diff --git a/crdSchemas/challenge_v1.json b/crdSchemas/acme.cert-manager.io/challenge_v1.json
similarity index 100%
rename from crdSchemas/challenge_v1.json
rename to crdSchemas/acme.cert-manager.io/challenge_v1.json
diff --git a/crdSchemas/order_v1.json b/crdSchemas/acme.cert-manager.io/order_v1.json
similarity index 100%
rename from crdSchemas/order_v1.json
rename to crdSchemas/acme.cert-manager.io/order_v1.json
diff --git a/crdSchemas/imageupdater_v1alpha1.json b/crdSchemas/argocd-image-updater.argoproj.io/imageupdater_v1alpha1.json
similarity index 100%
rename from crdSchemas/imageupdater_v1alpha1.json
rename to crdSchemas/argocd-image-updater.argoproj.io/imageupdater_v1alpha1.json
diff --git a/crdSchemas/analysisrun_v1alpha1.json b/crdSchemas/argoproj.io/analysisrun_v1alpha1.json
similarity index 100%
rename from crdSchemas/analysisrun_v1alpha1.json
rename to crdSchemas/argoproj.io/analysisrun_v1alpha1.json
diff --git a/crdSchemas/analysistemplate_v1alpha1.json b/crdSchemas/argoproj.io/analysistemplate_v1alpha1.json
similarity index 100%
rename from crdSchemas/analysistemplate_v1alpha1.json
rename to crdSchemas/argoproj.io/analysistemplate_v1alpha1.json
diff --git a/crdSchemas/application_v1alpha1.json b/crdSchemas/argoproj.io/application_v1alpha1.json
similarity index 100%
rename from crdSchemas/application_v1alpha1.json
rename to crdSchemas/argoproj.io/application_v1alpha1.json
diff --git a/crdSchemas/applicationset_v1alpha1.json b/crdSchemas/argoproj.io/applicationset_v1alpha1.json
similarity index 100%
rename from crdSchemas/applicationset_v1alpha1.json
rename to crdSchemas/argoproj.io/applicationset_v1alpha1.json
diff --git a/crdSchemas/appproject_v1alpha1.json b/crdSchemas/argoproj.io/appproject_v1alpha1.json
similarity index 100%
rename from crdSchemas/appproject_v1alpha1.json
rename to crdSchemas/argoproj.io/appproject_v1alpha1.json
diff --git a/crdSchemas/clusteranalysistemplate_v1alpha1.json b/crdSchemas/argoproj.io/clusteranalysistemplate_v1alpha1.json
similarity index 100%
rename from crdSchemas/clusteranalysistemplate_v1alpha1.json
rename to crdSchemas/argoproj.io/clusteranalysistemplate_v1alpha1.json
diff --git a/crdSchemas/experiment_v1alpha1.json b/crdSchemas/argoproj.io/experiment_v1alpha1.json
similarity index 100%
rename from crdSchemas/experiment_v1alpha1.json
rename to crdSchemas/argoproj.io/experiment_v1alpha1.json
diff --git a/crdSchemas/rollout_v1alpha1.json b/crdSchemas/argoproj.io/rollout_v1alpha1.json
similarity index 100%
rename from crdSchemas/rollout_v1alpha1.json
rename to crdSchemas/argoproj.io/rollout_v1alpha1.json
diff --git a/crdSchemas/attune.io/attunedefaults_v1alpha1.json b/crdSchemas/attune.io/attunedefaults_v1alpha1.json
new file mode 100644
index 0000000..cc32433
--- /dev/null
+++ b/crdSchemas/attune.io/attunedefaults_v1alpha1.json
@@ -0,0 +1,763 @@
+{
+ "description": "AttuneDefaults is the Schema for the attunedefaults API.\nIt defines cluster-scoped default values for AttunePolicy resources.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "AttuneDefaultsSpec defines cluster-scoped default values for AttunePolicy resources.",
+ "properties": {
+ "costPricing": {
+ "description": "CostPricing configures the per-unit pricing used to compute\nEstimatedMonthlySavings. If omitted, defaults to standard\non-demand Linux pricing ($0.031/vCPU-hour, $0.004/GiB-hour).",
+ "properties": {
+ "cpuPerCoreHour": {
+ "description": "CPUPerCoreHour is the cost per vCPU-hour (e.g. \"0.031\").\nDefaults to 0.031 if not specified.",
+ "type": "string"
+ },
+ "memoryPerGiBHour": {
+ "description": "MemoryPerGiBHour is the cost per GiB-hour (e.g. \"0.004\").\nDefaults to 0.004 if not specified.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpu": {
+ "description": "CPU configures default CPU resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "excludeKnownSidecars": {
+ "description": "ExcludeKnownSidecars, when true (the default when unset on both\ndefaults and policy), automatically skips well-known mesh and\nsidecar container names. Set to false cluster-wide to restore\nexclude-only-via-excludedContainers behavior for policies that\ndo not set the field themselves.",
+ "type": "boolean"
+ },
+ "memory": {
+ "description": "Memory configures default memory resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metricsSource": {
+ "description": "MetricsSource configures default metrics source settings.",
+ "properties": {
+ "cloudwatch": {
+ "description": "CloudWatch configures an Amazon CloudWatch Container Insights metrics source.",
+ "properties": {
+ "clusterName": {
+ "description": "ClusterName is the EKS cluster name for Container Insights metrics.\nRequired for metric filtering.",
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the AWS region (e.g. \"us-east-1\"). Required.",
+ "type": "string"
+ },
+ "roleArn": {
+ "description": "RoleARN is an optional IAM role ARN to assume for cross-account access.\nIf not set, uses the pod's service account IAM role (IRSA/Pod Identity).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "clusterName",
+ "region"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpuRecordingMetric": {
+ "description": "CPURecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of rate(container_cpu_usage_seconds_total). Labels must include\nnamespace, pod, and container. When set, the operator does not wrap the\nmetric in rate(). Pair with MemoryRecordingMetric for a recording-rules-only path.",
+ "type": "string"
+ },
+ "datadog": {
+ "description": "Datadog configures a Datadog metrics source.",
+ "properties": {
+ "apiKeySecretRef": {
+ "description": "APIKeySecretRef references a Secret containing the Datadog API key.\nThe Secret must contain an \"api-key\" key and optionally an \"app-key\" key.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "site": {
+ "default": "datadoghq.com",
+ "description": "Site is the Datadog site (e.g. \"datadoghq.com\", \"datadoghq.eu\", \"us5.datadoghq.com\").\nDefaults to \"datadoghq.com\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "apiKeySecretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "historyWindow": {
+ "description": "HistoryWindow is the time window for historical metrics data.\nDefaults to 7d (168h) if not specified.",
+ "type": "string"
+ },
+ "memoryRecordingMetric": {
+ "description": "MemoryRecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of container_memory_working_set_bytes. Same label requirements\nas CPURecordingMetric.",
+ "type": "string"
+ },
+ "minimumDataPoints": {
+ "description": "MinimumDataPoints is the minimum number of data points required\nbefore generating recommendations. Minimum 1, default 48 samples.\nWith the default queryStep of 5m, 48 samples is about 4 hours of data.\nDefaults to 48 if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "podAggregation": {
+ "description": "PodAggregation controls how multi-pod series are reduced in Prometheus\nrange queries for this policy.\n Max (default): max by (container) \u2014 size for the busiest pod; O(containers) series.\n Avg: avg by (container) across pods.\n None: no aggregation (one series per pod; expensive for high replica counts).\nDatadog and CloudWatch already group by container; this field applies to Prometheus.",
+ "enum": [
+ "Max",
+ "Avg",
+ "None"
+ ],
+ "type": "string"
+ },
+ "prometheus": {
+ "description": "Prometheus configures a Prometheus metrics source.",
+ "properties": {
+ "address": {
+ "description": "Address is the URL of the Prometheus-compatible query endpoint.",
+ "type": "string"
+ },
+ "bearerTokenSecret": {
+ "description": "BearerTokenSecret references a Kubernetes Secret containing a bearer\ntoken for authenticating with managed Prometheus services.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Headers are custom HTTP headers added to every query request.\nUse for non-secret tenant or routing headers (e.g. \"X-Scope-OrgID\"\nfor Mimir). Do not put credentials here; use BearerTokenSecret for\nauthentication tokens.",
+ "type": "object"
+ },
+ "queryParameters": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "QueryParameters are appended to every query request URL.\nUse for backend-specific settings such as Thanos deduplication\n(e.g. {\"dedup\": \"true\", \"partial_response\": \"true\"}). Reserved\nquery keys controlled by the operator (`query`, `start`, `end`, `step`,\n`time`, `timeout`) are rejected.",
+ "type": "object"
+ },
+ "tls": {
+ "description": "TLS configures TLS settings for the connection.",
+ "properties": {
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify disables TLS certificate verification.\nUse only for self-signed certificates in development.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "address"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryStep": {
+ "description": "QueryStep is the step interval for Prometheus range queries and ETA\ncalculations. Should match your Prometheus scrape interval for\naccurate time estimates. Minimum 10s, maximum 1h. Default 5m.",
+ "type": "string"
+ },
+ "rateWindow": {
+ "description": "RateWindow is the window used in the PromQL rate() function for CPU\nqueries. Defaults to queryStep if not set. Must be >= 30s and <= historyWindow.\nAdvanced users may set this independently to control CPU rate smoothing\n(e.g. a short rateWindow for responsive tracking with a longer queryStep).",
+ "type": "string"
+ },
+ "vpa": {
+ "description": "VPA configures consumption of existing VerticalPodAutoscaler recommendations.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the VerticalPodAutoscaler object.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the VPA. Defaults to the policy's namespace.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "updateStrategy": {
+ "description": "UpdateStrategy configures default update strategy settings.",
+ "properties": {
+ "autoRevert": {
+ "description": "AutoRevert automatically reverts changes if degradation is detected.\nDefaults to true if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "type": "boolean"
+ },
+ "canary": {
+ "description": "Canary configures canary rollout behavior when Type is Canary.",
+ "properties": {
+ "autoPromote": {
+ "description": "AutoPromote controls whether the operator automatically promotes the\nresize to all pods after the observation period passes without safety\nviolations. When false (default), the user must manually switch the\nmode to Auto to resize the remaining pods.",
+ "type": "boolean"
+ },
+ "observationPeriod": {
+ "description": "ObservationPeriod is how long to observe canary pods before proceeding.",
+ "type": "string"
+ },
+ "percentage": {
+ "description": "Percentage is the percentage of pods to resize first.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "observationPeriod",
+ "percentage"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between successive resize operations.\nDefaults to 1h if not specified.",
+ "type": "string"
+ },
+ "export": {
+ "description": "Export configures how recommendations are exported for external\nconsumption (e.g. GitOps workflows with ArgoCD or Flux).",
+ "properties": {
+ "configMap": {
+ "description": "ConfigMap enables exporting recommendations to ConfigMaps.",
+ "type": "boolean"
+ },
+ "pullRequest": {
+ "description": "PullRequest enables opt-in GitOps PR automation (default off).\nRequires a token Secret and repository identity. Never logs the token.",
+ "properties": {
+ "apiUrl": {
+ "description": "APIURL overrides the API base URL (Enterprise GitHub or self-hosted GitLab).\nDefaults: https://api.github.com or https://gitlab.com/api/v4.",
+ "type": "string"
+ },
+ "baseBranch": {
+ "description": "BaseBranch is the PR target branch. Defaults to \"main\".",
+ "type": "string"
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between PR create/update attempts for this\npolicy. Defaults to 24h.",
+ "type": "string"
+ },
+ "dryRun": {
+ "description": "DryRun logs the intended PR and updates status without calling the\nremote API. Useful for CI and first enablement.",
+ "type": "boolean"
+ },
+ "enabled": {
+ "description": "Enabled turns on PR automation. Default false.",
+ "type": "boolean"
+ },
+ "labels": {
+ "description": "Labels are applied to the pull request when supported by the provider.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum absolute percent change (per container\nresource vs template) required to open or update a PR. Defaults to 10.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "provider": {
+ "description": "Provider is \"github\" or \"gitlab\". Default \"github\".",
+ "enum": [
+ "github",
+ "gitlab"
+ ],
+ "type": "string"
+ },
+ "repository": {
+ "description": "Repository is \"owner/name\" (GitHub) or \"group/project\" (GitLab path).\nRequired when Enabled is true.",
+ "type": "string"
+ },
+ "tokenSecretRef": {
+ "description": "TokenSecretRef references a Secret key holding a PAT / project token.\nGitHub: repo contents + pull requests. GitLab: api scope on the project.\nRequired when Enabled is true.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "includeExplanationsInStatus": {
+ "description": "IncludeExplanationsInStatus controls whether recommendation explanation\nchains are written to status. Set to false on large policies to shrink\nCR size. Default: true.",
+ "type": "boolean"
+ },
+ "initialSizing": {
+ "description": "InitialSizing enables a mutating admission webhook that sets resource\nrequests/limits on new pods at creation time, based on existing\nrecommendations. This eliminates the \"deploy with bad defaults, wait\nfor first reconcile\" gap. Requires the namespace label\nattune.io/initial-sizing=enabled. Defaults to false.",
+ "type": "boolean"
+ },
+ "maxConcurrentResizes": {
+ "default": 1,
+ "description": "MaxConcurrentResizes is the maximum number of pods to resize\nconcurrently within a single reconcile cycle. Default: 1 (serial).",
+ "format": "int32",
+ "maximum": 50,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxStatusRecommendations": {
+ "description": "MaxStatusRecommendations caps how many workload recommendations are\nwritten to status.recommendations. Resizes still use the full in-memory\nset. When the cap is hit, entries with the largest absolute CPU+memory\nrequest change are kept. Default: 100 (operator may override via flag).",
+ "format": "int32",
+ "maximum": 500,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxTotalCpuIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalCPUIncrease is the maximum aggregate CPU increase allowed\nacross all pods in a single reconcile cycle (e.g. \"2000m\", \"4\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxTotalMemoryIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalMemoryIncrease is the maximum aggregate memory increase\nallowed across all pods in a single reconcile cycle (e.g. \"4Gi\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resizeMethod": {
