Skip to content

GCP.PrivateCA reference

Source: src/GCP/PrivateCA/CaPool.ts

A Certificate Authority Service CaPool — a group of Certificate Authorities that share issuance policy and form a trust anchor.

Changing caPoolId, location, tier, or encryptionSpec replaces the resource. Labels, publishingOptions, and issuancePolicy update in place.

Generated name

const pool = yield* GCP.PrivateCA.CaPool("AppCa", {});

Explicit id, labels, and publishing

const pool = yield* GCP.PrivateCA.CaPool("AppCa", {
caPoolId: "app-ca",
location: "us-central1",
tier: "DEVOPS",
labels: { env: "prod" },
publishingOptions: {
publishCaCert: false,
publishCrl: false,
},
});
const pool = yield* GCP.PrivateCA.CaPool("LeafCa", {
tier: "DEVOPS",
issuancePolicy: {
maximumLifetime: "2592000s",
allowedIssuanceModes: {
allowConfigBasedIssuance: true,
allowCsrBasedIssuance: true,
},
identityConstraints: {
allowSubjectPassthrough: true,
allowSubjectAltNamesPassthrough: true,
},
},
});

Source: src/GCP/PrivateCA/CertificateAuthority.ts

A Certificate Authority Service CertificateAuthority — a named CA in a CaPool that issues certificates.

Changing certificateAuthorityId, caPool, location, type, lifetime, keySpec, config, or gcsBucket replaces the CA. Labels and userDefinedAccessUrls update in place. desiredState enable/disable the CA after create (STAGED is the API’s create-time state).

Destroy disables an ENABLED CA, then deletes it with skipGracePeriod so the 30-day undelete window is skipped (required for pnpm nuke:gcp). STAGED CAs are deleted directly. Provisioning a Google-managed HSM key typically takes under a minute on a DEVOPS pool.

CertificateAuthority: Creating a Certificate Authority

Section titled “CertificateAuthority: Creating a Certificate Authority”

Generated name in an existing pool

const pool = yield* GCP.PrivateCA.CaPool("Pool", { tier: "DEVOPS" });
const ca = yield* GCP.PrivateCA.CertificateAuthority("Root", {
caPool: pool.name,
});

Explicit id, labels, and subject

const ca = yield* GCP.PrivateCA.CertificateAuthority("Root", {
caPool: pool.name,
certificateAuthorityId: "app-root",
type: "SELF_SIGNED",
lifetime: "315360000s",
keySpec: { algorithm: "EC_P256_SHA256" },
desiredState: "ENABLED",
labels: { env: "prod" },
config: {
subjectConfig: {
subject: {
organization: "Example",
commonName: "Example Root CA",
},
},
x509Config: {
caOptions: { isCa: true },
keyUsage: {
baseKeyUsage: {
certSign: true,
crlSign: true,
},
},
},
},
});
const ca = yield* GCP.PrivateCA.CertificateAuthority("Root", {
caPool: pool.name,
desiredState: "STAGED",
});

Source: src/GCP/PrivateCA/CertificateTemplate.ts

A Certificate Authority Service certificate template — reusable issuance policy (identity constraints, X.509 defaults, and allowed extensions) applied when issuing certificates from a CaPool.

Changing certificateTemplateId or location replaces the template. Description, labels, lifetime, identity constraints, passthrough extensions, and predefined X.509 values update in place.

CertificateTemplate: Creating a Certificate Template

Section titled “CertificateTemplate: Creating a Certificate Template”

Generated name

const template = yield* GCP.PrivateCA.CertificateTemplate("LeafTls", {
description: "leaf TLS certificates",
identityConstraints: {
allowSubjectPassthrough: true,
allowSubjectAltNamesPassthrough: true,
},
});

Explicit id, lifetime, and labels

const template = yield* GCP.PrivateCA.CertificateTemplate("LeafTls", {
certificateTemplateId: "leaf-tls",
location: "us-central1",
description: "leaf TLS certificates",
maximumLifetime: "86400s",
labels: { env: "prod" },
identityConstraints: {
allowSubjectPassthrough: true,
allowSubjectAltNamesPassthrough: true,
},
passthroughExtensions: {
knownExtensions: ["EXTENDED_KEY_USAGE"],
},
predefinedValues: {
caOptions: { isCa: false },
keyUsage: {
baseKeyUsage: {
digitalSignature: true,
keyEncipherment: true,
},
extendedKeyUsage: { serverAuth: true },
},
},
});

CertificateTemplate: Updating a Certificate Template

Section titled “CertificateTemplate: Updating a Certificate Template”
const template = yield* GCP.PrivateCA.CertificateTemplate("LeafTls", {
certificateTemplateId: "leaf-tls",
description: "leaf TLS certificates v2",
maximumLifetime: "172800s",
labels: { env: "prod", role: "tls" },
identityConstraints: {
allowSubjectPassthrough: true,
allowSubjectAltNamesPassthrough: false,
},
});

Source: src/GCP/PrivateCA/FetchCaCerts.ts

Runtime binding for Certificate Authority Service caPools.fetchCaCerts.

Bind this operation to a CaPool in a Function/Action init phase. Provide FetchCaCertsHttp. Returns PEM CA certificate chains for authorities in the ENABLED, DISABLED, or STAGED states.

const fetchCaCerts = yield* GCP.PrivateCA.FetchCaCerts(pool);
const { caCerts } = yield* fetchCaCerts();

Source: src/GCP/PrivateCA/FetchCaCertsHttp.ts Kind: Layer · Provides: GCP.PrivateCA.FetchCaCerts

HTTP implementation of FetchCaCerts.

Source: src/GCP/PrivateCA/GetCertificateAuthority.ts

Runtime binding for Certificate Authority Service certificateAuthorities.get.

Bind this operation to a CertificateAuthority in a Function/Action init phase. Provide GetCertificateAuthorityHttp.

GetCertificateAuthority: Observing Certificate Authorities

Section titled “GetCertificateAuthority: Observing Certificate Authorities”
const getCa = yield* GCP.PrivateCA.GetCertificateAuthority(root);
const live = yield* getCa();

Source: src/GCP/PrivateCA/GetCertificateAuthorityHttp.ts Kind: Layer · Provides: GCP.PrivateCA.GetCertificateAuthority

HTTP implementation of GetCertificateAuthority.