Subscription configuration

Each subscribed customer receives a writable config repository and a read-only credentials repository on CNX's Git server. Repository access uses the customer's organisation SSO integration; operators coordinate access with their internal SSO and repository access team. Kafka consumers use the separately issued client-certificate identity.

The customer account is assigned by CNX; configuration files do not override it.

Config repository

README.md
subscriptions.yml
csr/
  siem-primary.pem
version: 1
subscriptions:
  - id: siem-primary
    name: "Primary SIEM"
    csr: csr/siem-primary.pem
    feeds:
      - dns.logs.ops
      - dns.logs.platform
FieldMeaning
versionConfiguration format version, 1
subscriptionsList of subscriber definitions
idUnique, stable subscriber handle; siem-primary is an example. Changing it creates a new subscriber identity.
nameOptional operator label
csrRepository path to the PEM CSR for the subscriber's locally held key
feedsRequested logical feed names, subject to account entitlements

The config README supplies the accepted subscriber-ID syntax. The feed catalog defines the logical feed names. CNX controls feed definitions and service limits; these are not customer-editable settings.

Credentials repository

cnx_ca.crt
cnx_ica_service.crt
cnx_ica_external_client.crt
subscribers/
  <subscription-id>/
    client.crt
    client-fullchain.crt
    connection.yml
    manifest.yml
FileContents
cnx_ca.crtCNX root CA, shared at the repository root
cnx_ica_service.crtIntermediate CA that issues CNX broker certificates, shared at the repository root
cnx_ica_external_client.crtIntermediate CA that issues subscriber client certificates, shared at the repository root
subscribers/<subscription-id>/client.crtIssued client leaf certificate, PEM
subscribers/<subscription-id>/client-fullchain.crtClient leaf plus its issuing intermediate CA, bundled PEM
subscribers/<subscription-id>/connection.ymlBootstrap endpoint, topics, and assigned consumer group
subscribers/<subscription-id>/manifest.ymlCertificate and subscription metadata

Broker trust uses cnx_ca.crt and cnx_ica_service.crt. The external-client ICA identifies the issuer of your client certificate; it is separate from the broker's service ICA.

The default branch holds the current successfully published credentials. Private keys remain with the customer. Local conversion to PKCS12 or JKS combines the delivered certificates with that private key.

The repository README links to Connecting a Kafka consumer for setup instructions. connection.yml supplies the subscriber-specific values used by those instructions. Its contents are described above; the issued file defines the exact YAML layout and values for your subscription.

Identity and renewal

CNX assigns each subscription a certificate identity, selected-topic access, and a dedicated consumer group. CSR subject and extension requests do not control the issued identity or permissions. Certificates are issued through CNX's HSM-backed signing service for client authentication, with a 365-day validity period and renewal when fewer than 30 days remain.

Publication of a renewal does not update the consumer's local files or keystore; the customer deploys the replacement. Git history preserves prior certificates, but access is controlled by certificate revocation and Kafka permissions.

Removing a subscription from accepted configuration stops new routing and removes its Kafka permissions. Retained topic records expire under the normal retention policy. Invalid configuration or a repository-fetch failure preserves the last accepted configuration. Certificate revocation and final account retirement are handled by CNX.