+ "description": "ResizeMethod controls what happens when an in-place resize fails.\n InPlaceOnly (default): skip the pod and retry next cycle.\n InPlaceOrRecreate: fall back to pod eviction if in-place resize\n fails or is marked Infeasible by kubelet. The owning controller\n recreates the pod with updated resources. Evictions respect\n PodDisruptionBudgets and never evict the last replica.\nDefaults to InPlaceOnly if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "InPlaceOnly",
+ "InPlaceOrRecreate"
+ ],
+ "type": "string"
+ },
+ "safetyObservationPeriod": {
+ "description": "SafetyObservationPeriod is how long to observe a pod after resize before\nconcluding the resize is safe. Applies to all modes (Auto, OneShot, Canary).\nTakes precedence over canary.observationPeriod when set. Must be >= 1m.\nDefaults to 5m if neither this nor canary.observationPeriod is set.",
+ "type": "string"
+ },
+ "schedule": {
+ "description": "Schedule restricts when resize operations can occur. Recommendations\nare always computed; only resize execution is gated. If omitted,\nresizes can occur at any time (current behavior).",
+ "properties": {
+ "daysOfWeek": {
+ "description": "DaysOfWeek restricts resizes to specific days. Values: Monday through Sunday.\nIf omitted, all days are allowed.",
+ "items": {
+ "enum": [
+ "Monday",
+ "Tuesday",
+ "Wednesday",
+ "Thursday",
+ "Friday",
+ "Saturday",
+ "Sunday"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "timezone": {
+ "default": "UTC",
+ "description": "Timezone for interpreting window start/end times. Must be a valid\nIANA timezone name (e.g. \"America/New_York\"). Default: \"UTC\".",
+ "type": "string"
+ },
+ "windows": {
+ "description": "Windows defines time-of-day ranges when resizes are allowed.\nIf multiple windows are specified, resizes are allowed during any of them.",
+ "items": {
+ "description": "TimeWindow defines a daily time range.",
+ "properties": {
+ "end": {
+ "description": "End time in HH:MM format (24-hour). If end < start, the window\nwraps past midnight (e.g. start=22:00, end=06:00).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ },
+ "start": {
+ "description": "Start time in HH:MM format (24-hour).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sloGuardrails": {
+ "description": "SLOGuardrails defines application-level SLO metrics to check after\na resize. If any metric breaches its threshold during the safety\nobservation period, the resize is automatically reverted.\nRequires a Prometheus-compatible metrics source.",
+ "items": {
+ "description": "SLOGuardrail defines an application-level metric that is checked after\na resize to detect degradation. If the metric breaches the threshold,\nthe safety monitor triggers an automatic revert.",
+ "properties": {
+ "comparison": {
+ "default": "above",
+ "description": "Comparison is \"above\" or \"below\". \"above\" reverts when value > threshold.",
+ "enum": [
+ "above",
+ "below"
+ ],
+ "type": "string"
+ },
+ "evaluationWindow": {
+ "description": "EvaluationWindow is how long after resize to check. Defaults to 5m.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name identifies this guardrail for logging and status reporting.",
+ "type": "string"
+ },
+ "query": {
+ "description": "Query is a PromQL query that returns a scalar value.\nTemplate variables: {{ .Namespace }}, {{ .WorkloadName }}, {{ .PodName }}",
+ "type": "string"
+ },
+ "threshold": {
+ "description": "Threshold is the value that triggers a revert.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "query",
+ "threshold"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "templatePersistence": {
+ "description": "TemplatePersistence optionally writes recommended resources into the\nworkload pod template (Deployment/StatefulSet) so new pods start\ncorrectly sized. Default off. Do not enable under unmanaged GitOps\nsync without adopting recommendations in Git; prefer export or\ninitialSizing in that case.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled turns on template persistence. When false or unset, templates\nare never mutated.",
+ "type": "boolean"
+ },
+ "when": {
+ "description": "When selects the trigger. Defaults to AfterSuccessfulResize when\nEnabled is true and When is empty.",
+ "enum": [
+ "AfterSuccessfulResize",
+ "OnRecommendation"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Mode determines the update behavior, graduated from safe to automated:\n Recommend: collects metrics and writes recommendations to status, no pod changes.\n OneShot: resizes one pod per reconcile cycle.\n Canary: resizes a percentage of pods first, then the rest after observation.\n Auto: resizes all eligible pods each cycle.\n Observe: collects metrics and tracks data points but does not surface recommendations or savings.\nStart with Recommend in production and promote after reviewing status.\nDefaults to Recommend if not set (applied by the controller, not the webhook,\nso that AttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "Observe",
+ "Recommend",
+ "OneShot",
+ "Canary",
+ "Auto"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/attune.io/attunenamespacedefaults_v1alpha1.json b/crdSchemas/attune.io/attunenamespacedefaults_v1alpha1.json
new file mode 100644
index 0000000..d0cb517
--- /dev/null
+++ b/crdSchemas/attune.io/attunenamespacedefaults_v1alpha1.json
@@ -0,0 +1,763 @@
+{
+ "description": "AttuneNamespaceDefaults is the Schema for namespace-scoped defaults.\nValues here override cluster-scoped AttuneDefaults but are overridden\nby per-policy values. Precedence: policy > namespace defaults > cluster defaults.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "AttuneDefaultsSpec defines cluster-scoped default values for AttunePolicy resources.",
+ "properties": {
+ "costPricing": {
+ "description": "CostPricing configures the per-unit pricing used to compute\nEstimatedMonthlySavings. If omitted, defaults to standard\non-demand Linux pricing ($0.031/vCPU-hour, $0.004/GiB-hour).",
+ "properties": {
+ "cpuPerCoreHour": {
+ "description": "CPUPerCoreHour is the cost per vCPU-hour (e.g. \"0.031\").\nDefaults to 0.031 if not specified.",
+ "type": "string"
+ },
+ "memoryPerGiBHour": {
+ "description": "MemoryPerGiBHour is the cost per GiB-hour (e.g. \"0.004\").\nDefaults to 0.004 if not specified.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpu": {
+ "description": "CPU configures default CPU resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "excludeKnownSidecars": {
+ "description": "ExcludeKnownSidecars, when true (the default when unset on both\ndefaults and policy), automatically skips well-known mesh and\nsidecar container names. Set to false cluster-wide to restore\nexclude-only-via-excludedContainers behavior for policies that\ndo not set the field themselves.",
+ "type": "boolean"
+ },
+ "memory": {
+ "description": "Memory configures default memory resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metricsSource": {
+ "description": "MetricsSource configures default metrics source settings.",
+ "properties": {
+ "cloudwatch": {
+ "description": "CloudWatch configures an Amazon CloudWatch Container Insights metrics source.",
+ "properties": {
+ "clusterName": {
+ "description": "ClusterName is the EKS cluster name for Container Insights metrics.\nRequired for metric filtering.",
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the AWS region (e.g. \"us-east-1\"). Required.",
+ "type": "string"
+ },
+ "roleArn": {
+ "description": "RoleARN is an optional IAM role ARN to assume for cross-account access.\nIf not set, uses the pod's service account IAM role (IRSA/Pod Identity).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "clusterName",
+ "region"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpuRecordingMetric": {
+ "description": "CPURecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of rate(container_cpu_usage_seconds_total). Labels must include\nnamespace, pod, and container. When set, the operator does not wrap the\nmetric in rate(). Pair with MemoryRecordingMetric for a recording-rules-only path.",
+ "type": "string"
+ },
+ "datadog": {
+ "description": "Datadog configures a Datadog metrics source.",
+ "properties": {
+ "apiKeySecretRef": {
+ "description": "APIKeySecretRef references a Secret containing the Datadog API key.\nThe Secret must contain an \"api-key\" key and optionally an \"app-key\" key.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "site": {
+ "default": "datadoghq.com",
+ "description": "Site is the Datadog site (e.g. \"datadoghq.com\", \"datadoghq.eu\", \"us5.datadoghq.com\").\nDefaults to \"datadoghq.com\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "apiKeySecretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "historyWindow": {
+ "description": "HistoryWindow is the time window for historical metrics data.\nDefaults to 7d (168h) if not specified.",
+ "type": "string"
+ },
+ "memoryRecordingMetric": {
+ "description": "MemoryRecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of container_memory_working_set_bytes. Same label requirements\nas CPURecordingMetric.",
+ "type": "string"
+ },
+ "minimumDataPoints": {
+ "description": "MinimumDataPoints is the minimum number of data points required\nbefore generating recommendations. Minimum 1, default 48 samples.\nWith the default queryStep of 5m, 48 samples is about 4 hours of data.\nDefaults to 48 if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "podAggregation": {
+ "description": "PodAggregation controls how multi-pod series are reduced in Prometheus\nrange queries for this policy.\n Max (default): max by (container) \u2014 size for the busiest pod; O(containers) series.\n Avg: avg by (container) across pods.\n None: no aggregation (one series per pod; expensive for high replica counts).\nDatadog and CloudWatch already group by container; this field applies to Prometheus.",
+ "enum": [
+ "Max",
+ "Avg",
+ "None"
+ ],
+ "type": "string"
+ },
+ "prometheus": {
+ "description": "Prometheus configures a Prometheus metrics source.",
+ "properties": {
+ "address": {
+ "description": "Address is the URL of the Prometheus-compatible query endpoint.",
+ "type": "string"
+ },
+ "bearerTokenSecret": {
+ "description": "BearerTokenSecret references a Kubernetes Secret containing a bearer\ntoken for authenticating with managed Prometheus services.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Headers are custom HTTP headers added to every query request.\nUse for non-secret tenant or routing headers (e.g. \"X-Scope-OrgID\"\nfor Mimir). Do not put credentials here; use BearerTokenSecret for\nauthentication tokens.",
+ "type": "object"
+ },
+ "queryParameters": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "QueryParameters are appended to every query request URL.\nUse for backend-specific settings such as Thanos deduplication\n(e.g. {\"dedup\": \"true\", \"partial_response\": \"true\"}). Reserved\nquery keys controlled by the operator (`query`, `start`, `end`, `step`,\n`time`, `timeout`) are rejected.",
+ "type": "object"
+ },
+ "tls": {
+ "description": "TLS configures TLS settings for the connection.",
+ "properties": {
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify disables TLS certificate verification.\nUse only for self-signed certificates in development.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "address"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryStep": {
+ "description": "QueryStep is the step interval for Prometheus range queries and ETA\ncalculations. Should match your Prometheus scrape interval for\naccurate time estimates. Minimum 10s, maximum 1h. Default 5m.",
+ "type": "string"
+ },
+ "rateWindow": {
+ "description": "RateWindow is the window used in the PromQL rate() function for CPU\nqueries. Defaults to queryStep if not set. Must be >= 30s and <= historyWindow.\nAdvanced users may set this independently to control CPU rate smoothing\n(e.g. a short rateWindow for responsive tracking with a longer queryStep).",
+ "type": "string"
+ },
+ "vpa": {
+ "description": "VPA configures consumption of existing VerticalPodAutoscaler recommendations.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the VerticalPodAutoscaler object.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the VPA. Defaults to the policy's namespace.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "updateStrategy": {
+ "description": "UpdateStrategy configures default update strategy settings.",
+ "properties": {
+ "autoRevert": {
+ "description": "AutoRevert automatically reverts changes if degradation is detected.\nDefaults to true if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "type": "boolean"
+ },
+ "canary": {
+ "description": "Canary configures canary rollout behavior when Type is Canary.",
+ "properties": {
+ "autoPromote": {
+ "description": "AutoPromote controls whether the operator automatically promotes the\nresize to all pods after the observation period passes without safety\nviolations. When false (default), the user must manually switch the\nmode to Auto to resize the remaining pods.",
+ "type": "boolean"
+ },
+ "observationPeriod": {
+ "description": "ObservationPeriod is how long to observe canary pods before proceeding.",
+ "type": "string"
+ },
+ "percentage": {
+ "description": "Percentage is the percentage of pods to resize first.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "observationPeriod",
+ "percentage"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between successive resize operations.\nDefaults to 1h if not specified.",
+ "type": "string"
+ },
+ "export": {
+ "description": "Export configures how recommendations are exported for external\nconsumption (e.g. GitOps workflows with ArgoCD or Flux).",
+ "properties": {
+ "configMap": {
+ "description": "ConfigMap enables exporting recommendations to ConfigMaps.",
+ "type": "boolean"
+ },
+ "pullRequest": {
+ "description": "PullRequest enables opt-in GitOps PR automation (default off).\nRequires a token Secret and repository identity. Never logs the token.",
+ "properties": {
+ "apiUrl": {
+ "description": "APIURL overrides the API base URL (Enterprise GitHub or self-hosted GitLab).\nDefaults: https://api.github.com or https://gitlab.com/api/v4.",
+ "type": "string"
+ },
+ "baseBranch": {
+ "description": "BaseBranch is the PR target branch. Defaults to \"main\".",
+ "type": "string"
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between PR create/update attempts for this\npolicy. Defaults to 24h.",
+ "type": "string"
+ },
+ "dryRun": {
+ "description": "DryRun logs the intended PR and updates status without calling the\nremote API. Useful for CI and first enablement.",
+ "type": "boolean"
+ },
+ "enabled": {
+ "description": "Enabled turns on PR automation. Default false.",
+ "type": "boolean"
+ },
+ "labels": {
+ "description": "Labels are applied to the pull request when supported by the provider.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum absolute percent change (per container\nresource vs template) required to open or update a PR. Defaults to 10.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "provider": {
+ "description": "Provider is \"github\" or \"gitlab\". Default \"github\".",
+ "enum": [
+ "github",
+ "gitlab"
+ ],
+ "type": "string"
+ },
+ "repository": {
