Namespace Policy
The QHxPolicy is a singleton, namespaced Kubernetes resource used to define
policy for an entire Kubernetes namespace. At most one such policy can be
created per namespace.
- Resource Type Names & Abbreviations
QHxPolicy,qhxp- API Version
qhx.dev/v1- Namespaced
- Yes
QHx can operate without a QHxPolicy being created. A QHxPolicy is only
needed if it is desired to define cryptographic policy for a specific namespace
which overrides cluster-level policy.
If a QHxPolicy is not created for a given namespace, or if a specific
configuration value is not set in a given QHxPolicy, the cluster-level value
configured in QHxClusterPolicy is used.
Reference
Section titled “Reference”spec.signatureAlgorithm (string)
Section titled “spec.signatureAlgorithm (string)”Default: inherit
Permitted values: inherit, mldsa44, mldsa65, mldsa87, dilithium3,
ec-p256†, ec-p384†, rsa-2048†, rsa-4096†
† Non-quantum-safe conventional algorithms supported for compatibility.
If this setting is set to inherit, the value is inherited from
QHxClusterPolicy (if created), or from the system-level default.
mldsa44, mldsa65 and mldsa87 correspond to quantum-safe ML-DSA (FIPS
204). ec-p256 and ec-p384 correspond to NIST ECDSA and represent
non-quantum-safe conventional signature algorithms. rsa-2048 and rsa-2048
correspond to the RSA non-quantum-safe conventional signature algorithm.
Example
Section titled “Example”An annotated example QHxPolicy is as follows:
---apiVersion: qhx.dev/v1kind: QHxPolicy
metadata: name: qhx-local-policy
spec: ## Use the ML-DSA-65 post-quantum-safe NIST signature algorithm. signatureAlgorithm: mldsa65