GCP.PrivateCA reference
CaPool
Section titled “CaPool”Source:
src/GCP/PrivateCA/CaPool.ts
A Certificate Authority Service CaPool — a group of Certificate Authorities that share issuance policy and form a trust anchor.
Changing caPoolId, location, tier, or encryptionSpec replaces
the resource. Labels, publishingOptions, and issuancePolicy update
in place.
CaPool: Creating a CaPool
Section titled “CaPool: Creating a CaPool”Generated name
const pool = yield* GCP.PrivateCA.CaPool("AppCa", {});Explicit id, labels, and publishing
const pool = yield* GCP.PrivateCA.CaPool("AppCa", { caPoolId: "app-ca", location: "us-central1", tier: "DEVOPS", labels: { env: "prod" }, publishingOptions: { publishCaCert: false, publishCrl: false, },});CaPool: Issuance Policy
Section titled “CaPool: Issuance Policy”const pool = yield* GCP.PrivateCA.CaPool("LeafCa", { tier: "DEVOPS", issuancePolicy: { maximumLifetime: "2592000s", allowedIssuanceModes: { allowConfigBasedIssuance: true, allowCsrBasedIssuance: true, }, identityConstraints: { allowSubjectPassthrough: true, allowSubjectAltNamesPassthrough: true, }, },});CertificateAuthority
Section titled “CertificateAuthority”Source:
src/GCP/PrivateCA/CertificateAuthority.ts
A Certificate Authority Service CertificateAuthority — a named CA in a CaPool that issues certificates.
Changing certificateAuthorityId, caPool, location, type,
lifetime, keySpec, config, or gcsBucket replaces the CA. Labels
and userDefinedAccessUrls update in place. desiredState enable/disable
the CA after create (STAGED is the API’s create-time state).
Destroy disables an ENABLED CA, then deletes it with skipGracePeriod
so the 30-day undelete window is skipped (required for pnpm nuke:gcp).
STAGED CAs are deleted directly. Provisioning a Google-managed HSM key
typically takes under a minute on a DEVOPS pool.
CertificateAuthority: Creating a Certificate Authority
Section titled “CertificateAuthority: Creating a Certificate Authority”Generated name in an existing pool
const pool = yield* GCP.PrivateCA.CaPool("Pool", { tier: "DEVOPS" });const ca = yield* GCP.PrivateCA.CertificateAuthority("Root", { caPool: pool.name,});Explicit id, labels, and subject
const ca = yield* GCP.PrivateCA.CertificateAuthority("Root", { caPool: pool.name, certificateAuthorityId: "app-root", type: "SELF_SIGNED", lifetime: "315360000s", keySpec: { algorithm: "EC_P256_SHA256" }, desiredState: "ENABLED", labels: { env: "prod" }, config: { subjectConfig: { subject: { organization: "Example", commonName: "Example Root CA", }, }, x509Config: { caOptions: { isCa: true }, keyUsage: { baseKeyUsage: { certSign: true, crlSign: true, }, }, }, },});CertificateAuthority: Staging a CA
Section titled “CertificateAuthority: Staging a CA”const ca = yield* GCP.PrivateCA.CertificateAuthority("Root", { caPool: pool.name, desiredState: "STAGED",});CertificateTemplate
Section titled “CertificateTemplate”Source:
src/GCP/PrivateCA/CertificateTemplate.ts
A Certificate Authority Service certificate template — reusable issuance policy (identity constraints, X.509 defaults, and allowed extensions) applied when issuing certificates from a CaPool.
Changing certificateTemplateId or location replaces the template.
Description, labels, lifetime, identity constraints, passthrough
extensions, and predefined X.509 values update in place.
CertificateTemplate: Creating a Certificate Template
Section titled “CertificateTemplate: Creating a Certificate Template”Generated name
const template = yield* GCP.PrivateCA.CertificateTemplate("LeafTls", { description: "leaf TLS certificates", identityConstraints: { allowSubjectPassthrough: true, allowSubjectAltNamesPassthrough: true, },});Explicit id, lifetime, and labels
const template = yield* GCP.PrivateCA.CertificateTemplate("LeafTls", { certificateTemplateId: "leaf-tls", location: "us-central1", description: "leaf TLS certificates", maximumLifetime: "86400s", labels: { env: "prod" }, identityConstraints: { allowSubjectPassthrough: true, allowSubjectAltNamesPassthrough: true, }, passthroughExtensions: { knownExtensions: ["EXTENDED_KEY_USAGE"], }, predefinedValues: { caOptions: { isCa: false }, keyUsage: { baseKeyUsage: { digitalSignature: true, keyEncipherment: true, }, extendedKeyUsage: { serverAuth: true }, }, },});CertificateTemplate: Updating a Certificate Template
Section titled “CertificateTemplate: Updating a Certificate Template”const template = yield* GCP.PrivateCA.CertificateTemplate("LeafTls", { certificateTemplateId: "leaf-tls", description: "leaf TLS certificates v2", maximumLifetime: "172800s", labels: { env: "prod", role: "tls" }, identityConstraints: { allowSubjectPassthrough: true, allowSubjectAltNamesPassthrough: false, },});FetchCaCerts
Section titled “FetchCaCerts”Source:
src/GCP/PrivateCA/FetchCaCerts.ts
Runtime binding for Certificate Authority Service caPools.fetchCaCerts.
Bind this operation to a CaPool in a Function/Action init phase.
Provide FetchCaCertsHttp. Returns PEM CA certificate chains for
authorities in the ENABLED, DISABLED, or STAGED states.
FetchCaCerts: Fetching CA Certificates
Section titled “FetchCaCerts: Fetching CA Certificates”const fetchCaCerts = yield* GCP.PrivateCA.FetchCaCerts(pool);const { caCerts } = yield* fetchCaCerts();FetchCaCertsHttp
Section titled “FetchCaCertsHttp”Source:
src/GCP/PrivateCA/FetchCaCertsHttp.tsKind: Layer · Provides:GCP.PrivateCA.FetchCaCerts
HTTP implementation of FetchCaCerts.
GetCertificateAuthority
Section titled “GetCertificateAuthority”Source:
src/GCP/PrivateCA/GetCertificateAuthority.ts
Runtime binding for Certificate Authority Service
certificateAuthorities.get.
Bind this operation to a CertificateAuthority in a Function/Action
init phase. Provide GetCertificateAuthorityHttp.
GetCertificateAuthority: Observing Certificate Authorities
Section titled “GetCertificateAuthority: Observing Certificate Authorities”const getCa = yield* GCP.PrivateCA.GetCertificateAuthority(root);const live = yield* getCa();GetCertificateAuthorityHttp
Section titled “GetCertificateAuthorityHttp”Source:
src/GCP/PrivateCA/GetCertificateAuthorityHttp.tsKind: Layer · Provides:GCP.PrivateCA.GetCertificateAuthority
HTTP implementation of GetCertificateAuthority.