+ "description": "Repository is \"owner/name\" (GitHub) or \"group/project\" (GitLab path).\nRequired when Enabled is true.",
+ "type": "string"
+ },
+ "tokenSecretRef": {
+ "description": "TokenSecretRef references a Secret key holding a PAT / project token.\nGitHub: repo contents + pull requests. GitLab: api scope on the project.\nRequired when Enabled is true.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "includeExplanationsInStatus": {
+ "description": "IncludeExplanationsInStatus controls whether recommendation explanation\nchains are written to status. Set to false on large policies to shrink\nCR size. Default: true.",
+ "type": "boolean"
+ },
+ "initialSizing": {
+ "description": "InitialSizing enables a mutating admission webhook that sets resource\nrequests/limits on new pods at creation time, based on existing\nrecommendations. This eliminates the \"deploy with bad defaults, wait\nfor first reconcile\" gap. Requires the namespace label\nattune.io/initial-sizing=enabled. Defaults to false.",
+ "type": "boolean"
+ },
+ "maxConcurrentResizes": {
+ "default": 1,
+ "description": "MaxConcurrentResizes is the maximum number of pods to resize\nconcurrently within a single reconcile cycle. Default: 1 (serial).",
+ "format": "int32",
+ "maximum": 50,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxStatusRecommendations": {
+ "description": "MaxStatusRecommendations caps how many workload recommendations are\nwritten to status.recommendations. Resizes still use the full in-memory\nset. When the cap is hit, entries with the largest absolute CPU+memory\nrequest change are kept. Default: 100 (operator may override via flag).",
+ "format": "int32",
+ "maximum": 500,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxTotalCpuIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalCPUIncrease is the maximum aggregate CPU increase allowed\nacross all pods in a single reconcile cycle (e.g. \"2000m\", \"4\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxTotalMemoryIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalMemoryIncrease is the maximum aggregate memory increase\nallowed across all pods in a single reconcile cycle (e.g. \"4Gi\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resizeMethod": {
+ "description": "ResizeMethod controls what happens when an in-place resize fails.\n InPlaceOnly (default): skip the pod and retry next cycle.\n InPlaceOrRecreate: fall back to pod eviction if in-place resize\n fails or is marked Infeasible by kubelet. The owning controller\n recreates the pod with updated resources. Evictions respect\n PodDisruptionBudgets and never evict the last replica.\nDefaults to InPlaceOnly if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "InPlaceOnly",
+ "InPlaceOrRecreate"
+ ],
+ "type": "string"
+ },
+ "safetyObservationPeriod": {
+ "description": "SafetyObservationPeriod is how long to observe a pod after resize before\nconcluding the resize is safe. Applies to all modes (Auto, OneShot, Canary).\nTakes precedence over canary.observationPeriod when set. Must be >= 1m.\nDefaults to 5m if neither this nor canary.observationPeriod is set.",
+ "type": "string"
+ },
+ "schedule": {
+ "description": "Schedule restricts when resize operations can occur. Recommendations\nare always computed; only resize execution is gated. If omitted,\nresizes can occur at any time (current behavior).",
+ "properties": {
+ "daysOfWeek": {
+ "description": "DaysOfWeek restricts resizes to specific days. Values: Monday through Sunday.\nIf omitted, all days are allowed.",
+ "items": {
+ "enum": [
+ "Monday",
+ "Tuesday",
+ "Wednesday",
+ "Thursday",
+ "Friday",
+ "Saturday",
+ "Sunday"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "timezone": {
+ "default": "UTC",
+ "description": "Timezone for interpreting window start/end times. Must be a valid\nIANA timezone name (e.g. \"America/New_York\"). Default: \"UTC\".",
+ "type": "string"
+ },
+ "windows": {
+ "description": "Windows defines time-of-day ranges when resizes are allowed.\nIf multiple windows are specified, resizes are allowed during any of them.",
+ "items": {
+ "description": "TimeWindow defines a daily time range.",
+ "properties": {
+ "end": {
+ "description": "End time in HH:MM format (24-hour). If end < start, the window\nwraps past midnight (e.g. start=22:00, end=06:00).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ },
+ "start": {
+ "description": "Start time in HH:MM format (24-hour).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sloGuardrails": {
+ "description": "SLOGuardrails defines application-level SLO metrics to check after\na resize. If any metric breaches its threshold during the safety\nobservation period, the resize is automatically reverted.\nRequires a Prometheus-compatible metrics source.",
+ "items": {
+ "description": "SLOGuardrail defines an application-level metric that is checked after\na resize to detect degradation. If the metric breaches the threshold,\nthe safety monitor triggers an automatic revert.",
+ "properties": {
+ "comparison": {
+ "default": "above",
+ "description": "Comparison is \"above\" or \"below\". \"above\" reverts when value > threshold.",
+ "enum": [
+ "above",
+ "below"
+ ],
+ "type": "string"
+ },
+ "evaluationWindow": {
+ "description": "EvaluationWindow is how long after resize to check. Defaults to 5m.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name identifies this guardrail for logging and status reporting.",
+ "type": "string"
+ },
+ "query": {
+ "description": "Query is a PromQL query that returns a scalar value.\nTemplate variables: {{ .Namespace }}, {{ .WorkloadName }}, {{ .PodName }}",
+ "type": "string"
+ },
+ "threshold": {
+ "description": "Threshold is the value that triggers a revert.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "query",
+ "threshold"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "templatePersistence": {
+ "description": "TemplatePersistence optionally writes recommended resources into the\nworkload pod template (Deployment/StatefulSet) so new pods start\ncorrectly sized. Default off. Do not enable under unmanaged GitOps\nsync without adopting recommendations in Git; prefer export or\ninitialSizing in that case.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled turns on template persistence. When false or unset, templates\nare never mutated.",
+ "type": "boolean"
+ },
+ "when": {
+ "description": "When selects the trigger. Defaults to AfterSuccessfulResize when\nEnabled is true and When is empty.",
+ "enum": [
+ "AfterSuccessfulResize",
+ "OnRecommendation"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Mode determines the update behavior, graduated from safe to automated:\n Recommend: collects metrics and writes recommendations to status, no pod changes.\n OneShot: resizes one pod per reconcile cycle.\n Canary: resizes a percentage of pods first, then the rest after observation.\n Auto: resizes all eligible pods each cycle.\n Observe: collects metrics and tracks data points but does not surface recommendations or savings.\nStart with Recommend in production and promote after reviewing status.\nDefaults to Recommend if not set (applied by the controller, not the webhook,\nso that AttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "Observe",
+ "Recommend",
+ "OneShot",
+ "Canary",
+ "Auto"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/attune.io/attunepolicy_v1alpha1.json b/crdSchemas/attune.io/attunepolicy_v1alpha1.json
new file mode 100644
index 0000000..64820d0
--- /dev/null
+++ b/crdSchemas/attune.io/attunepolicy_v1alpha1.json
@@ -0,0 +1,1759 @@
+{
+ "description": "AttunePolicy is the Schema for the attunepolicies API.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "AttunePolicySpec defines the desired state of AttunePolicy.",
+ "properties": {
+ "cpu": {
+ "description": "CPU configures CPU resource recommendations.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "excludeKnownSidecars": {
+ "description": "ExcludeKnownSidecars, when true (the default), automatically skips\nwell-known mesh and sidecar container names (for example istio-proxy,\nlinkerd-proxy) in addition to ExcludedContainers. Set to false to\nrestore pre-feature behavior where only ExcludedContainers is used.",
+ "type": "boolean"
+ },
+ "excludedContainers": {
+ "description": "ExcludedContainers is a list of container names to skip when computing\nrecommendations and performing resizes. Use this for custom sidecars\nor agents. When ExcludeKnownSidecars is true (the default), this list\nis unioned with the built-in known-sidecar names (istio-proxy, etc.).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 100,
+ "type": "array"
+ },
+ "memory": {
+ "description": "Memory configures memory resource recommendations.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metricsSource": {
+ "description": "MetricsSource configures where and how to collect metrics.",
+ "properties": {
+ "cloudwatch": {
+ "description": "CloudWatch configures an Amazon CloudWatch Container Insights metrics source.",
+ "properties": {
+ "clusterName": {
+ "description": "ClusterName is the EKS cluster name for Container Insights metrics.\nRequired for metric filtering.",
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the AWS region (e.g. \"us-east-1\"). Required.",
+ "type": "string"
+ },
+ "roleArn": {
+ "description": "RoleARN is an optional IAM role ARN to assume for cross-account access.\nIf not set, uses the pod's service account IAM role (IRSA/Pod Identity).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "clusterName",
+ "region"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpuRecordingMetric": {
+ "description": "CPURecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of rate(container_cpu_usage_seconds_total). Labels must include\nnamespace, pod, and container. When set, the operator does not wrap the\nmetric in rate(). Pair with MemoryRecordingMetric for a recording-rules-only path.",
+ "type": "string"
+ },
+ "datadog": {
+ "description": "Datadog configures a Datadog metrics source.",
+ "properties": {
+ "apiKeySecretRef": {
+ "description": "APIKeySecretRef references a Secret containing the Datadog API key.\nThe Secret must contain an \"api-key\" key and optionally an \"app-key\" key.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "site": {
+ "default": "datadoghq.com",
+ "description": "Site is the Datadog site (e.g. \"datadoghq.com\", \"datadoghq.eu\", \"us5.datadoghq.com\").\nDefaults to \"datadoghq.com\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "apiKeySecretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "historyWindow": {
+ "description": "HistoryWindow is the time window for historical metrics data.\nDefaults to 7d (168h) if not specified.",
+ "type": "string"
+ },
+ "memoryRecordingMetric": {
+ "description": "MemoryRecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of container_memory_working_set_bytes. Same label requirements\nas CPURecordingMetric.",
+ "type": "string"
+ },
+ "minimumDataPoints": {
+ "description": "MinimumDataPoints is the minimum number of data points required\nbefore generating recommendations. Minimum 1, default 48 samples.\nWith the default queryStep of 5m, 48 samples is about 4 hours of data.\nDefaults to 48 if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "podAggregation": {
+ "description": "PodAggregation controls how multi-pod series are reduced in Prometheus\nrange queries for this policy.\n Max (default): max by (container) \u2014 size for the busiest pod; O(containers) series.\n Avg: avg by (container) across pods.\n None: no aggregation (one series per pod; expensive for high replica counts).\nDatadog and CloudWatch already group by container; this field applies to Prometheus.",
+ "enum": [
+ "Max",
+ "Avg",
+ "None"
+ ],
+ "type": "string"
+ },
+ "prometheus": {
+ "description": "Prometheus configures a Prometheus metrics source.",
+ "properties": {
+ "address": {
+ "description": "Address is the URL of the Prometheus-compatible query endpoint.",
+ "type": "string"
+ },
+ "bearerTokenSecret": {
+ "description": "BearerTokenSecret references a Kubernetes Secret containing a bearer\ntoken for authenticating with managed Prometheus services.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Headers are custom HTTP headers added to every query request.\nUse for non-secret tenant or routing headers (e.g. \"X-Scope-OrgID\"\nfor Mimir). Do not put credentials here; use BearerTokenSecret for\nauthentication tokens.",
+ "type": "object"
+ },
+ "queryParameters": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "QueryParameters are appended to every query request URL.\nUse for backend-specific settings such as Thanos deduplication\n(e.g. {\"dedup\": \"true\", \"partial_response\": \"true\"}). Reserved\nquery keys controlled by the operator (`query`, `start`, `end`, `step`,\n`time`, `timeout`) are rejected.",
+ "type": "object"
+ },
+ "tls": {
+ "description": "TLS configures TLS settings for the connection.",
+ "properties": {
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify disables TLS certificate verification.\nUse only for self-signed certificates in development.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "address"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryStep": {
+ "description": "QueryStep is the step interval for Prometheus range queries and ETA\ncalculations. Should match your Prometheus scrape interval for\naccurate time estimates. Minimum 10s, maximum 1h. Default 5m.",
+ "type": "string"
+ },
+ "rateWindow": {
+ "description": "RateWindow is the window used in the PromQL rate() function for CPU\nqueries. Defaults to queryStep if not set. Must be >= 30s and <= historyWindow.\nAdvanced users may set this independently to control CPU rate smoothing\n(e.g. a short rateWindow for responsive tracking with a longer queryStep).",
+ "type": "string"
+ },
+ "vpa": {
+ "description": "VPA configures consumption of existing VerticalPodAutoscaler recommendations.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the VerticalPodAutoscaler object.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the VPA. Defaults to the policy's namespace.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "paused": {
+ "description": "Paused stops the operator from reconciling this policy. Metrics\ncollection, recommendations, and resizes are all halted. Existing\nresizes are not reverted. Use this during maintenance windows or\nwhen debugging unexpected behavior. The operator sets Ready=False\nwith reason=Paused while this field is true.",
+ "type": "boolean"
+ },
+ "runtimeProfile": {
+ "description": "RuntimeProfile applies language/runtime-oriented defaults for memory\nresize safety. Unset or \"generic\" leaves policy fields unchanged.\nProfiles document recommended resizePolicy and decrease settings;\nthey do not auto-patch pod specs. Supported values: generic, java,\npython, golang, nodejs.",
+ "enum": [
+ "generic",
+ "java",
+ "python",
+ "golang",
+ "nodejs"
+ ],
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef identifies the workload(s) to be attuned.",
