Identity & security

x/cert — Certificates

TLS certificates for mutual authentication between providers and tenants.

Reference

What it does

The cert module anchors TLS certificates on-chain so that providers and tenants can mutually authenticate off-chain connections. When a tenant's client connects to a provider daemon endpoint — to send a manifest, fetch logs, or reach a deployed service — both sides verify the peer's certificate against chain state.

Certificates are issued and revoked by their owning accounts, giving every marketplace participant a self-service PKI whose root of trust is the ledger rather than a commercial certificate authority.

Why it exists: Leases are agreed on-chain but workloads are served off-chain. Without a shared PKI, the off-chain hop would be the weakest link — either unauthenticated or dependent on external CAs. Anchoring certificates in consensus lets any lease counterparty verify exactly who they are talking to.

State

Primary objects

ConceptDefinition
mTLSMutual TLS — both client and server authenticate, each verified against on-chain certificate state.
RevocationOn-chain invalidation of a certificate, effective for all future connection checks.

Messages

Messages & queries

Message and query surfaces are documented at implementation level in the module docs ↗ and the source ↗. The objects above are the state those messages create and transition.

Connections

Module interactions

Flows

Core flow

  1. Issue — Accounts issue certificates. Owning accounts create certificates for their endpoints and clients — self-service PKI.
  2. Present — Peers present on connect. Provider endpoints and tenant clients present chain-anchored certificates when connections open.
  3. Verify — Both sides check chain state. Mutual verification against on-chain records before any workload data moves.
  4. Revoke — Revocation is on-chain. Invalidation takes effect for all future connection checks, visible to every counterparty.

Questions

Asked about x/cert

Why not just use public certificate authorities?

Leases are agreed on-chain but workloads are served off-chain. Anchoring certificates in consensus lets any lease counterparty verify exactly who they are talking to, without depending on external authorities for the protocol's most sensitive hop.

What is mTLS in this context?

Mutual TLS: both client and server authenticate, each verified against on-chain certificate state — the lease counterparties are the identities the certificates authenticate.

What happens on key compromise?

The owning account revokes the certificate on-chain, and revocation is effective for all future connection checks across the marketplace.

More questions → FAQ

Related

Related modules