Certificate Syncs are configured per Application. First select which certificate to sync, then configure the Nutanix Prism Central destination.
Prerequisites
Before setting up the sync, gather the following from your Nutanix environment:- A Nutanix Prism Central instance reachable from Infisical over HTTPS (hostname or IP address, port default
9440), either directly or via an Infisical Gateway. - A Prism Central account or API key with the Cluster Admin role on the target cluster.
- A Nutanix Prism Central Connection correctly configured.
Create a Nutanix Prism Central Sync
- Infisical UI
- API
- In your Application, go to the Certificate Syncs tab and click Create Sync.
- Select the Nutanix Prism Central option.
-
Configure the Destination:
- Nutanix Prism Central Connection: Choose the connection to authenticate with.
- Cluster: From the list of clusters available in Prism Central, select the target cluster.
-
Configure the Sync Options:
- Auto-Sync Enabled: Automatically update the certificate on the Nutanix cluster whenever it is renewed or updated in Infisical.
-
Configure the Details:
- Name: A name for this sync.
- Description: Optional description.
- Select the certificate to sync.
- Review and click Create Sync.
How It Works
When a sync runs, Infisical calls the Nutanix Clustermgmt API v4 to replace the SSL certificate on the selected cluster:- Connects to Prism Central using the configured credentials (Basic Auth or API Key).
- Takes the certificate associated with the sync.
- Configures the certificate and private key onto the Nutanix cluster.
Each Nutanix Prism Central sync targets a single cluster. To update multiple clusters, create one sync per cluster.
Certificate Management
The Nutanix Prism Central Certificate Sync provides:- Automatic Deployment: Replace the SSL certificate on the target Nutanix cluster whenever the synced certificate changes in Infisical.
- Certificate Updates: Push renewed certificates to the cluster automatically when auto-sync is enabled.
Certificate removal is not supported for Nutanix Prism Central. A cluster always has exactly one active SSL certificate, which can only be replaced, not deleted.
Manual Certificate Sync
You can manually trigger certificate synchronization to the Nutanix cluster using the sync certificates functionality. This is useful for:- Initial setup when deploying a certificate to a cluster for the first time
- Testing certificate sync configurations
- Force sync after making changes
Certificate Renewal Behavior
When a certificate is renewed in Infisical, the renewed certificate is automatically pushed to the Nutanix cluster on the next sync. If Auto-Sync is enabled, this happens without any manual action.FAQ
Can I import certificates from Nutanix back into Infisical?
Can I import certificates from Nutanix back into Infisical?
No. The Nutanix API does not allow private key extraction, so importing certificates from Nutanix into Infisical is not supported.
What happens if my Prism Central uses a self-signed TLS certificate?
What happens if my Prism Central uses a self-signed TLS certificate?
When creating the App Connection, disable the Reject Unauthorized option to allow connections to Prism Central instances with self-signed or untrusted TLS certificates. Use this only in trusted network environments.
Which Nutanix API version is used?
Which Nutanix API version is used?
Infisical uses the Nutanix Clustermgmt API v4.2 to manage SSL certificates on clusters.
Do I need to restart the cluster after updating the certificate?
Do I need to restart the cluster after updating the certificate?
No restart is required. Nutanix applies the new SSL certificate as an async task. Infisical waits for the task to complete before marking the sync as successful.
What’s Next?
NetScaler
Deploy certificates to Citrix NetScaler ADC appliances.
Auto-Renewal
Enable automatic certificate renewal and syncing.
Alerting
Get notified about certificate lifecycle events.
Other Sync Destinations
View all supported sync destinations.