+ "properties": {
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Deployment",
+ "StatefulSet",
+ "DaemonSet",
+ "CronJob",
+ "Job",
+ "ReplicaSet"
+ ],
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of a specific target resource.",
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects target resources by labels.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "updateStrategy": {
+ "description": "UpdateStrategy configures how and when to apply resource changes.",
+ "properties": {
+ "autoRevert": {
+ "description": "AutoRevert automatically reverts changes if degradation is detected.\nDefaults to true if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "type": "boolean"
+ },
+ "canary": {
+ "description": "Canary configures canary rollout behavior when Type is Canary.",
+ "properties": {
+ "autoPromote": {
+ "description": "AutoPromote controls whether the operator automatically promotes the\nresize to all pods after the observation period passes without safety\nviolations. When false (default), the user must manually switch the\nmode to Auto to resize the remaining pods.",
+ "type": "boolean"
+ },
+ "observationPeriod": {
+ "description": "ObservationPeriod is how long to observe canary pods before proceeding.",
+ "type": "string"
+ },
+ "percentage": {
+ "description": "Percentage is the percentage of pods to resize first.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "observationPeriod",
+ "percentage"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between successive resize operations.\nDefaults to 1h if not specified.",
+ "type": "string"
+ },
+ "export": {
+ "description": "Export configures how recommendations are exported for external\nconsumption (e.g. GitOps workflows with ArgoCD or Flux).",
+ "properties": {
+ "configMap": {
+ "description": "ConfigMap enables exporting recommendations to ConfigMaps.",
+ "type": "boolean"
+ },
+ "pullRequest": {
+ "description": "PullRequest enables opt-in GitOps PR automation (default off).\nRequires a token Secret and repository identity. Never logs the token.",
+ "properties": {
+ "apiUrl": {
+ "description": "APIURL overrides the API base URL (Enterprise GitHub or self-hosted GitLab).\nDefaults: https://api.github.com or https://gitlab.com/api/v4.",
+ "type": "string"
+ },
+ "baseBranch": {
+ "description": "BaseBranch is the PR target branch. Defaults to \"main\".",
+ "type": "string"
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between PR create/update attempts for this\npolicy. Defaults to 24h.",
+ "type": "string"
+ },
+ "dryRun": {
+ "description": "DryRun logs the intended PR and updates status without calling the\nremote API. Useful for CI and first enablement.",
+ "type": "boolean"
+ },
+ "enabled": {
+ "description": "Enabled turns on PR automation. Default false.",
+ "type": "boolean"
+ },
+ "labels": {
+ "description": "Labels are applied to the pull request when supported by the provider.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum absolute percent change (per container\nresource vs template) required to open or update a PR. Defaults to 10.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "provider": {
+ "description": "Provider is \"github\" or \"gitlab\". Default \"github\".",
+ "enum": [
+ "github",
+ "gitlab"
+ ],
+ "type": "string"
+ },
+ "repository": {
+ "description": "Repository is \"owner/name\" (GitHub) or \"group/project\" (GitLab path).\nRequired when Enabled is true.",
+ "type": "string"
+ },
+ "tokenSecretRef": {
+ "description": "TokenSecretRef references a Secret key holding a PAT / project token.\nGitHub: repo contents + pull requests. GitLab: api scope on the project.\nRequired when Enabled is true.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "includeExplanationsInStatus": {
+ "description": "IncludeExplanationsInStatus controls whether recommendation explanation\nchains are written to status. Set to false on large policies to shrink\nCR size. Default: true.",
+ "type": "boolean"
+ },
+ "initialSizing": {
+ "description": "InitialSizing enables a mutating admission webhook that sets resource\nrequests/limits on new pods at creation time, based on existing\nrecommendations. This eliminates the \"deploy with bad defaults, wait\nfor first reconcile\" gap. Requires the namespace label\nattune.io/initial-sizing=enabled. Defaults to false.",
+ "type": "boolean"
+ },
+ "maxConcurrentResizes": {
+ "default": 1,
+ "description": "MaxConcurrentResizes is the maximum number of pods to resize\nconcurrently within a single reconcile cycle. Default: 1 (serial).",
+ "format": "int32",
+ "maximum": 50,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxStatusRecommendations": {
+ "description": "MaxStatusRecommendations caps how many workload recommendations are\nwritten to status.recommendations. Resizes still use the full in-memory\nset. When the cap is hit, entries with the largest absolute CPU+memory\nrequest change are kept. Default: 100 (operator may override via flag).",
+ "format": "int32",
+ "maximum": 500,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxTotalCpuIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalCPUIncrease is the maximum aggregate CPU increase allowed\nacross all pods in a single reconcile cycle (e.g. \"2000m\", \"4\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxTotalMemoryIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalMemoryIncrease is the maximum aggregate memory increase\nallowed across all pods in a single reconcile cycle (e.g. \"4Gi\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resizeMethod": {
+ "description": "ResizeMethod controls what happens when an in-place resize fails.\n InPlaceOnly (default): skip the pod and retry next cycle.\n InPlaceOrRecreate: fall back to pod eviction if in-place resize\n fails or is marked Infeasible by kubelet. The owning controller\n recreates the pod with updated resources. Evictions respect\n PodDisruptionBudgets and never evict the last replica.\nDefaults to InPlaceOnly if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "InPlaceOnly",
+ "InPlaceOrRecreate"
+ ],
+ "type": "string"
+ },
+ "safetyObservationPeriod": {
+ "description": "SafetyObservationPeriod is how long to observe a pod after resize before\nconcluding the resize is safe. Applies to all modes (Auto, OneShot, Canary).\nTakes precedence over canary.observationPeriod when set. Must be >= 1m.\nDefaults to 5m if neither this nor canary.observationPeriod is set.",
+ "type": "string"
+ },
+ "schedule": {
+ "description": "Schedule restricts when resize operations can occur. Recommendations\nare always computed; only resize execution is gated. If omitted,\nresizes can occur at any time (current behavior).",
+ "properties": {
+ "daysOfWeek": {
+ "description": "DaysOfWeek restricts resizes to specific days. Values: Monday through Sunday.\nIf omitted, all days are allowed.",
+ "items": {
+ "enum": [
+ "Monday",
+ "Tuesday",
+ "Wednesday",
+ "Thursday",
+ "Friday",
+ "Saturday",
+ "Sunday"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "timezone": {
+ "default": "UTC",
+ "description": "Timezone for interpreting window start/end times. Must be a valid\nIANA timezone name (e.g. \"America/New_York\"). Default: \"UTC\".",
+ "type": "string"
+ },
+ "windows": {
+ "description": "Windows defines time-of-day ranges when resizes are allowed.\nIf multiple windows are specified, resizes are allowed during any of them.",
+ "items": {
+ "description": "TimeWindow defines a daily time range.",
+ "properties": {
+ "end": {
+ "description": "End time in HH:MM format (24-hour). If end < start, the window\nwraps past midnight (e.g. start=22:00, end=06:00).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ },
+ "start": {
+ "description": "Start time in HH:MM format (24-hour).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sloGuardrails": {
+ "description": "SLOGuardrails defines application-level SLO metrics to check after\na resize. If any metric breaches its threshold during the safety\nobservation period, the resize is automatically reverted.\nRequires a Prometheus-compatible metrics source.",
+ "items": {
+ "description": "SLOGuardrail defines an application-level metric that is checked after\na resize to detect degradation. If the metric breaches the threshold,\nthe safety monitor triggers an automatic revert.",
+ "properties": {
+ "comparison": {
+ "default": "above",
+ "description": "Comparison is \"above\" or \"below\". \"above\" reverts when value > threshold.",
+ "enum": [
+ "above",
+ "below"
+ ],
+ "type": "string"
+ },
+ "evaluationWindow": {
+ "description": "EvaluationWindow is how long after resize to check. Defaults to 5m.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name identifies this guardrail for logging and status reporting.",
+ "type": "string"
+ },
+ "query": {
+ "description": "Query is a PromQL query that returns a scalar value.\nTemplate variables: {{ .Namespace }}, {{ .WorkloadName }}, {{ .PodName }}",
+ "type": "string"
+ },
+ "threshold": {
+ "description": "Threshold is the value that triggers a revert.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "query",
+ "threshold"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "templatePersistence": {
+ "description": "TemplatePersistence optionally writes recommended resources into the\nworkload pod template (Deployment/StatefulSet) so new pods start\ncorrectly sized. Default off. Do not enable under unmanaged GitOps\nsync without adopting recommendations in Git; prefer export or\ninitialSizing in that case.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled turns on template persistence. When false or unset, templates\nare never mutated.",
+ "type": "boolean"
+ },
+ "when": {
+ "description": "When selects the trigger. Defaults to AfterSuccessfulResize when\nEnabled is true and When is empty.",
+ "enum": [
+ "AfterSuccessfulResize",
+ "OnRecommendation"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Mode determines the update behavior, graduated from safe to automated:\n Recommend: collects metrics and writes recommendations to status, no pod changes.\n OneShot: resizes one pod per reconcile cycle.\n Canary: resizes a percentage of pods first, then the rest after observation.\n Auto: resizes all eligible pods each cycle.\n Observe: collects metrics and tracks data points but does not surface recommendations or savings.\nStart with Recommend in production and promote after reviewing status.\nDefaults to Recommend if not set (applied by the controller, not the webhook,\nso that AttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "Observe",
+ "Recommend",
+ "OneShot",
+ "Canary",
+ "Auto"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "default": 100,
+ "description": "Weight determines the priority of this policy when multiple policies\nmatch the same workload. Higher values take precedence.",
+ "format": "int32",
+ "maximum": 1000,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "cpu",
+ "memory",
+ "metricsSource",
+ "targetRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "AttunePolicyStatus defines the observed state of AttunePolicy.",
+ "properties": {
+ "canary": {
+ "description": "Canary tracks the canary rollout phase when autoPromote is enabled.",
+ "properties": {
+ "observedGeneration": {
+ "description": "ObservedGeneration is the policy generation when this canary cycle\nstarted. If the policy spec changes (generation increments), the\ncanary observation resets so the new configuration is re-validated.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "phase": {
+ "description": "Phase indicates the current canary state.\nCanaryInProgress: canary pods resized, observing for safety violations.\nFullRollout: observation passed with no violations, all pods are being resized.",
+ "type": "string"
+ },
+ "pods": {
+ "description": "Pods lists the names of pods selected for the canary subset.\nPopulated when Mode is Canary and pods have been resized.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 100,
+ "type": "array"
+ },
+ "startTime": {
+ "description": "StartTime is when the canary subset was first resized.",
+ "format": "date-time",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions represent the latest available observations of the policy's state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "cooldown": {
+ "description": "Cooldown exposes the effective cooldown including exponential backoff.",
+ "properties": {
+ "backoffMultiplier": {
+ "description": "BackoffMultiplier is the current backoff multiplier (1, 2, 4, 8, or 16).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveReverts": {
+ "description": "ConsecutiveReverts is the number of consecutive reverts driving the backoff.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "effectiveCooldown": {
+ "description": "EffectiveCooldown is the current cooldown duration including backoff.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "lastReconcileTime": {
+ "description": "LastReconcileTime is the timestamp of the most recent reconciliation.\nServes as a heartbeat to confirm the operator is actively evaluating\nthis policy, even when no state changes occur.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "recommendations": {
+ "description": "Recommendations contains per-workload resource recommendations.",
+ "items": {
+ "description": "WorkloadRecommendation contains recommendations for a single workload.",
+ "properties": {
+ "containers": {
+ "description": "Containers contains per-container recommendations.",
+ "items": {
+ "description": "ContainerRecommendation contains recommendations for a single container.",
+ "properties": {
+ "confidence": {
+ "description": "Confidence is the confidence score of the recommendation (0-1).",
+ "type": "number"
+ },
+ "current": {
+ "description": "Current contains the current resource values.",
+ "properties": {
+ "cpuLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPULimit is the CPU limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "cpuRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPURequest is the CPU request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryLimit is the memory limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryRequest is the memory request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "cpuLimit",
+ "cpuRequest",
+ "memoryLimit",
+ "memoryRequest"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dataPoints": {
+ "description": "DataPoints is the number of data points used to generate the recommendation.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "explanation": {
+ "description": "Explanation contains the reasoning chain behind the recommendation.",
+ "properties": {
+ "cpu": {
+ "description": "CPU contains the CPU recommendation reasoning.",
+ "properties": {
