Skip to content

Commit 27feafe

Browse files
authored
Merge pull request #1193 from irbekrm/update_approver
Explains what happens if CertificateRequest is denied
2 parents 193b6b2 + 06cf8a8 commit 27feafe

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

content/docs/projects/approver-policy.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -72,6 +72,14 @@ selector.
7272
least one policy is appropriate for the request but none of those permit the
7373
request, the request is denied.**
7474

75+
A denied CertificateRequest is considered to be permanently failed. If it was
76+
created for a Certificate resource, the issuance will be retried with
77+
[exponential
78+
backoff](../faq/README.md#what-happens-if-issuance-fails-will-it-be-retried)
79+
like all other permanent issuance failures. A CertificateRequest that is neither
80+
approved nor denied (because no matching policy was found) will not be further
81+
processed by cert-manager until it gets either approved or denied.
82+
7583
CertificateRequestPolicies are cluster scoped resources that can be thought of
7684
as "policy profiles". They describe any request that is approved by that
7785
policy. Policies are bound to Kubernetes users and ServiceAccounts using RBAC.

0 commit comments

Comments
 (0)