Updated on 2026-09-30 GMT+08:00

Revoking a Cluster Access Certificate

Function

This API is used to revoke an access certificate of a specified cluster.

After the certificate is revoked, the certificate and kubectl configuration file originally downloaded by the certificate applicant can no longer be used to access the cluster. In this case, the certificate applicant can download the certificate or kubectl configuration file again and use the newly downloaded file to access the cluster.

Constraints

Before revoking a cluster access certificate, you need to get the user ID, which can be obtained in either of the following ways:

  • Method 1: Obtain the certificate downloaded by the applicant. The name (CN - Common Name) of the certificate is the required user ID.

  • Method 2: If you cannot obtain the certificate downloaded by the applicant, use CTS to obtain the events of deleting a user (deleteUser) and deleting an agency (deleteAgency). The resource IDs of the events are the IDs of the deleted user and delegated account, respectively.

If the ID still cannot be obtained, submit a service ticket.

Calling Method

For details, see Calling APIs.

URI

POST /api/v3/projects/{project_id}/clusters/{cluster_id}/clustercertrevoke

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Details:

Project ID. For details about how to obtain the value, see How to Obtain Parameters in the API URI.

Constraints:

None

Options:

Project IDs of the account

Default value:

N/A

cluster_id

Yes

String

Details:

Cluster ID. For details about how to obtain the value, see How to Obtain Parameters in the API URI.

Constraints:

None

Options:

Cluster IDs

Default value:

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

Content-Type

Yes

String

Definition:

Type (or format) of the request body. The default value is application/json. Other values of this field will be provided for specific APIs, if any.

Constraints:

GET requests are not validated.

Range:

N/A

Default Value:

N/A

X-Auth-Token

Yes

String

Details:

Requests for calling an API can be authenticated using either a token or AK/SK. If token-based authentication is used, this parameter is mandatory and must be set to a user token. For details, see Obtaining a User Token.

Constraints:

None

Options:

N/A

Default value:

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

userId

No

String

Definition

User ID. For details about how to obtain the ID, see the constraints of this API.

Constraints

This parameter is mutually exclusive with agencyId. Specify either of them.

Range

N/A

Default Value

N/A

agencyId

No

String

Definition

Agency ID. For details about how to obtain the ID, see the constraints of this API.

Constraints

This parameter is mutually exclusive with userId. Specify either of them.

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

None

Example Requests

POST /api/v3/projects/{project_id}/clusters/{cluster_id}/clustercertrevoke

{
  "userId" : "537e7a3bd**********6c5657fd908ff"
}

Example Responses

None

Status Codes

Status Code

Description

200

Cluster access certificate is revoked.

Error Codes

See Error Codes.