+ "afterBounds": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBounds is the value after bounds clamping.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterBurst": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBurst is the value after applying the burst factor.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterChangeFilter": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterChangeFilter is the value after change filtering.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterConfidence": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterConfidence is the value after applying the confidence adjustment.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterOverhead": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterOverhead is the value after applying the overhead.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "bounds": {
+ "description": "Bounds are the configured minimum and maximum limits.",
+ "properties": {
+ "max": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Max is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "min": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Min is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "max",
+ "min"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "boundsApplied": {
+ "description": "BoundsApplied indicates whether the value was clamped to min, max, or neither.",
+ "type": "string"
+ },
+ "burstFactor": {
+ "description": "BurstFactor is the multiplier applied when burst is detected (max > 3x p95).\n1.0 when no burst. Uses logarithmic scaling to avoid excessive inflation.",
+ "type": "number"
+ },
+ "changeFilterApplied": {
+ "description": "ChangeFilterApplied indicates whether the result was filtered or capped.",
+ "type": "string"
+ },
+ "confidence": {
+ "description": "Confidence is the profile confidence score used for adjustment.",
+ "type": "number"
+ },
+ "confidenceFactor": {
+ "description": "ConfidenceFactor is the multiplier derived from the confidence score.",
+ "type": "number"
+ },
+ "final": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Final is the final resource recommendation after any post-processing.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "finalAdjustment": {
+ "description": "FinalAdjustment describes any controller-level adjustment after the estimator chain.",
+ "type": "string"
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change threshold.",
+ "type": "number"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum change threshold required to alter the current value.",
+ "type": "number"
+ },
+ "overhead": {
+ "description": "Overhead is the configured overhead percentage applied to the raw percentile.",
+ "type": "number"
+ },
+ "rawPercentile": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "RawPercentile is the selected percentile before any adjustments.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "afterBounds",
+ "afterChangeFilter",
+ "afterConfidence",
+ "afterOverhead",
+ "bounds",
+ "confidence",
+ "confidenceFactor",
+ "final",
+ "maxChangePercent",
+ "minChangePercent",
+ "overhead",
+ "rawPercentile"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "memory": {
+ "description": "Memory contains the memory recommendation reasoning.",
+ "properties": {
+ "afterBounds": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBounds is the value after bounds clamping.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterBurst": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBurst is the value after applying the burst factor.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterChangeFilter": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterChangeFilter is the value after change filtering.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterConfidence": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterConfidence is the value after applying the confidence adjustment.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterOverhead": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterOverhead is the value after applying the overhead.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "bounds": {
+ "description": "Bounds are the configured minimum and maximum limits.",
+ "properties": {
+ "max": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Max is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "min": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Min is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "max",
+ "min"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "boundsApplied": {
+ "description": "BoundsApplied indicates whether the value was clamped to min, max, or neither.",
+ "type": "string"
+ },
+ "burstFactor": {
+ "description": "BurstFactor is the multiplier applied when burst is detected (max > 3x p95).\n1.0 when no burst. Uses logarithmic scaling to avoid excessive inflation.",
+ "type": "number"
+ },
+ "changeFilterApplied": {
+ "description": "ChangeFilterApplied indicates whether the result was filtered or capped.",
+ "type": "string"
+ },
+ "confidence": {
+ "description": "Confidence is the profile confidence score used for adjustment.",
+ "type": "number"
+ },
+ "confidenceFactor": {
+ "description": "ConfidenceFactor is the multiplier derived from the confidence score.",
+ "type": "number"
+ },
+ "final": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Final is the final resource recommendation after any post-processing.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "finalAdjustment": {
+ "description": "FinalAdjustment describes any controller-level adjustment after the estimator chain.",
+ "type": "string"
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change threshold.",
+ "type": "number"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum change threshold required to alter the current value.",
+ "type": "number"
+ },
+ "overhead": {
+ "description": "Overhead is the configured overhead percentage applied to the raw percentile.",
+ "type": "number"
+ },
+ "rawPercentile": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "RawPercentile is the selected percentile before any adjustments.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "afterBounds",
+ "afterChangeFilter",
+ "afterConfidence",
+ "afterOverhead",
+ "bounds",
+ "confidence",
+ "confidenceFactor",
+ "final",
+ "maxChangePercent",
+ "minChangePercent",
+ "overhead",
+ "rawPercentile"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "lastUpdated": {
+ "description": "LastUpdated is the timestamp of the last recommendation update.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the container name.",
+ "type": "string"
+ },
+ "recommended": {
+ "description": "Recommended contains the recommended resource values.",
+ "properties": {
+ "cpuLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPULimit is the CPU limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "cpuRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPURequest is the CPU request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryLimit is the memory limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryRequest is the memory request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "cpuLimit",
+ "cpuRequest",
+ "memoryLimit",
+ "memoryRequest"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "confidence",
+ "current",
+ "dataPoints",
+ "lastUpdated",
+ "name",
+ "recommended"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "kind": {
+ "description": "Kind is the kind of the workload (e.g. Deployment, StatefulSet).",
+ "type": "string"
+ },
+ "lastDataTime": {
+ "description": "LastDataTime is the timestamp when Prometheus last returned non-empty\ndata for this workload. Used for staleness detection.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "stale": {
+ "description": "Stale indicates the recommendation is based on cached data because\nPrometheus did not return fresh data during the most recent query.\nResizes are not executed with stale recommendations.",
+ "type": "boolean"
+ },
+ "workload": {
+ "description": "Workload is the name of the workload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "containers",
+ "kind",
+ "workload"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 500,
+ "type": "array"
+ },
+ "resizeHistory": {
+ "description": "ResizeHistory records past resize operations.",
+ "items": {
+ "description": "ResizeHistoryEntry records a single resize operation.",
+ "properties": {
+ "container": {
+ "description": "Container is the name of the resized container.",
+ "type": "string"
+ },
+ "from": {
+ "description": "From is the previous resource value.",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method is the resize method used.",
+ "enum": [
+ "InPlace",
+ "Eviction",
+ "TemplatePersistence"
+ ],
+ "type": "string"
+ },
+ "reason": {
+ "description": "Reason explains why the resize was reverted or failed.\nOnly populated when Result is Reverted or Failed.\nValues include: oomkill, restart, notready, throttle,\nannotation-conflict, immediate-safety-check, slo:,\ninfeasible (kubelet Infeasible / InPlaceOnly skip).",
+ "type": "string"
+ },
+ "resource": {
+ "description": "Resource is the resource type that was resized, or \"template\" when the\nhistory entry records a workload template persistence patch.",
+ "enum": [
+ "cpu",
+ "memory",
+ "cpu+memory",
+ "template"
+ ],
+ "type": "string"
+ },
+ "result": {
+ "description": "Result is the outcome of the resize operation.",
+ "enum": [
+ "Success",
+ "Failed",
+ "Reverted",
+ "Evicted",
+ "TemplatePatched"
+ ],
+ "type": "string"
+ },
+ "timestamp": {
+ "description": "Timestamp is when the resize operation occurred.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "to": {
+ "description": "To is the new resource value.",
+ "type": "string"
+ },
+ "workload": {
+ "description": "Workload is the name of the resized workload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "container",
+ "from",
+ "method",
+ "resource",
+ "result",
+ "timestamp",
+ "to",
+ "workload"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "type": "array"
+ },
+ "savings": {
+ "description": "Savings summarizes estimated resource savings.",
+ "properties": {
+ "cpuRequestIncrease": {
+ "description": "CPURequestIncrease is the total CPU request increase for under-provisioned\nworkloads (e.g. \"500m\"). Empty when all recommendations are decreases.",
+ "type": "string"
+ },
+ "cpuRequestReduction": {
+ "description": "CPURequestReduction is the total CPU request reduction (e.g. \"200m\").",
+ "type": "string"
+ },
+ "cpuRequestTotal": {
+ "description": "CPURequestTotal is the total current CPU requests across all workloads (e.g. \"2000m\").",
+ "type": "string"
+ },
+ "estimatedMonthlyCostIncrease": {
+ "description": "EstimatedMonthlyCostIncrease is the estimated monthly cost increase for\nunder-provisioned workloads based on configured or default pricing (e.g. \"$5.00\").",
+ "type": "string"
+ },
+ "estimatedMonthlySavings": {
+ "description": "EstimatedMonthlySavings is the estimated monthly cost savings based on\nconfigured or default pricing (e.g. \"$12.50\").",
+ "type": "string"
+ },
+ "memoryRequestIncrease": {
+ "description": "MemoryRequestIncrease is the total memory request increase for under-provisioned\nworkloads (e.g. \"512Mi\"). Empty when all recommendations are decreases.",
+ "type": "string"
+ },
+ "memoryRequestReduction": {
+ "description": "MemoryRequestReduction is the total memory request reduction (e.g. \"256Mi\").",
+ "type": "string"
+ },
+ "memoryRequestTotal": {
+ "description": "MemoryRequestTotal is the total current memory requests across all workloads (e.g. \"2Gi\").",
+ "type": "string"
+ },
+ "reclaimedCpuRequest": {
+ "description": "ReclaimedCPURequest is estimated freeable CPU request capacity if recommended\ndecreases were applied (same quantity as cpuRequestReduction). Preferred field\nname for bin-packing and cluster-autoscaler capacity planning.",
+ "type": "string"
+ },
+ "reclaimedMemoryRequest": {
+ "description": "ReclaimedMemoryRequest is estimated freeable memory request capacity if\nrecommended decreases were applied (same quantity as memoryRequestReduction).",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "workloadErrors": {
+ "description": "WorkloadErrors records per-workload errors from the most recent\nreconcile cycle. Capped at 10 entries to limit status size.",
+ "items": {
+ "description": "WorkloadError records an error encountered while processing a specific workload.",
+ "properties": {
+ "error": {
+ "description": "Error is a human-readable description of the error.",
+ "type": "string"
+ },
+ "workload": {
+ "description": "Workload is the name of the affected workload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "error",
+ "workload"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "workloads": {
+ "description": "Workloads summarizes workload discovery and resize counts.",
+ "properties": {
+ "dataPointsCollected": {
+ "description": "DataPointsCollected is the maximum number of data points collected across\nall containers in the discovered workloads.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "dataPointsRequired": {
+ "description": "DataPointsRequired is the minimum number of data points needed before\ngenerating recommendations (from metricsSource.minimumDataPoints).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "deferred": {
+ "description": "Deferred is the number of pods whose in-place resize is Deferred by the\nkubelet (node cannot accept the change yet). Retried automatically when\nthe condition clears on a later reconcile.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "discovered": {
+ "description": "Discovered is the number of workloads matching the target selector.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "infeasible": {
+ "description": "Infeasible is the number of pods whose in-place resize is Infeasible on\nthe current node. With resizeMethod InPlaceOnly these pods are skipped;\nwith InPlaceOrRecreate the operator may fall back to eviction.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "pending": {
+ "description": "Pending is the number of workloads awaiting resize.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "resized": {
+ "description": "Resized is the number of workloads that have been resized.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "withRecommendations": {
+ "description": "WithRecommendations is the number of workloads with active recommendations.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "discovered",
+ "pending",
+ "resized",
+ "withRecommendations"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/objectstore_v1.json b/crdSchemas/barmancloud.cnpg.io/objectstore_v1.json
similarity index 100%
rename from crdSchemas/objectstore_v1.json
rename to crdSchemas/barmancloud.cnpg.io/objectstore_v1.json
diff --git a/crdSchemas/sealedsecret_v1alpha1.json b/crdSchemas/bitnami.com/sealedsecret_v1alpha1.json
similarity index 100%
rename from crdSchemas/sealedsecret_v1alpha1.json
rename to crdSchemas/bitnami.com/sealedsecret_v1alpha1.json
diff --git a/crdSchemas/certificate_v1.json b/crdSchemas/cert-manager.io/certificate_v1.json
similarity index 100%
rename from crdSchemas/certificate_v1.json
rename to crdSchemas/cert-manager.io/certificate_v1.json
