package caclient

import ""


var (

    // ProvCert is the environment controlling the use of pre-provisioned certs, for VMs.
    // May also be used in K8S to use a Secret to bootstrap (as a 'refresh key'), but use short-lived tokens
    // with extra SAN (labels, etc) in data path.
    ProvCert = env.RegisterStringVar("PROV_CERT", "",
        "Set to a directory containing provisioned certs, for VMs").Get()

func NewCitadelClient Uses

func NewCitadelClient(endpoint string, tls bool, rootCert []byte) (caClientInterface.Client, error)

NewCitadelClient create a CA client for Citadel.

