolean
certificate
One of:
null
remote_enabled
required

Whether this core is talking to the bus over TLS, which is what accepting remote-site pollers requires.

boolean
Examplegenerated
{
"can_switch": true,
"certificate": {
"certificate": "example",
"expires_in_days": 1,
"fingerprint_sha256": "example",
"issued_at": "example",
"issued_by": "example",
"issuer": "example",
"key_algorithm": "example",
"key_unreadable": true,
"materialized": true,
"not_after": "example",
"not_before": "example",
"sans": [
"example"
],
"subject": "example"
},
"remote_enabled": true
}

A supplied name is not a usable hostname or IP address

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks ManageSystem

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

This deployment has no bus certificate store

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}