diff --git a/crdSchemas/certificaterequest_v1.json b/crdSchemas/cert-manager.io/certificaterequest_v1.json
similarity index 100%
rename from crdSchemas/certificaterequest_v1.json
rename to crdSchemas/cert-manager.io/certificaterequest_v1.json
diff --git a/crdSchemas/clusterissuer_v1.json b/crdSchemas/cert-manager.io/clusterissuer_v1.json
similarity index 100%
rename from crdSchemas/clusterissuer_v1.json
rename to crdSchemas/cert-manager.io/clusterissuer_v1.json
diff --git a/crdSchemas/issuer_v1.json b/crdSchemas/cert-manager.io/issuer_v1.json
similarity index 100%
rename from crdSchemas/issuer_v1.json
rename to crdSchemas/cert-manager.io/issuer_v1.json
diff --git a/crdSchemas/cfgate.io/cloudflareaccessapplication_v1alpha1.json b/crdSchemas/cfgate.io/cloudflareaccessapplication_v1alpha1.json
new file mode 100644
index 0000000..20461ba
--- /dev/null
+++ b/crdSchemas/cfgate.io/cloudflareaccessapplication_v1alpha1.json
@@ -0,0 +1,733 @@
+{
+ "description": "CloudflareAccessApplication binds Gateway API targets to reusable Cloudflare Access policies.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareAccessApplicationSpec defines Gateway API target bindings to reusable Access policies.",
+ "properties": {
+ "application": {
+ "description": "Application defines Access Application settings shared by generated apps.\nThe path field overrides any path derived from HTTPRoute rules.",
+ "properties": {
+ "allowedIdps": {
+ "description": "AllowedIdps restricts which identity providers can authenticate.\nValues are Cloudflare Identity Provider UUIDs.\nWhen empty, all IdPs configured in the account are allowed.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 25,
+ "type": "array"
+ },
+ "appLauncherVisible": {
+ "default": true,
+ "description": "AppLauncherVisible controls whether the application appears in the\nCloudflare App Launcher dashboard. Use pointer to distinguish\nexplicit false (hidden) from absent (default visible).",
+ "type": "boolean"
+ },
+ "autoRedirectToIdentity": {
+ "description": "AutoRedirectToIdentity auto-redirects to the identity provider\nwhen a single IdP is configured in allowedIdps. Skips the IdP\nselection page.",
+ "type": "boolean"
+ },
+ "corsHeaders": {
+ "description": "CORSHeaders configures CORS for browser-based APIs behind Access.\nWhen set, Cloudflare responds to OPTIONS preflight on behalf of the origin.\nMutually exclusive with optionsPreflightBypass.",
+ "properties": {
+ "allowAllHeaders": {
+ "description": "AllowAllHeaders allows all HTTP request headers.",
+ "type": "boolean"
+ },
+ "allowAllMethods": {
+ "description": "AllowAllMethods allows all HTTP request methods.",
+ "type": "boolean"
+ },
+ "allowAllOrigins": {
+ "description": "AllowAllOrigins allows all origins.",
+ "type": "boolean"
+ },
+ "allowCredentials": {
+ "description": "AllowCredentials includes credentials (cookies, authorization headers,\nor TLS client certificates) with CORS requests.",
+ "type": "boolean"
+ },
+ "allowedHeaders": {
+ "description": "AllowedHeaders lists specific allowed HTTP request headers.\nIgnored when allowAllHeaders is true.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ },
+ "allowedMethods": {
+ "description": "AllowedMethods lists specific allowed HTTP request methods.\nIgnored when allowAllMethods is true.",
+ "items": {
+ "description": "CORSAllowedMethod is an HTTP method allowed for CORS requests.",
+ "enum": [
+ "GET",
+ "POST",
+ "HEAD",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array"
+ },
+ "allowedOrigins": {
+ "description": "AllowedOrigins lists specific allowed origins.\nIgnored when allowAllOrigins is true.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ },
+ "maxAge": {
+ "description": "MaxAge is the maximum number of seconds preflight results can be cached.",
+ "maximum": 86400,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "customDenyMessage": {
+ "description": "CustomDenyMessage shown when access is denied.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "customDenyUrl": {
+ "description": "CustomDenyURL redirects to this URL when denied (instead of message).",
+ "type": "string"
+ },
+ "customNonIdentityDenyUrl": {
+ "description": "CustomNonIdentityDenyURL is the URL users are redirected to when\ndenied by a non-identity (service auth) policy. Separate from\ncustomDenyUrl which handles identity-based denials.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "domain": {
+ "description": "Domain is the protected domain (auto-generated from routes if omitted).\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)",
+ "rule": "self == '' || self.split('.').all(s, size(s) <= 63)"
+ }
+ ]
+ },
+ "enableBindingCookie": {
+ "default": false,
+ "description": "EnableBindingCookie enables binding cookies for sticky sessions.",
+ "type": "boolean"
+ },
+ "httpOnlyCookieAttribute": {
+ "default": true,
+ "description": "HttpOnlyCookieAttribute adds HttpOnly to session cookies.",
+ "type": "boolean"
+ },
+ "logoUrl": {
+ "description": "LogoURL is the application logo in dashboard.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the display name in Cloudflare dashboard.\nDefaults to CR name if omitted.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "optionsPreflightBypass": {
+ "description": "OptionsPreflightBypass allows OPTIONS preflight requests to bypass\nAccess authentication and go directly to the origin. Enabling this\nremoves all CORS header settings. Mutually exclusive with corsHeaders.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "Path restricts protection to a specific absolute path prefix.\nCloudflare Access paths must not include query strings or fragments.",
+ "maxLength": 1024,
+ "pattern": "^/[^?#]*$",
+ "type": "string"
+ },
+ "pathCookieAttribute": {
+ "description": "PathCookieAttribute scopes the Access JWT cookie to the application\npath instead of the hostname. When enabled, users must re-authenticate\nfor different paths on the same hostname.",
+ "type": "boolean"
+ },
+ "readServiceTokensFromHeader": {
+ "description": "ReadServiceTokensFromHeader enables reading service tokens from a\nsingle custom HTTP header instead of the standard CF-Access-Client-Id\nand CF-Access-Client-Secret header pair. The value is the header name.\nThe header value must contain a JSON object with \"cf-access-client-id\"\nand \"cf-access-client-secret\" keys.",
+ "maxLength": 256,
+ "type": "string"
+ },
+ "sameSiteCookieAttribute": {
+ "default": "lax",
+ "description": "SameSiteCookieAttribute controls cross-site cookie behavior.",
+ "enum": [
+ "strict",
+ "lax",
+ "none"
+ ],
+ "type": "string"
+ },
+ "serviceAuth401Redirect": {
+ "description": "ServiceAuth401Redirect returns a 401 status code instead of\nredirecting to the Access login page when a request is blocked by a\nService Auth (non_identity) policy. Enable for API consumers.",
+ "type": "boolean"
+ },
+ "sessionDuration": {
+ "default": "24h",
+ "description": "SessionDuration controls session cookie lifetime.",
+ "pattern": "^([0-9]+(ns|us|ms|s|m|h))+$",
+ "type": "string"
+ },
+ "skipInterstitial": {
+ "default": false,
+ "description": "SkipInterstitial bypasses the Access login page for API requests.",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "self_hosted",
+ "description": "Type is the application type.",
+ "enum": [
+ "self_hosted"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "corsHeaders and optionsPreflightBypass are mutually exclusive",
+ "rule": "!(has(self.corsHeaders) && has(self.optionsPreflightBypass) && self.optionsPreflightBypass)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "cloudflareRef": {
+ "description": "CloudflareRef references Cloudflare credentials. When omitted, credentials\nare inherited from each target's route -> Gateway -> CloudflareTunnel chain.\nMultiple targets must inherit the same Cloudflare account.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare account name (looked up via API).",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the secret containing credentials.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret (defaults to policy namespace).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "policyRefs": {
+ "description": "PolicyRefs lists reusable CloudflareAccessPolicy resources to attach.",
+ "items": {
+ "description": "AccessPolicyReference references a reusable CloudflareAccessPolicy.",
+ "properties": {
+ "name": {
+ "description": "Name is the CloudflareAccessPolicy name.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "default": "",
+ "description": "Namespace is the CloudflareAccessPolicy namespace. Empty defaults to application namespace.\nCross-namespace references require ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "precedence": {
+ "description": "Precedence determines policy evaluation order for the application. Lower values run first.\nWhen omitted, the controller uses list order starting at 1.",
+ "maximum": 9999,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name",
+ "namespace"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "targetRef": {
+ "description": "TargetRef identifies a single Gateway API target.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs identifies multiple Gateway API targets.",
+ "items": {
+ "description": "PolicyTargetReference identifies a Gateway API resource for Access application attachment.\n\nPolicyTargetReference follows the Gateway API LocalPolicyTargetReferenceWithSectionName\npattern. It targets Gateway API Gateway and HTTPRoute resources and extracts\nhostnames and paths from those resources to create corresponding Cloudflare Access\napplications.\n\nCross-namespace references require a ReferenceGrant in the target namespace that permits\nCloudflareAccessApplication resources from the application's namespace.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "policyRefs"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be specified",
+ "rule": "has(self.targetRef) || has(self.targetRefs)"
+ },
+ {
+ "message": "targetRef and targetRefs are mutually exclusive",
+ "rule": "!(has(self.targetRef) && has(self.targetRefs))"
+ },
+ {
+ "message": "policyRefs must either all omit precedence or all specify precedence",
+ "rule": "self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p, has(p.precedence))"
+ },
+ {
+ "message": "policyRefs precedence values must be unique",
+ "rule": "self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p, has(p.precedence) && self.policyRefs.exists_one(q, has(q.precedence) && q.precedence == p.precedence))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareAccessApplicationStatus defines observed Access application state.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the resolved Cloudflare account ID used for Access application cleanup.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "ancestors": {
+ "description": "Ancestors contains status for each targetRef.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the policy attachment status for a specific target.\n\nPolicyAncestorStatus follows the Gateway API PolicyAncestorStatus pattern to report\nper-target attachment status. Each target reference in the spec has a corresponding\nancestor status entry showing whether the policy was successfully attached.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef identifies the target.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions for this specific target.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "controllerName": {
+ "description": "ControllerName identifies the controller managing this attachment.",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "applications": {
+ "description": "Applications are Cloudflare Access Applications managed by this resource.",
+ "items": {
+ "description": "AccessApplicationObserved records a Cloudflare Access Application created for one host/path target.",
+ "properties": {
+ "aud": {
+ "description": "AUD is the Application Audience Tag.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "domain": {
+ "description": "Domain is the protected hostname/path in Cloudflare.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "id": {
+ "description": "ID is the Cloudflare Access Application ID.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef identifies the Gateway API target that produced this application.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "attachedTargets": {
+ "description": "AttachedTargets is the count of successfully attached Gateway API targets.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "conditions": {
+ "description": "Conditions describe current state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "credentialSecretRef": {
+ "description": "CredentialSecretRef is the resolved credentials Secret used for cleanup.\nThe namespace is always stored explicitly.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the last generation processed.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/cfgate.io/cloudflareaccesspolicy_v1alpha1.json b/crdSchemas/cfgate.io/cloudflareaccesspolicy_v1alpha1.json
new file mode 100644
index 0000000..23424ca
--- /dev/null
+++ b/crdSchemas/cfgate.io/cloudflareaccesspolicy_v1alpha1.json
@@ -0,0 +1,1014 @@
+{
+ "description": "CloudflareAccessPolicy is the Schema for the cloudflareaccesspolicies API.\n\nCloudflareAccessPolicy manages a reusable account-level Cloudflare Access Policy.\nCloudflareAccessApplication attaches reusable policies to Gateway API targets.\n\nAccess rules are organized into implementation tiers based on IdP requirements:\n - P0: IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken (no IdP)\n - P1: Email, EmailList, EmailDomain, OIDCClaim (basic IdP required)\n - P2: GSuiteGroup (Google Workspace required)\n - P3: not in current product scope (Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.)\n\nStatus conditions:\n - Ready: policy is synced and service tokens are ready when configured\n - CredentialsValid: Cloudflare credentials have been validated\n - ServiceTokensReady: all service tokens have been created\n - PolicySynced: reusable Access policy exists in Cloudflare",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareAccessPolicySpec defines a reusable Cloudflare Access policy.\n\nCloudflareAccessPolicySpec manages account-level reusable Access policies. Applications\nattach these policies through CloudflareAccessApplication policyRefs.",
+ "properties": {
+ "approvalGroups": {
+ "description": "ApprovalGroups defines who can approve access.",
+ "items": {
+ "description": "ApprovalGroup defines who can approve access requests for approval-required policies.\n\nApprovalGroup specifies approvers by email address or email list UUID. When a\npolicy requires approval, users matching this group can approve or deny access requests.",
+ "properties": {
+ "approvalsNeeded": {
+ "default": 1,
+ "description": "ApprovalsNeeded is number of approvals required.",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "emailListUuid": {
+ "description": "EmailListUUID is a Cloudflare Access email list UUID whose members can approve.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "emails": {
