apiVersion: pgd.k8s.enterprisedb.io/v1beta1 kind: PGDGroup metadata: name: region-a spec: instances: 2 proxyInstances: 2 witnessInstances: 1 pgd: parentGroup: name: world create: true discovery: - host: region-a-group - host: region-b-group - host: region-c-group cnp: storage: size: 1Gi connectivity: dns: additional: - domain: my.domain hostSuffix: -dc1 tls: mode: verify-ca clientCert: # if the pre-provisioned secrets is set, the caCertSecret will accept a CA secrets, which contains ca.crt or ca.key optionally caCertSecret: client-ca-secrets preProvisioned: streamingReplica: secretRef: replication-secrets-region-a serverCert: caCertSecret: server-ca-key-pair certManager: spec: issuerRef: name: server-ca-issuer kind: Issuer group: cert-manager.io --- apiVersion: pgd.k8s.enterprisedb.io/v1beta1 kind: PGDGroup metadata: name: region-b spec: instances: 2 proxyInstances: 2 witnessInstances: 1 pgd: parentGroup: name: world discovery: - host: region-a-group - host: region-b-group - host: region-c-group cnp: storage: size: 1Gi connectivity: dns: additional: - domain: my.domain hostSuffix: -dc1 tls: mode: verify-ca clientCert: caCertSecret: client-ca-secrets preProvisioned: streamingReplica: secretRef: replication-secrets-region-b serverCert: caCertSecret: server-ca-key-pair certManager: spec: issuerRef: name: server-ca-issuer kind: Issuer group: cert-manager.io --- apiVersion: pgd.k8s.enterprisedb.io/v1beta1 kind: PGDGroup metadata: name: region-c spec: instances: 0 proxyInstances: 0 witnessInstances: 1 pgd: parentGroup: name: world discovery: - host: region-a-group - host: region-b-group - host: region-c-group cnp: storage: size: 1Gi connectivity: dns: additional: - domain: my.domain hostSuffix: -dc1 tls: mode: verify-ca clientCert: caCertSecret: client-ca-secrets preProvisioned: streamingReplica: secretRef: replication-secrets-region-c serverCert: caCertSecret: server-ca-key-pair certManager: spec: issuerRef: name: server-ca-issuer kind: Issuer group: cert-manager.io --- ### This is the pre-provisioned client certificate which is signed by certificate in client-ca-secrets apiVersion: v1 data: tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNYekNDQWdTZ0F3SUJBZ0lSQUw0N2V5eXEydzNEN0gwM2RPaE9iaFF3Q2dZSUtvWkl6ajBFQXdJd0lqRWcKTUI0R0ExVUVBeE1YYlhrdGMyVnNabk5wWjI1bFpDMWpiR2xsYm5RdFkyRXdIaGNOTWpReE1URTVNVE14T1RVeQpXaGNOTWpVd01qRTNNVE14T1RVeVdqQWNNUm93R0FZRFZRUUREQkZ6ZEhKbFlXMXBibWRmY21Wd2JHbGpZVENDCkFTSXdEUVlKS29aSWh2Y05BUUVCQlFBRGdnRVBBRENDQVFvQ2dnRUJBT0hScytwV3lwVUFGcEFidm82UmZQdHkKc2d6ejM3bXRualYxVVY2MURYL0IrUkd5bmFKNkNuNUxsVXVtSFdrbUFxRVpnNWZOVEV5RnByNXlKRHNKNDQzbQpHb1ZrQ3ZDY3lPSTZMY2lEOU9VRHhFZWNPUDE1QWgrQ0RNMG5URFB2eS9IRG05Mnh3aVFldmYxY0lucGJRVGpPCkVaTFl2YWNkQlR4aWIxS2tVZmJqb0ZNWUJTNHRYaVIzZ2F3aUFRKzYrWHgrN1RUTmUxNlhLT1NXZmdjSkNTNzcKOFZtSS9iOGtnZ2hZU1BZNjdvdEJnK2ZicHJLNUhoNXdpU3ZlMGpORlg1MzhId05YVTBIM29JbEhXM2dEV0svZAova1hsUTdKdHpPSDJtN3NYVnl3eDlHVUlOakZ2TTR1RkFDdkVtYkorcUJ1SkNtQlQ1M1E2NExySzc4c1AvTEVDCkF3RUFBYU5XTUZRd0RnWURWUjBQQVFIL0JBUURBZ09JTUJNR0ExVWRKUVFNTUFvR0NDc0dBUVVGQndNQ01Bd0cKQTFVZEV3RUIvd1FDTUFBd0h3WURWUjBqQkJnd0ZvQVVscmFqNDFKcFROeVRsMkRmTGkzcVZvbXBBcFV3Q2dZSQpLb1pJemowRUF3SURTUUF3UmdJaEFPWkhZUG5aTEV5WlEvejZ2Mm9kYWM2WmZhTXYzVzlBUmlKNE9pNnF5dW5GCkFpRUFvTDhUb1JoVUpaL3pOSTY2N1VMR0JpeUdTU1p3L0R0UHFoTnU5RkVQQWc0PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcFFJQkFBS0NBUUVBNGRHejZsYktsUUFXa0J1K2pwRjgrM0t5RFBQZnVhMmVOWFZSWHJVTmY4SDVFYktkCm9ub0tma3VWUzZZZGFTWUNvUm1EbDgxTVRJV212bklrT3duamplWWFoV1FLOEp6STRqb3R5SVAwNVFQRVI1dzQKL1hrQ0g0SU16U2RNTSsvTDhjT2IzYkhDSkI2OS9Wd2llbHRCT000Umt0aTlweDBGUEdKdlVxUlI5dU9nVXhnRgpMaTFlSkhlQnJDSUJEN3I1Zkg3dE5NMTdYcGNvNUpaK0J3a0pMdnZ4V1lqOXZ5U0NDRmhJOWpydWkwR0Q1OXVtCnNya2VIbkNKSzk3U00wVmZuZndmQTFkVFFmZWdpVWRiZUFOWXI5MytSZVZEc20zTTRmYWJ1eGRYTERIMFpRZzIKTVc4emk0VUFLOFNac242b0c0a0tZRlBuZERyZ3VzcnZ5dy84c1FJREFRQUJBb0lCQUR1MEJMeE5MQXhPMUtoUApIWWQyQWJROU04UG02bHllQVhraXhsdWl4S25sYitOMDlPWlRHOWtlUkorV2tLb1BLWnpNTVJWK2F0REVlVHhhCjB5ZGt5dXZtVFZhOUI0TnNBRlNIaXprN1loRDJlUHR4MjBOd3JkWUV2VHUwU3hwa0tPaUhqZnNFRjA4VGJhbkIKcFQveVJvRXRRa292MFp5UU9LVXBaVU5WUEhKb1p0RkplNXlPK1crZmx6cmFSeDJmVWlsZlZCbm5uT0YxcDFGMAp1azhIa2xFZ3BUVkRlV1RKa0tydlM2L09sMGNhSEhiSTVoNENIL1pzY0R5SVU4bVd0aS9TYTBHOVZjb3pVRUgrCm5EaDFPeTFQZ1FudEg3YWcrQzkxcUZuTUE2QnI3ZzdkWFllVHVpQmVNbzV5UG40aitnNzBVU0JYUVNzM090UEwKeE45VTNwMENnWUVBL2xjand3YkNXZC9PcXRsb0dJbGhGVkpRc0hYd2pzdy91cVNMNkRYRTlQQkJ3U01LOHY4VAo4Z2pwZ2I2ZVpQQjRUQW1Ob1c1Rm1tbTFuNjV0LzlETVRhZE4yMFNuTmJnUWxEQVN6OEUvNDZjMEdLUkRBTjhZClBMVG13MWh4QktIc0dRaTlieUNuTnJPc1M3NzBNM3VTeGtobFpWQmxrd21KTm5mUUp2QlgyZGNDZ1lFQTQwcnIKaXZvK1MwQmYzcExDWTdBR0gwL29ZLytRdUVEczZLdk9pMnR3NHFwekhnNWlTUmhuSHMxTmpqNm5wWlBaMkpwbApMSUthd1o1TDJ6QkhmaEVzOEpnM3NuTG1ieEpySi95N21QTnpkVHVSSlBMM1BEbVVVRlFaU2Y3YlFPL21PbmZFClEzZ0IrNE1VWlRrNVdDaCtrNVJQM1RJejFqd0hvMVQ3S0txV1hMY0NnWUVBelNPRmdaaWpDeEE3eFl0Q3JYK28Kb1NUYVZlbGFWQ0tqU0N2TmVFWmVERnozL0FvQ204bG0wZkdrUFBSOUZ0YnBnQks0ZkRyUHd1SitEa1FIRHF6ZgpDOGJrUWZWV2xEcFlqTjFWWHVIMFlPNk1VMCt4aHpOcGZoVStodEovbllmb1FLek85YUcxbktaQVVudTZ4UWRuCmM2d1N0Q3VyTVhRZ2lxRUtiMDJzM2RNQ2dZRUF3SWpuUzl1OHh3dnA2ZVZScXhZaHFZYUw2YUZFR3dCTWJxK1MKajhGY1ozVlJmSVZjdG1Sb2Zjd1ZSVWhIeE5lZ2NuNGU4L3hTVVc3Zy9QUkJxMFdyVnNicWIwd3JiSzBpZmtYMQpONVFLR3FWeHh1WFZqbnVMNmh2RExFNHB0akZCU2dmSUJncnpTdlYzWW1OOTh2S2lmaXJsR0E5OW41MU1Md3crCmtPMG4zN01DZ1lFQTN1TGJQTG45SjhPT3ZRWjk3eThhQkdaZ1RjdlhOeUpnTHhJTW14NGtoc3pGaTBqMUFhY1MKZ090MEVSWEN0VEQwT2hkS2RWWDE4ZmREZ1BOZUU2MzhEenIxN001NTlIbHc1ZGJJdHQ4MllrV01PYU5SMlJHVwpMcmMreDluUWpvNVNhOUwwZXUwcEQxM0NIS1FCZ2RHNDA0bEh2UnNjT0I5WmRKa29ZeWF0a3cwPQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo= kind: Secret metadata: name: replication-secrets-region-a type: Opaque --- ### This is the pre-provisioned client certificate which is signed by certificate in client-ca-secrets apiVersion: v1 data: tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNYekNDQWdTZ0F3SUJBZ0lSQUw0N2V5eXEydzNEN0gwM2RPaE9iaFF3Q2dZSUtvWkl6ajBFQXdJd0lqRWcKTUI0R0ExVUVBeE1YYlhrdGMyVnNabk5wWjI1bFpDMWpiR2xsYm5RdFkyRXdIaGNOTWpReE1URTVNVE14T1RVeQpXaGNOTWpVd01qRTNNVE14T1RVeVdqQWNNUm93R0FZRFZRUUREQkZ6ZEhKbFlXMXBibWRmY21Wd2JHbGpZVENDCkFTSXdEUVlKS29aSWh2Y05BUUVCQlFBRGdnRVBBRENDQVFvQ2dnRUJBT0hScytwV3lwVUFGcEFidm82UmZQdHkKc2d6ejM3bXRualYxVVY2MURYL0IrUkd5bmFKNkNuNUxsVXVtSFdrbUFxRVpnNWZOVEV5RnByNXlKRHNKNDQzbQpHb1ZrQ3ZDY3lPSTZMY2lEOU9VRHhFZWNPUDE1QWgrQ0RNMG5URFB2eS9IRG05Mnh3aVFldmYxY0lucGJRVGpPCkVaTFl2YWNkQlR4aWIxS2tVZmJqb0ZNWUJTNHRYaVIzZ2F3aUFRKzYrWHgrN1RUTmUxNlhLT1NXZmdjSkNTNzcKOFZtSS9iOGtnZ2hZU1BZNjdvdEJnK2ZicHJLNUhoNXdpU3ZlMGpORlg1MzhId05YVTBIM29JbEhXM2dEV0svZAova1hsUTdKdHpPSDJtN3NYVnl3eDlHVUlOakZ2TTR1RkFDdkVtYkorcUJ1SkNtQlQ1M1E2NExySzc4c1AvTEVDCkF3RUFBYU5XTUZRd0RnWURWUjBQQVFIL0JBUURBZ09JTUJNR0ExVWRKUVFNTUFvR0NDc0dBUVVGQndNQ01Bd0cKQTFVZEV3RUIvd1FDTUFBd0h3WURWUjBqQkJnd0ZvQVVscmFqNDFKcFROeVRsMkRmTGkzcVZvbXBBcFV3Q2dZSQpLb1pJemowRUF3SURTUUF3UmdJaEFPWkhZUG5aTEV5WlEvejZ2Mm9kYWM2WmZhTXYzVzlBUmlKNE9pNnF5dW5GCkFpRUFvTDhUb1JoVUpaL3pOSTY2N1VMR0JpeUdTU1p3L0R0UHFoTnU5RkVQQWc0PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcFFJQkFBS0NBUUVBNGRHejZsYktsUUFXa0J1K2pwRjgrM0t5RFBQZnVhMmVOWFZSWHJVTmY4SDVFYktkCm9ub0tma3VWUzZZZGFTWUNvUm1EbDgxTVRJV212bklrT3duamplWWFoV1FLOEp6STRqb3R5SVAwNVFQRVI1dzQKL1hrQ0g0SU16U2RNTSsvTDhjT2IzYkhDSkI2OS9Wd2llbHRCT000Umt0aTlweDBGUEdKdlVxUlI5dU9nVXhnRgpMaTFlSkhlQnJDSUJEN3I1Zkg3dE5NMTdYcGNvNUpaK0J3a0pMdnZ4V1lqOXZ5U0NDRmhJOWpydWkwR0Q1OXVtCnNya2VIbkNKSzk3U00wVmZuZndmQTFkVFFmZWdpVWRiZUFOWXI5MytSZVZEc20zTTRmYWJ1eGRYTERIMFpRZzIKTVc4emk0VUFLOFNac242b0c0a0tZRlBuZERyZ3VzcnZ5dy84c1FJREFRQUJBb0lCQUR1MEJMeE5MQXhPMUtoUApIWWQyQWJROU04UG02bHllQVhraXhsdWl4S25sYitOMDlPWlRHOWtlUkorV2tLb1BLWnpNTVJWK2F0REVlVHhhCjB5ZGt5dXZtVFZhOUI0TnNBRlNIaXprN1loRDJlUHR4MjBOd3JkWUV2VHUwU3hwa0tPaUhqZnNFRjA4VGJhbkIKcFQveVJvRXRRa292MFp5UU9LVXBaVU5WUEhKb1p0RkplNXlPK1crZmx6cmFSeDJmVWlsZlZCbm5uT0YxcDFGMAp1azhIa2xFZ3BUVkRlV1RKa0tydlM2L09sMGNhSEhiSTVoNENIL1pzY0R5SVU4bVd0aS9TYTBHOVZjb3pVRUgrCm5EaDFPeTFQZ1FudEg3YWcrQzkxcUZuTUE2QnI3ZzdkWFllVHVpQmVNbzV5UG40aitnNzBVU0JYUVNzM090UEwKeE45VTNwMENnWUVBL2xjand