Skip to main content

Reauthorize one controller provisioning mutation

POST 

/api/v1/certops/executor/provisioning-commands/:jobId/authorize-mutation

Narrow controller authorization check called immediately before each Kubernetes Certificate create or patch. Requires certops:provision:execute, immutable controller cluster binding, an active server-owned provisioning job, the deployment-wide CertOps rollout gate, and an unpaused workspace. Retries recheck the same authoritative state. This is not an agent claim, lease, heartbeat, or agent-protocol operation.

Request

Responses

Mutation remains authorized immediately before execution