Skip to content

Namespace Policy

The QHxPolicy is a singleton, namespaced Kubernetes resource used to define policy for an entire Kubernetes namespace. At most one such policy can be created per namespace.

Resource Type Names & Abbreviations
QHxPolicy, qhxp
API Version
qhx.dev/v1
Namespaced
Yes

QHx can operate without a QHxPolicy being created. A QHxPolicy is only needed if it is desired to define cryptographic policy for a specific namespace which overrides cluster-level policy.

If a QHxPolicy is not created for a given namespace, or if a specific configuration value is not set in a given QHxPolicy, the cluster-level value configured in QHxClusterPolicy is used.

Default: inherit

Permitted values: inherit, mldsa44, mldsa65, mldsa87, dilithium3, ec-p256†, ec-p384†, rsa-2048†, rsa-4096†

† Non-quantum-safe conventional algorithms supported for compatibility.

If this setting is set to inherit, the value is inherited from QHxClusterPolicy (if created), or from the system-level default.

mldsa44, mldsa65 and mldsa87 correspond to quantum-safe ML-DSA (FIPS 204). ec-p256 and ec-p384 correspond to NIST ECDSA and represent non-quantum-safe conventional signature algorithms. rsa-2048 and rsa-2048 correspond to the RSA non-quantum-safe conventional signature algorithm.

An annotated example QHxPolicy is as follows:

---
apiVersion: qhx.dev/v1
kind: QHxPolicy
metadata:
name: qhx-local-policy
spec:
## Use the ML-DSA-65 post-quantum-safe NIST signature algorithm.
signatureAlgorithm: mldsa65