3YkNXZC9PcXRsb0dJbGhGVkpRc0hYd2pzdy91cVNMNkRYRTlQQkJ3U01LOHY4VAo4Z2pwZ2I2ZVpQQjRUQW1Ob1c1Rm1tbTFuNjV0LzlETVRhZE4yMFNuTmJnUWxEQVN6OEUvNDZjMEdLUkRBTjhZClBMVG13MWh4QktIc0dRaTlieUNuTnJPc1M3NzBNM3VTeGtobFpWQmxrd21KTm5mUUp2QlgyZGNDZ1lFQTQwcnIKaXZvK1MwQmYzcExDWTdBR0gwL29ZLytRdUVEczZLdk9pMnR3NHFwekhnNWlTUmhuSHMxTmpqNm5wWlBaMkpwbApMSUthd1o1TDJ6QkhmaEVzOEpnM3NuTG1ieEpySi95N21QTnpkVHVSSlBMM1BEbVVVRlFaU2Y3YlFPL21PbmZFClEzZ0IrNE1VWlRrNVdDaCtrNVJQM1RJejFqd0hvMVQ3S0txV1hMY0NnWUVBelNPRmdaaWpDeEE3eFl0Q3JYK28Kb1NUYVZlbGFWQ0tqU0N2TmVFWmVERnozL0FvQ204bG0wZkdrUFBSOUZ0YnBnQks0ZkRyUHd1SitEa1FIRHF6ZgpDOGJrUWZWV2xEcFlqTjFWWHVIMFlPNk1VMCt4aHpOcGZoVStodEovbllmb1FLek85YUcxbktaQVVudTZ4UWRuCmM2d1N0Q3VyTVhRZ2lxRUtiMDJzM2RNQ2dZRUF3SWpuUzl1OHh3dnA2ZVZScXhZaHFZYUw2YUZFR3dCTWJxK1MKajhGY1ozVlJmSVZjdG1Sb2Zjd1ZSVWhIeE5lZ2NuNGU4L3hTVVc3Zy9QUkJxMFdyVnNicWIwd3JiSzBpZmtYMQpONVFLR3FWeHh1WFZqbnVMNmh2RExFNHB0akZCU2dmSUJncnpTdlYzWW1OOTh2S2lmaXJsR0E5OW41MU1Md3crCmtPMG4zN01DZ1lFQTN1TGJQTG45SjhPT3ZRWjk3eThhQkdaZ1RjdlhOeUpnTHhJTW14NGtoc3pGaTBqMUFhY1MKZ090MEVSWEN0VEQwT2hkS2RWWDE4ZmREZ1BOZUU2MzhEenIxN001NTlIbHc1ZGJJdHQ4MllrV01PYU5SMlJHVwpMcmMreDluUWpvNVNhOUwwZXUwcEQxM0NIS1FCZ2RHNDA0bEh2UnNjT0I5WmRKa29ZeWF0a3cwPQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo= kind: Secret metadata: name: replication-secrets-region-b type: kubernetes.io/tls --- ### This is the pre-provisioned client certificate which is signed by certificate in client-ca-secrets apiVersion: v1 data: tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNYekNDQWdTZ0F3SUJBZ0lSQUw0N2V5eXEydzNEN0gwM2RPaE9iaFF3Q2dZSUtvWkl6ajBFQXdJd0lqRWcKTUI0R0ExVUVBeE1YYlhrdGMyVnNabk5wWjI1bFpDMWpiR2xsYm5RdFkyRXdIaGNOTWpReE1URTVNVE14T1RVeQpXaGNOTWpVd01qRTNNVE14T1RVeVdqQWNNUm93R0FZRFZRUUREQkZ6ZEhKbFlXMXBibWRmY21Wd2JHbGpZVENDCkFTSXdEUVlKS29aSWh2Y05BUUVCQlFBRGdnRVBBRENDQVFvQ2dnRUJBT0hScytwV3lwVUFGcEFidm82UmZQdHkKc2d6ejM3bXRualYxVVY2MURYL0IrUkd5bmFKNkNuNUxsVXVtSFdrbUFxRVpnNWZOVEV5RnByNXlKRHNKNDQzbQpHb1ZrQ3ZDY3lPSTZMY2lEOU9VRHhFZWNPUDE1QWgrQ0RNMG5URFB2eS9IRG05Mnh3aVFldmYxY0lucGJRVGpPCkVaTFl2YWNkQlR4aWIxS2tVZmJqb0ZNWUJTNHRYaVIzZ2F3aUFRKzYrWHgrN1RUTmUxNlhLT1NXZmdjSkNTNzcKOFZtSS9iOGtnZ2hZU1BZNjdvdEJnK2ZicHJLNUhoNXdpU3ZlMGpORlg1MzhId05YVTBIM29JbEhXM2dEV0svZAova1hsUTdKdHpPSDJtN3NYVnl3eDlHVUlOakZ2TTR1RkFDdkVtYkorcUJ1SkNtQlQ1M1E2NExySzc4c1AvTEVDCkF3RUFBYU5XTUZRd0RnWURWUjBQQVFIL0JBUURBZ09JTUJNR0ExVWRKUVFNTUFvR0NDc0dBUVVGQndNQ01Bd0cKQTFVZEV3RUIvd1FDTUFBd0h3WURWUjBqQkJnd0ZvQVVscmFqNDFKcFROeVRsMkRmTGkzcVZvbXBBcFV3Q2dZSQpLb1pJemowRUF3SURTUUF3UmdJaEFPWkhZUG5aTEV5WlEvejZ2Mm9kYWM2WmZhTXYzVzlBUmlKNE9pNnF5dW5GCkFpRUFvTDhUb1JoVUpaL3pOSTY2N1VMR0JpeUdTU1p3L0R0UHFoTnU5RkVQQWc0PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcFFJQkFBS0NBUUVBNGRHejZsYktsUUFXa0J1K2pwRjgrM0t5RFBQZnVhMmVOWFZSWHJVTmY4SDVFYktkCm9ub0tma3VWUzZZZGFTWUNvUm1EbDgxTVRJV212bklrT3duamplWWFoV1FLOEp6STRqb3R5SVAwNVFQRVI1dzQKL1hrQ0g0SU16U2RNTSsvTDhjT2IzYkhDSkI2OS9Wd2llbHRCT000Umt0aTlweDBGUEdKdlVxUlI5dU9nVXhnRgpMaTFlSkhlQnJDSUJEN3I1Zkg3dE5NMTdYcGNvNUpaK0J3a0pMdnZ4V1lqOXZ5U0NDRmhJOWpydWkwR0Q1OXVtCnNya2VIbkNKSzk3U00wVmZuZndmQTFkVFFmZWdpVWRiZUFOWXI5MytSZVZEc20zTTRmYWJ1eGRYTERIMFpRZzIKTVc4emk0VUFLOFNac242b0c0a0tZRlBuZERyZ3VzcnZ5dy84c1FJREFRQUJBb0lCQUR1MEJMeE5MQXhPMUtoUApIWWQyQWJROU04UG02bHllQVhraXhsdWl4S25sYitOMDlPWlRHOWtlUkorV2tLb1BLWnpNTVJWK2F0REVlVHhhCjB5ZGt5dXZtVFZhOUI0TnNBRlNIaXprN1loRDJlUHR4MjBOd3JkWUV2VHUwU3hwa0tPaUhqZnNFRjA4VGJhbkIKcFQveVJvRXRRa292MFp5UU9LVXBaVU5WUEhKb1p0RkplNXlPK1crZmx6cmFSeDJmVWlsZlZCbm5uT0YxcDFGMAp1azhIa2xFZ3BUVkRlV1RKa0tydlM2L09sMGNhSEhiSTVoNENIL1pzY0R5SVU4bVd0aS9TYTBHOVZjb3pVRUgrCm5EaDFPeTFQZ1FudEg3YWcrQzkxcUZuTUE2QnI3ZzdkWFllVHVpQmVNbzV5UG40aitnNzBVU0JYUVNzM090UEwKeE45VTNwMENnWUVBL2xjand3YkNXZC9PcXRsb0dJbGhGVkpRc0hYd2pzdy91cVNMNkRYRTlQQkJ3U01LOHY4VAo4Z2pwZ2I2ZVpQQjRUQW1Ob1c1Rm1tbTFuNjV0LzlETVRhZE4yMFNuTmJnUWxEQVN6OEUvNDZjMEdLUkRBTjhZClBMVG13MWh4QktIc0dRaTlieUNuTnJPc1M3NzBNM3VTeGtobFpWQmxrd21KTm5mUUp2QlgyZGNDZ1lFQTQwcnIKaXZvK1MwQmYzcExDWTdBR0gwL29ZLytRdUVEczZLdk9pMnR3NHFwekhnNWlTUmhuSHMxTmpqNm5wWlBaMkpwbApMSUthd1o