PKI Manager v2.0.0
Major release introducing a cert-manager external issuer for Kubernetes and CRL signing & distribution. PKI Manager can now act as a certificate authority for in-cluster cert-manager CertificateRequests, with private keys staying in the Cosmian KMS.
☸️ Kubernetes cert-manager External Issuer (new)
- Go external-issuer controller (controller-runtime 0.20, cert-manager 1.16) that signs cert-manager
CertificateRequests by calling the backendPOST /api/v1/external/signendpoint — one cluster token maps to one CA. - CSRs are signed via KMS certify; the previous offline-signing path was dropped.
- Automatic approval of cert-manager
CertificateRequests via a built-in approver. - Revoke-on-delete, Prometheus metrics, source filtering, and signer tests.
- Full in-cluster end-to-end deployment on kind: PKI Manager + Cosmian KMS + cert-manager + ingress-nginx, browser-reachable via ingress.
- Helm chart, install guide, security notes, and an external-issuer API contract with e2e verification.
- New Clusters management page in the UI.
🔏 CRL Signing & Distribution (new)
- CRLs are now signed with the CA key and resolved against the correct CA key id.
- CRLs are served over HTTP for distribution.
- CDP (CRL Distribution Point) and CRL regeneration wired into the certificate issuance paths.
🔐 Certificates & Crypto
- ECDSA leaf certificates enabled, plus EC key export.
🐛 Fixes
- Cert detail page now works for offline-signed (k8s) certificates.
UserMenuno longer crashes when OIDC is disabled.- Removed unreachable code in the
certificaterequest_controller. - Dropped dead offline-signing config; fixed the KMS docker-compose setup.
📚 Docs & Chores
- Per-directory
CLAUDE.mdguides; fixed KMS README path. - Added the "CRL Signing & Distribution" backlog milestone (TASK-110..116).
- Added a
config.jsonplaceholder for Docker.
Full Changelog: v1.8.1...v2.0.0