description: (
req: any,
) => {
authentication: {
acceptAssertedSelectors: boolean;
adminIds: string[];
assertedSelectorHeader: string;
attestWorkloads: boolean;
bootstrapping: string;
credentialStatusNote: string;
enforced: boolean;
entities: { id: string; label: string; what: string }[];
identityNote: string;
policy: { allow: string[]; method: string }[];
trustLocalSocket: boolean;
what: string;
};
authorities: {
chainSubjects: any;
jwt: any;
note: string;
realm: string;
source: any;
trustAnchors: any;
x509: {
active: boolean;
id: any;
keyType: any;
notAfter: any;
source: any;
subject: any;
}[];
};
brokerApi: {
brokers: { id: string; problem: string; raw: string; types: string[] }[];
listeners: any;
methods: { name: string; path: any; streaming: boolean }[];
referenceTypes: string[];
securityHeader: string;
service: string;
specification: string;
};
bundle: {
profiles: { https_spiffe: string; https_web: string };
refreshHint: any;
scheme: string;
schemeNote: string;
sequence: number;
url: string;
};
enabled: boolean;
error: any;
federated: {
bundleEndpointProfile: any;
bundleEndpointUrl: any;
createdAt: any;
endpointSpiffeId: any;
jwtKeys: any;
keys: any;
refreshHint: any;
sequence: any;
trustDomain: any;
trustDomainId: string;
updatedAt: any;
x509Keys: any;
}[];
links: {
agents: string;
api: string;
brokers: string;
bundle: string;
console: string;
directory: string;
entries: string;
metadata: string;
};
nodeAttestation: any;
notChecked: string[];
ready: boolean;
refused: string[];
registry: {
agents: any;
entries: any;
maxAgents: any;
maxEntries: any;
note: string;
};
serverApi: {
listeners: any;
services: {
methods: { implemented: boolean; name: string; path: any; what: any }[];
name: string;
what: string;
}[];
};
serverId: string;
trustDomain: string;
trustDomainId: string;
what: string;
workloadApi: {
listeners: any;
methods: {
implemented: boolean;
name: string;
path: any;
streaming: boolean;
what: any;
}[];
securityHeader: string;
securityHeaderRequired: boolean;
service: string;
};
workloadAttestation: {
attestors: any;
connections: any[];
nativeModule: boolean;
problem: string;
tcp: Record<string, any>;
unattestedSocketServed: boolean;
unknownConfigured: any;
};
} = ...
Type Declaration
-
- (
req: any,
): {
authentication: {
acceptAssertedSelectors: boolean;
adminIds: string[];
assertedSelectorHeader: string;
attestWorkloads: boolean;
bootstrapping: string;
credentialStatusNote: string;
enforced: boolean;
entities: { id: string; label: string; what: string }[];
identityNote: string;
policy: { allow: string[]; method: string }[];
trustLocalSocket: boolean;
what: string;
};
authorities: {
chainSubjects: any;
jwt: any;
note: string;
realm: string;
source: any;
trustAnchors: any;
x509: {
active: boolean;
id: any;
keyType: any;
notAfter: any;
source: any;
subject: any;
}[];
};
brokerApi: {
brokers: { id: string; problem: string; raw: string; types: string[] }[];
listeners: any;
methods: { name: string; path: any; streaming: boolean }[];
referenceTypes: string[];
securityHeader: string;
service: string;
specification: string;
};
bundle: {
profiles: { https_spiffe: string; https_web: string };
refreshHint: any;
scheme: string;
schemeNote: string;
sequence: number;
url: string;
};
enabled: boolean;
error: any;
federated: {
bundleEndpointProfile: any;
bundleEndpointUrl: any;
createdAt: any;
endpointSpiffeId: any;
jwtKeys: any;
keys: any;
refreshHint: any;
sequence: any;
trustDomain: any;
trustDomainId: string;
updatedAt: any;
x509Keys: any;
}[];
links: {
agents: string;
api: string;
brokers: string;
bundle: string;
console: string;
directory: string;
entries: string;
metadata: string;
};
nodeAttestation: any;
notChecked: string[];
ready: boolean;
refused: string[];
registry: {
agents: any;
entries: any;
maxAgents: any;
maxEntries: any;
note: string;
};
serverApi: {
listeners: any;
services: {
methods: { implemented: boolean; name: string; path: any; what: any }[];
name: string;
what: string;
}[];
};
serverId: string;
trustDomain: string;
trustDomainId: string;
what: string;
workloadApi: {
listeners: any;
methods: {
implemented: boolean;
name: string;
path: any;
streaming: boolean;
what: any;
}[];
securityHeader: string;
securityHeaderRequired: boolean;
service: string;
};
workloadAttestation: {
attestors: any;
connections: any[];
nativeModule: boolean;
problem: string;
tcp: Record<string, any>;
unattestedSocketServed: boolean;
unknownConfigured: any;
};
}
-
Returns {
authentication: {
acceptAssertedSelectors: boolean;
adminIds: string[];
assertedSelectorHeader: string;
attestWorkloads: boolean;
bootstrapping: string;
credentialStatusNote: string;
enforced: boolean;
entities: { id: string; label: string; what: string }[];
identityNote: string;
policy: { allow: string[]; method: string }[];
trustLocalSocket: boolean;
what: string;
};
authorities: {
chainSubjects: any;
jwt: any;
note: string;
realm: string;
source: any;
trustAnchors: any;
x509: {
active: boolean;
id: any;
keyType: any;
notAfter: any;
source: any;
subject: any;
}[];
};
brokerApi: {
brokers: { id: string; problem: string; raw: string; types: string[] }[];
listeners: any;
methods: { name: string; path: any; streaming: boolean }[];
referenceTypes: string[];
securityHeader: string;
service: string;
specification: string;
};
bundle: {
profiles: { https_spiffe: string; https_web: string };
refreshHint: any;
scheme: string;
schemeNote: string;
sequence: number;
url: string;
};
enabled: boolean;
error: any;
federated: {
bundleEndpointProfile: any;
bundleEndpointUrl: any;
createdAt: any;
endpointSpiffeId: any;
jwtKeys: any;
keys: any;
refreshHint: any;
sequence: any;
trustDomain: any;
trustDomainId: string;
updatedAt: any;
x509Keys: any;
}[];
links: {
agents: string;
api: string;
brokers: string;
bundle: string;
console: string;
directory: string;
entries: string;
metadata: string;
};
nodeAttestation: any;
notChecked: string[];
ready: boolean;
refused: string[];
registry: {
agents: any;
entries: any;
maxAgents: any;
maxEntries: any;
note: string;
};
serverApi: {
listeners: any;
services: {
methods: { implemented: boolean; name: string; path: any; what: any }[];
name: string;
what: string;
}[];
};
serverId: string;
trustDomain: string;
trustDomainId: string;
what: string;
workloadApi: {
listeners: any;
methods: {
implemented: boolean;
name: string;
path: any;
streaming: boolean;
what: any;
}[];
securityHeader: string;
securityHeaderRequired: boolean;
service: string;
};
workloadAttestation: {
attestors: any;
connections: any[];
nativeModule: boolean;
problem: string;
tcp: Record<string, any>;
unattestedSocketServed: boolean;
unknownConfigured: any;
};
}
the description document
Describes the three SPIFFE surfaces — where they are, whether the sockets bound, and at length what is not checked — for
GET /spiffe.