+ "description": "Emails of approvers.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one approver (emails or emailListUuid) must be specified",
+ "rule": "(has(self.emails) && size(self.emails) > 0) || has(self.emailListUuid)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "approvalRequired": {
+ "default": false,
+ "description": "ApprovalRequired requires approval from specific users.",
+ "type": "boolean"
+ },
+ "cloudflareRef": {
+ "description": "CloudflareRef references Cloudflare credentials.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare account name (looked up via API).",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the secret containing credentials.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret (defaults to policy namespace).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "decision": {
+ "default": "allow",
+ "description": "Decision is the policy action.",
+ "enum": [
+ "allow",
+ "deny",
+ "bypass",
+ "non_identity"
+ ],
+ "type": "string"
+ },
+ "exclude": {
+ "description": "Exclude rules (if ANY match, policy does not apply).",
+ "items": {
+ "description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
+ "properties": {
+ "anyValidServiceToken": {
+ "description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
+ "type": "boolean"
+ },
+ "country": {
+ "description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
+ "properties": {
+ "codes": {
+ "description": "Codes are ISO 3166-1 alpha-2 country codes.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "codes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "email": {
+ "description": "Email matches specific email addresses.\nSDK: EmailRule",
+ "properties": {
+ "addresses": {
+ "description": "Addresses to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "addresses"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailDomain": {
+ "description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
+ "properties": {
+ "domain": {
+ "description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "domain"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailList": {
+ "description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the Access list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "everyone": {
+ "description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
+ "type": "boolean"
+ },
+ "group": {
+ "description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
+ "properties": {
+ "id": {
+ "description": "ID is the Cloudflare Access Group ID.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "id"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gsuiteGroup": {
+ "description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
+ "properties": {
+ "email": {
+ "description": "Email is the Google Workspace group email.",
+ "maxLength": 320,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "email",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ip": {
+ "description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
+ "properties": {
+ "ranges": {
+ "description": "Ranges are CIDR blocks (IPv4 or IPv6).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "ranges"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipList": {
+ "description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the IP list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "oidcClaim": {
+ "description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
+ "properties": {
+ "claimName": {
+ "description": "ClaimName is the OIDC claim to match.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "claimValue": {
+ "description": "ClaimValue is the expected value.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "claimName",
+ "claimValue",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "serviceToken": {
+ "description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
+ "properties": {
+ "name": {
+ "description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "tokenId": {
+ "description": "TokenID is the Cloudflare service token ID.",
+ "maxLength": 36,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tokenId or name must be specified",
+ "rule": "has(self.tokenId) || has(self.name)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one rule type must be specified",
+ "rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 25,
+ "type": "array"
+ },
+ "include": {
+ "description": "Include rules (ANY must match for policy to apply).",
+ "items": {
+ "description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
+ "properties": {
+ "anyValidServiceToken": {
+ "description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
+ "type": "boolean"
+ },
+ "country": {
+ "description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
+ "properties": {
+ "codes": {
+ "description": "Codes are ISO 3166-1 alpha-2 country codes.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "codes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "email": {
+ "description": "Email matches specific email addresses.\nSDK: EmailRule",
+ "properties": {
+ "addresses": {
+ "description": "Addresses to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "addresses"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailDomain": {
+ "description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
+ "properties": {
+ "domain": {
+ "description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "domain"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailList": {
+ "description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the Access list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "everyone": {
+ "description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
+ "type": "boolean"
+ },
+ "group": {
+ "description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
+ "properties": {
+ "id": {
+ "description": "ID is the Cloudflare Access Group ID.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "id"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gsuiteGroup": {
+ "description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
+ "properties": {
+ "email": {
+ "description": "Email is the Google Workspace group email.",
+ "maxLength": 320,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "email",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ip": {
+ "description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
+ "properties": {
+ "ranges": {
+ "description": "Ranges are CIDR blocks (IPv4 or IPv6).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "ranges"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipList": {
+ "description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the IP list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "oidcClaim": {
+ "description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
+ "properties": {
+ "claimName": {
+ "description": "ClaimName is the OIDC claim to match.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "claimValue": {
+ "description": "ClaimValue is the expected value.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "claimName",
+ "claimValue",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "serviceToken": {
+ "description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
+ "properties": {
+ "name": {
+ "description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "tokenId": {
+ "description": "TokenID is the Cloudflare service token ID.",
+ "maxLength": 36,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tokenId or name must be specified",
+ "rule": "has(self.tokenId) || has(self.name)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one rule type must be specified",
+ "rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 25,
+ "minItems": 1,
+ "type": "array"
+ },
+ "name": {
+ "description": "Name is the Cloudflare Access policy display name.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "purposeJustificationPrompt": {
+ "description": "PurposeJustificationPrompt is the prompt shown to user.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "purposeJustificationRequired": {
+ "default": false,
+ "description": "PurposeJustificationRequired requires user to provide justification.",
+ "type": "boolean"
+ },
+ "require": {
+ "description": "Require rules (ALL must match for policy to apply).",
+ "items": {
+ "description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
+ "properties": {
+ "anyValidServiceToken": {
+ "description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
+ "type": "boolean"
+ },
+ "country": {
+ "description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
+ "properties": {
+ "codes": {
+ "description": "Codes are ISO 3166-1 alpha-2 country codes.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "codes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "email": {
+ "description": "Email matches specific email addresses.\nSDK: EmailRule",
+ "properties": {
+ "addresses": {
+ "description": "Addresses to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "addresses"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailDomain": {
+ "description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
+ "properties": {
+ "domain": {
+ "description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "domain"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailList": {
+ "description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the Access list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "everyone": {
+ "description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
+ "type": "boolean"
+ },
+ "group": {
+ "description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
+ "properties": {
+ "id": {
+ "description": "ID is the Cloudflare Access Group ID.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "id"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gsuiteGroup": {
+ "description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
+ "properties": {
+ "email": {
+ "description": "Email is the Google Workspace group email.",
+ "maxLength": 320,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "email",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ip": {
+ "description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
+ "properties": {
+ "ranges": {
+ "description": "Ranges are CIDR blocks (IPv4 or IPv6).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "ranges"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipList": {
+ "description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the IP list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "oidcClaim": {
+ "description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
+ "properties": {
+ "claimName": {
+ "description": "ClaimName is the OIDC claim to match.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "claimValue": {
+ "description": "ClaimValue is the expected value.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "claimName",
+ "claimValue",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "serviceToken": {
+ "description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
+ "properties": {
+ "name": {
+ "description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "tokenId": {
+ "description": "TokenID is the Cloudflare service token ID.",
+ "maxLength": 36,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tokenId or name must be specified",
+ "rule": "has(self.tokenId) || has(self.name)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one rule type must be specified",
+ "rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 25,
+ "type": "array"
+ },
+ "serviceTokens": {
+ "description": "ServiceTokens for machine-to-machine authentication.",
+ "items": {
+ "description": "ServiceTokenConfig defines configuration for Cloudflare Access service tokens.\n\nServiceTokenConfig enables machine-to-machine authentication. The controller creates\nthe service token in Cloudflare and stores the credentials (client ID and secret) in\nthe referenced Kubernetes Secret. The secret is only visible at creation time.",
+ "properties": {
+ "duration": {
+ "default": "8760h",
+ "description": "Duration is the token validity period using Go duration format.\nOnly hours (h) supported by Cloudflare API. Use \"8760h\" for 1 year.",
+ "pattern": "^[0-9]+h$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the token display name.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "SecretRef stores the generated token credentials.",
+ "properties": {
+ "name": {
+ "description": "Name of the Secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "secretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "sessionDuration": {
+ "description": "SessionDuration overrides application session duration for this policy.",
+ "maxLength": 32,
+ "pattern": "^([0-9]+(ns|us|ms|s|m|h))+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "cloudflareRef",
+ "decision",
+ "include",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "include rules are required",
+ "rule": "size(self.include) > 0"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareAccessPolicyStatus defines the observed state of a CloudflareAccessPolicy resource.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare account ID used for this policy.",
+ "type": "string"
+ },
+ "appCount": {
+ "description": "AppCount is the number of Access Applications currently using this policy.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "conditions": {
+ "description": "Conditions describe current state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "credentialSecretRef": {
+ "description": "CredentialSecretRef is the resolved credentials Secret used for cleanup.\nThe namespace is always stored explicitly.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the last generation processed.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "policyId": {
+ "description": "PolicyID is the Cloudflare Access reusable policy ID.",
+ "type": "string"
+ },
+ "reusable": {
+ "description": "Reusable reports whether Cloudflare returned this policy as reusable.",
+ "type": "boolean"
+ },
+ "serviceTokenIds": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ServiceTokenIDs maps token names to Cloudflare IDs.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/cfgate.io/cloudflaredns_v1alpha1.json b/crdSchemas/cfgate.io/cloudflaredns_v1alpha1.json
new file mode 100644
index 0000000..9a368e5
--- /dev/null
+++ b/crdSchemas/cfgate.io/cloudflaredns_v1alpha1.json
@@ -0,0 +1,591 @@
+{