1TDJ6QkhmaEVzOEpnM3NuTG1ieEpySi95N21QTnpkVHVSSlBMM1BEbVVVRlFaU2Y3YlFPL21PbmZFClEzZ0IrNE1VWlRrNVdDaCtrNVJQM1RJejFqd0hvMVQ3S0txV1hMY0NnWUVBelNPRmdaaWpDeEE3eFl0Q3JYK28Kb1NUYVZlbGFWQ0tqU0N2TmVFWmVERnozL0FvQ204bG0wZkdrUFBSOUZ0YnBnQks0ZkRyUHd1SitEa1FIRHF6ZgpDOGJrUWZWV2xEcFlqTjFWWHVIMFlPNk1VMCt4aHpOcGZoVStodEovbllmb1FLek85YUcxbktaQVVudTZ4UWRuCmM2d1N0Q3VyTVhRZ2lxRUtiMDJzM2RNQ2dZRUF3SWpuUzl1OHh3dnA2ZVZScXhZaHFZYUw2YUZFR3dCTWJxK1MKajhGY1ozVlJmSVZjdG1Sb2Zjd1ZSVWhIeE5lZ2NuNGU4L3hTVVc3Zy9QUkJxMFdyVnNicWIwd3JiSzBpZmtYMQpONVFLR3FWeHh1WFZqbnVMNmh2RExFNHB0akZCU2dmSUJncnpTdlYzWW1OOTh2S2lmaXJsR0E5OW41MU1Md3crCmtPMG4zN01DZ1lFQTN1TGJQTG45SjhPT3ZRWjk3eThhQkdaZ1RjdlhOeUpnTHhJTW14NGtoc3pGaTBqMUFhY1MKZ090MEVSWEN0VEQwT2hkS2RWWDE4ZmREZ1BOZUU2MzhEenIxN001NTlIbHc1ZGJJdHQ4MllrV01PYU5SMlJHVwpMcmMreDluUWpvNVNhOUwwZXUwcEQxM0NIS1FCZ2RHNDA0bEh2UnNjT0I5WmRKa29ZeWF0a3cwPQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo= kind: Secret metadata: name: replication-secrets-region-c type: kubernetes.io/tls --- ### This is the client CA certificate, which will be used to sign other client certificate apiVersion: v1 data: ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJoakNDQVN1Z0F3SUJBZ0lSQU9ZYmNIcmxuSVgzcU55bi8wWkNSem93Q2dZSUtvWkl6ajBFQXdJd0lqRWcKTUI0R0ExVUVBeE1YYlhrdGMyVnNabk5wWjI1bFpDMWpiR2xsYm5RdFkyRXdIaGNOTWpReE1URTVNVE14T0RVMgpXaGNOTWpVd01qRTNNVE14T0RVMldqQWlNU0F3SGdZRFZRUURFeGR0ZVMxelpXeG1jMmxuYm1Wa0xXTnNhV1Z1CmRDMWpZVEJaTUJNR0J5cUdTTTQ5QWdFR0NDcUdTTTQ5QXdFSEEwSUFCQ3gvRHNQMHVPeXFEQjJRbjkzaG40OUQKVEZUOTVrOVpRY2lSeHoyWnMzZ1pWdms0TS80MzZRK3ZVTmZsMDJBS2s3ZWp2Q1YvQ29aYUFIUmkra3NOSkdLagpRakJBTUE0R0ExVWREd0VCL3dRRUF3SUNwREFQQmdOVkhSTUJBZjhFQlRBREFRSC9NQjBHQTFVZERnUVdCQlNXCnRxUGpVbWxNM0pPWFlOOHVMZXBXaWFrQ2xUQUtCZ2dxaGtqT1BRUURBZ05KQURCR0FpRUFveHowZENYZnlqZFIKckhjN3YvTjh6OFdDYWxSMEJrOTgwUFhWL0NNbVU4RUNJUUNsRVRkRnZncVFYWTM2UHUzSGNiS1ZURnJ1aDJkUQpMaStZQUxHSGI3aGZ5QT09Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K kind: Secret metadata: name: client-ca-secrets type: Opaque