Subscription configuration
Each subscribed customer receives a writable config repository and a
read-only credentials repository on CNX's Git server.
Repository access uses the customer's organisation SSO integration; operators
coordinate access with their internal SSO and repository access team. Kafka
consumers use the separately issued client-certificate identity.
The customer account is assigned by CNX; configuration files do not override it.
Config repository
README.md
subscriptions.yml
csr/
siem-primary.pemversion: 1
subscriptions:
- id: siem-primary
name: "Primary SIEM"
csr: csr/siem-primary.pem
feeds:
- dns.logs.ops
- dns.logs.platform| Field | Meaning |
|---|---|
version | Configuration format version, 1 |
subscriptions | List of subscriber definitions |
id | Unique, stable subscriber handle; siem-primary is an example. Changing it creates a new subscriber identity. |
name | Optional operator label |
csr | Repository path to the PEM CSR for the subscriber's locally held key |
feeds | Requested logical feed names, subject to account entitlements |
The config README supplies the accepted subscriber-ID syntax. The
feed catalog defines the logical feed names. CNX controls feed
definitions and service limits; these are not customer-editable settings.
Credentials repository
cnx_ca.crt
cnx_ica_service.crt
cnx_ica_external_client.crt
subscribers/
<subscription-id>/
client.crt
client-fullchain.crt
connection.yml
manifest.yml| File | Contents |
|---|---|
cnx_ca.crt | CNX root CA, shared at the repository root |
cnx_ica_service.crt | Intermediate CA that issues CNX broker certificates, shared at the repository root |
cnx_ica_external_client.crt | Intermediate CA that issues subscriber client certificates, shared at the repository root |
subscribers/<subscription-id>/client.crt | Issued client leaf certificate, PEM |
subscribers/<subscription-id>/client-fullchain.crt | Client leaf plus its issuing intermediate CA, bundled PEM |
subscribers/<subscription-id>/connection.yml | Bootstrap endpoint, topics, and assigned consumer group |
subscribers/<subscription-id>/manifest.yml | Certificate and subscription metadata |
Broker trust uses cnx_ca.crt and cnx_ica_service.crt. The external-client
ICA identifies the issuer of your client certificate; it is separate from
the broker's service ICA.
The default branch holds the current successfully published credentials. Private keys remain with the customer. Local conversion to PKCS12 or JKS combines the delivered certificates with that private key.
The repository README links to Connecting a Kafka consumer
for setup instructions. connection.yml supplies the subscriber-specific
values used by those instructions. Its contents are described above; the
issued file defines the exact YAML layout and values for your subscription.
Identity and renewal
CNX assigns each subscription a certificate identity, selected-topic access, and a dedicated consumer group. CSR subject and extension requests do not control the issued identity or permissions. Certificates are issued through CNX's HSM-backed signing service for client authentication, with a 365-day validity period and renewal when fewer than 30 days remain.
Publication of a renewal does not update the consumer's local files or keystore; the customer deploys the replacement. Git history preserves prior certificates, but access is controlled by certificate revocation and Kafka permissions.
Removing a subscription from accepted configuration stops new routing and removes its Kafka permissions. Retained topic records expire under the normal retention policy. Invalid configuration or a repository-fetch failure preserves the last accepted configuration. Certificate revocation and final account retirement are handled by CNX.