Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Memilih tingkat operasi
Certificate Authority Service menawarkan dua tingkat operasi yang dioptimalkan untuk workload untuk kumpulan
certificate authority (CA).
DevOps: Berfokus pada penerbitan sertifikat berumur pendek dalam jumlah besar yang
ditemukan di aplikasi berbasis microservice.
Enterprise: Berfokus pada volume yang lebih rendah, penerbitan sertifikat dengan masa berlaku lama
yang biasanya ditemukan di perangkat dan identitas pengguna, dengan pengelolaan siklus proses
yang penting.
Kedua tingkat tersebut dapat digunakan dengan jenis aplikasi apa pun dan kedua tingkat tersebut mendukung semua
linimasa sertifikat yang ditentukan pengguna. Aplikasi berbasis microservice mungkin
mendapatkan manfaat dari throughput pembuatan sertifikat yang lebih tinggi untuk kumpulan CA DevOps, yang dapat mendukung
lingkungan dengan tingkat startup beban kerja yang lebih tinggi dan memungkinkan sertifikat
dirotasi lebih sering. Tingkat DevOps mungkin juga lebih cocok untuk sertifikat dengan masa berlaku
yang lebih singkat karena tidak memiliki pengelolaan siklus proses sertifikat.
Beberapa perbedaan antara tingkat DevOps dan Enterprise disebutkan dalam tabel berikut:
Paket DevOps
Paket Enterprise
Dukungan HSM untuk kunci CA
Ya
Ya
Kunci CA yang dikelola pelanggan, didukung melalui Cloud KMS
Tidak
Ya
Dukungan untuk mencantumkan, mendeskripsikan, dan mencabut sertifikat
Tidak
Ya
Kuota QPS untuk CA*
25
7
* Kuota QPS mengacu pada jumlah maksimum sertifikat yang dapat
diterbitkan per detik oleh CA tertentu. Kumpulan CA dapat mencapai total QPS efektif yang lebih tinggi dengan beberapa CA.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-12 UTC."],[[["\u003cp\u003eCertificate Authority Service provides two operation tiers for CA pools: DevOps and Enterprise.\u003c/p\u003e\n"],["\u003cp\u003eThe DevOps tier is designed for high-volume, short-lived certificates, ideal for microservice applications, while the Enterprise tier supports lower-volume, long-lived certificates, suitable for devices and user identities.\u003c/p\u003e\n"],["\u003cp\u003eThe chosen operation tier for a CA pool is permanent and cannot be altered after creation.\u003c/p\u003e\n"],["\u003cp\u003eThe DevOps tier offers a higher QPS (Queries Per Second) quota for CAs (25) compared to the Enterprise tier (7), enabling faster certificate issuance.\u003c/p\u003e\n"],["\u003cp\u003eThe Enterprise tier supports certificate lifecycle management features, such as listing, describing, and revoking certificates, which are not available in the DevOps tier.\u003c/p\u003e\n"]]],[],null,["# Select the operation tiers\n==========================\n\nCertificate Authority Service offers two workload-optimized operation tiers for certificate\nauthority (CA) pools.\n\n- **DevOps**: Focused on high volume, short-lived certificate issuance which is found in microservice-based applications.\n- **Enterprise**: Focused on lower volume, long-lived certificate issuance which is normally found in devices and user identity, where lifecycle management is important.\n\n| **Note:** The operation tier is set when the CA pool is created and cannot be changed afterwards.\n\nBoth tiers can be used with any kind of application and both tiers support all\nuser-specified certificate timelines. Microservice-based applications might\nbenefit from the higher certificate creation throughput for DevOps CA pools, which can support\nenvironments with higher rates of workload startup and allow certificates to be\nrotated more frequently. DevOps tier might also be more suited for shorter-lived\ncertificates because it lacks certificate lifecycle management.\n\nFor information on how to get a rough estimate of the certificate creation throughput, see\n[Increase certificate creation throughput using CA pools](/certificate-authority-service/docs/higher-qps).\n\nSome differences between the DevOps and the Enterprise tier are mentioned in the following table:\n\n\\* QPS quota refers to the maximum number of certificates that can be\nissued per second by a given CA. A CA pool can reach a higher total effective QPS with multiple CAs.\n\nWhat's next\n-----------\n\n- Learn about [CA pools](/certificate-authority-service/docs/ca-pool).\n- Learn how to [create CA pools](/certificate-authority-service/docs/creating-ca-pool).\n- Learn how to [increase certificate creation throughput using CA pools](/certificate-authority-service/docs/higher-qps).\n- Learn about [quotas and limits](/certificate-authority-service/quotas)."]]