Skip to main content

Report a public cert-manager observation

POST 

/api/v1/certops/executor/observations

Additive controller transport, not the agent protocol. Requires certops:observations:write and a token immutable controllerClusterId binding. Workspace and cluster provenance are derived from that token; body values must match. Private material is audited and rejected before rollout, extension, or scope denial. The passive route remains available while a workspace is paused. Idempotency is semantic and excludes only retry diagnostic observationId and observedAt fields.

Request

Responses

Exact idempotent replay