+ "description": "CloudflareDNS is the Schema for the cloudflarednses API.\n\nCloudflareDNS manages DNS record synchronization independently from CloudflareTunnel resources.\nIt supports two target modes: tunnel references (for tunnel-based CNAME records) and external\ntargets (for non-tunnel DNS management). DNS records can be sourced from Gateway API routes\nor explicitly defined.\n\nCloudflareDNS implements ownership tracking via TXT records (aligned with external-dns patterns)\nto enable safe multi-cluster deployments and prevent accidental deletion of records created\nby other installations.\n\nStatus conditions:\n - Ready: DNS sync is fully operational\n - CredentialsValid: Cloudflare credentials have been validated\n - ZonesResolved: All configured zones have been resolved via API\n - RecordsSynced: DNS records have been synchronized to Cloudflare\n - OwnershipVerified: TXT ownership records have been verified, when enabled",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareDNSSpec defines the desired state of a CloudflareDNS resource.\n\nCloudflareDNSSpec configures DNS record synchronization, including the target\n(tunnel or external), zones to manage, hostname sources, and ownership tracking.\nEither tunnelRef or externalTarget must be specified (mutually exclusive).",
+ "properties": {
+ "cleanupPolicy": {
+ "description": "CleanupPolicy defines cleanup behavior for records.",
+ "properties": {
+ "deleteOnResourceRemoval": {
+ "description": "DeleteOnResourceRemoval deletes records when CloudflareDNS resource is deleted.\nnil defaults to true.",
+ "type": "boolean"
+ },
+ "deleteOnRouteRemoval": {
+ "description": "DeleteOnRouteRemoval deletes records when the source route is deleted.\nnil defaults to true.",
+ "type": "boolean"
+ },
+ "onlyManaged": {
+ "description": "OnlyManaged only deletes records that were created by cfgate (verified via ownership).\nnil defaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cloudflare": {
+ "description": "Cloudflare API credentials (required when using externalTarget).\nWhen using tunnelRef, credentials are inherited from the tunnel.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare Account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare Account name. Will be looked up via API.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "secretKeys": {
+ "description": "SecretKeys defines the key mappings within the secret.",
+ "properties": {
+ "apiToken": {
+ "default": "CLOUDFLARE_API_TOKEN",
+ "description": "APIToken is the key name for the Cloudflare API token.",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secretRef": {
+ "description": "SecretRef references the Secret containing Cloudflare API credentials.\nThe secret must contain an API token (not tunnel token).",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the tunnel's namespace.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "secretRef"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either accountId or accountName must be specified",
+ "rule": "has(self.accountId) || has(self.accountName)"
+ },
+ {
+ "message": "accountId must be a 32-character hex string",
+ "rule": "!has(self.accountId) || self.accountId.matches('^[a-f0-9]{32}$')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "defaults": {
+ "description": "Defaults defines default settings for DNS records.",
+ "properties": {
+ "proxied": {
+ "default": true,
+ "description": "Proxied enables Cloudflare proxy by default.",
+ "type": "boolean"
+ },
+ "ttl": {
+ "default": 1,
+ "description": "TTL is the default DNS record TTL in seconds.\nValid values: 1 (auto) or 60-86400 (explicit).",
+ "format": "int32",
+ "maximum": 86400,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "TTL must be 1 (auto) or between 60 and 86400 seconds",
+ "rule": "!has(self.ttl) || self.ttl == 1 || (self.ttl >= 60 && self.ttl <= 86400)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "externalTarget": {
+ "description": "ExternalTarget specifies a non-tunnel DNS target.",
+ "properties": {
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "CNAME",
+ "A",
+ "AAAA"
+ ]
+ },
+ {
+ "enum": [
+ "CNAME",
+ "A",
+ "AAAA"
+ ]
+ }
+ ],
+ "description": "Type is the DNS record type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the target value (domain for CNAME, IP for A/AAAA).\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "type",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fallbackCredentialsRef": {
+ "description": "FallbackCredentialsRef references fallback Cloudflare API credentials.\nUsed during deletion when primary credentials are unavailable.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ownership": {
+ "description": "Ownership defines how to track record ownership.",
+ "properties": {
+ "comment": {
+ "description": "Comment configures comment-based ownership.\n\nDeprecated: since v0.1.0-alpha.13. All fields are ignored. Will be removed in a future cleanup release.",
+ "properties": {
+ "enabled": {
+ "default": false,
+ "description": "Enabled enables comment-based ownership tracking.\n\nDeprecated: since v0.1.0-alpha.13. This field is ignored. The controller always\nwrites a \"managed by cfgate\" comment. Will be removed in a future cleanup release.",
+ "type": "boolean"
+ },
+ "template": {
+ "default": "managed by cfgate",
+ "description": "Template is the comment template.\n\nDeprecated: since v0.1.0-alpha.13. This field is ignored. The controller always\nuses \"managed by cfgate\" as the comment. Will be removed in a future cleanup release.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ownerId": {
+ "description": "OwnerID is the cluster/installation identifier used in TXT ownership records.\nUsed to distinguish records created by different cfgate installations.\nDefaults to the CloudflareDNS resource's namespace/name if not specified.",
+ "maxLength": 253,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(/[a-z0-9]([-a-z0-9]*[a-z0-9])?)?$",
+ "type": "string"
+ },
+ "txtRecord": {
+ "description": "TXTRecord configures TXT record-based ownership.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled enables TXT record ownership tracking.\nnil defaults to true.",
+ "type": "boolean"
+ },
+ "prefix": {
+ "default": "_cfgate",
+ "description": "Prefix is the prefix for TXT record names.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "policy": {
+ "allOf": [
+ {
+ "enum": [
+ "sync",
+ "upsert-only",
+ "create-only"
+ ]
+ },
+ {
+ "enum": [
+ "sync",
+ "upsert-only",
+ "create-only"
+ ]
+ }
+ ],
+ "default": "sync",
+ "description": "Policy controls DNS record lifecycle.",
+ "type": "string"
+ },
+ "source": {
+ "description": "Source defines where to get hostnames to sync.",
+ "properties": {
+ "explicit": {
+ "description": "Explicit defines explicit hostnames to sync.",
+ "items": {
+ "description": "DNSExplicitHostname defines an explicit hostname to sync with optional per-hostname configuration.\n\nDNSExplicitHostname provides direct specification of DNS hostnames without depending on\nGateway API route discovery. The Target field supports the template\nvariable for dynamic resolution when using tunnelRef.",
+ "properties": {
+ "hostname": {
+ "description": "Hostname is the DNS hostname to create.\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)",
+ "rule": "self.split('.').all(s, size(s) <= 63)"
+ }
+ ]
+ },
+ "proxied": {
+ "description": "Proxied enables Cloudflare proxy for this record.\nnil inherits from zone or defaults.",
+ "type": "boolean"
+ },
+ "target": {
+ "description": "Target overrides the resolved record target for this hostname.\nSupports template variable when tunnelRef is used.\nDefaults to the resource-level resolved target when omitted.\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "ttl": {
+ "default": 1,
+ "description": "TTL is the DNS record TTL in seconds. 1 means auto (Cloudflare managed).\nValid values: 1 (auto) or 60-86400 (explicit).",
+ "format": "int32",
+ "maximum": 86400,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "hostname"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "TTL must be 1 (auto) or between 60 and 86400 seconds",
+ "rule": "!has(self.ttl) || self.ttl == 1 || (self.ttl >= 60 && self.ttl <= 86400)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 100,
+ "type": "array"
+ },
+ "gatewayRoutes": {
+ "description": "GatewayRoutes configures watching Gateway API routes.",
+ "properties": {
+ "annotationFilter": {
+ "description": "AnnotationFilter only syncs routes with this annotation.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "enabled": {
+ "default": true,
+ "description": "Enabled enables watching Gateway API routes.",
+ "type": "boolean"
+ },
+ "namespaceSelector": {
+ "description": "NamespaceSelector limits route discovery to specific namespaces.",
+ "properties": {
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels selects namespaces with matching labels.",
+ "maxProperties": 10,
+ "type": "object"
+ },
+ "matchNames": {
+ "description": "MatchNames selects namespaces by name.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one selector must be specified",
+ "rule": "has(self.matchLabels) || has(self.matchNames)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tunnelRef": {
+ "description": "TunnelRef references a CloudflareTunnel for CNAME target resolution.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the CloudflareTunnel.",
+ "maxLength": 63,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the CloudflareTunnel.\nDefaults to the CloudflareDNS's namespace.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "zones": {
+ "description": "Zones defines the DNS zones to manage.",
+ "items": {
+ "description": "DNSZoneConfig defines a DNS zone where records will be managed.\n\nDNSZoneConfig identifies a Cloudflare DNS zone either by name (requiring API lookup)\nor by explicit zone ID. The optional Proxied field sets the default proxy behavior\nfor all records in this zone.",
+ "properties": {
+ "id": {
+ "description": "ID is the optional explicit zone ID (skips API lookup).",
+ "maxLength": 32,
+ "pattern": "^[a-f0-9]{32}$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the zone domain name (e.g., example.com).\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)",
+ "rule": "self.split('.').all(s, size(s) <= 63)"
+ }
+ ]
+ },
+ "proxied": {
+ "description": "Proxied sets the default proxied setting for this zone.\nnil inherits from spec.defaults.proxied.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "zones"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tunnelRef or externalTarget must be specified",
+ "rule": "has(self.tunnelRef) || has(self.externalTarget)"
+ },
+ {
+ "message": "tunnelRef and externalTarget are mutually exclusive",
+ "rule": "!(has(self.tunnelRef) && has(self.externalTarget))"
+ },
+ {
+ "message": "cloudflare credentials required when using externalTarget",
+ "rule": "has(self.tunnelRef) || has(self.cloudflare)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareDNSStatus defines the observed state of a CloudflareDNS resource.\n\nCloudflareDNSStatus captures the synchronization state of all DNS records, including\ncounts of synced, pending, and failed records. The ResolvedTarget field shows the\nactual CNAME target being used (either from tunnel or external target).",
+ "properties": {
+ "conditions": {
+ "description": "Conditions represent the latest available observations.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "failedRecords": {
+ "description": "FailedRecords is the number of records that failed to sync.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "lastSyncTime": {
+ "description": "LastSyncTime is the last time records were synced.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the generation observed by the controller.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "pendingRecords": {
+ "description": "PendingRecords is the number of records pending sync.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "records": {
+ "description": "Records contains the status of individual DNS records.",
+ "items": {
+ "description": "DNSRecordSyncStatus represents the synchronization status of a single DNS record.\n\nDNSRecordSyncStatus tracks individual DNS record state including the Cloudflare record ID,\ncurrent configuration, and sync status. The Status field indicates: Synced (successfully\nsynchronized), Pending (awaiting sync), or Failed (sync failed, see Error field).",
+ "properties": {
+ "error": {
+ "description": "Error contains the error message if status is Failed.",
+ "type": "string"
+ },
+ "hostname": {
+ "description": "Hostname is the DNS hostname.",
+ "type": "string"
+ },
+ "proxied": {
+ "description": "Proxied indicates if Cloudflare proxy is enabled.",
+ "type": "boolean"
+ },
+ "recordId": {
+ "description": "RecordID is the Cloudflare record ID.",
+ "type": "string"
+ },
+ "status": {
+ "description": "Status is the sync status: Synced, Pending, Failed.",
+ "type": "string"
+ },
+ "target": {
+ "description": "Target is the record target/content.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL is the record TTL.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": {
+ "description": "Type is the DNS record type (CNAME, A, AAAA).",
+ "type": "string"
+ },
+ "zoneId": {
+ "description": "ZoneID is the Cloudflare zone ID where the record was created.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "hostname",
+ "proxied",
+ "status",
+ "target",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 1000,
+ "type": "array"
+ },
+ "resolvedTarget": {
+ "description": "ResolvedTarget is the resolved CNAME target (tunnel domain or external value).",
+ "type": "string"
+ },
+ "syncedRecords": {
+ "description": "SyncedRecords is the number of successfully synced records.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/cfgate.io/cloudflaretunnel_v1alpha1.json b/crdSchemas/cfgate.io/cloudflaretunnel_v1alpha1.json
new file mode 100644
index 0000000..783ad2b
--- /dev/null
+++ b/crdSchemas/cfgate.io/cloudflaretunnel_v1alpha1.json
@@ -0,0 +1,483 @@
+{
+ "description": "CloudflareTunnel is the Schema for the cloudflaretunnels API.\n\nCloudflareTunnel manages the lifecycle of a Cloudflare Tunnel and its cloudflared daemon\ndeployment. It handles tunnel creation or adoption, credential management, and deploys\ncloudflared pods that establish secure connections to Cloudflare's edge network.\n\nCloudflareTunnel follows a composable architecture where tunnel lifecycle is separate from\nDNS management. Use CloudflareDNS with a tunnelRef to create DNS records pointing to this\ntunnel's domain.\n\nStatus conditions:\n - Ready: tunnel is fully operational\n - CredentialsValid: API credentials have been validated\n - TunnelReady: tunnel exists in Cloudflare\n - ConfigurationSynced: ingress configuration is synced\n - CloudflaredDeployed: cloudflared pods are running",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareTunnelSpec defines the desired state of a CloudflareTunnel resource.\n\nCloudflareTunnelSpec configures the tunnel identity, Cloudflare credentials, cloudflared\ndeployment settings, and origin connection defaults. The tunnel manages lifecycle only;\nDNS records are managed separately via CloudflareDNS resources.",
+ "properties": {
+ "cloudflare": {
+ "description": "Cloudflare defines the Cloudflare API credentials.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare Account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare Account name. Will be looked up via API.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "secretKeys": {
+ "description": "SecretKeys defines the key mappings within the secret.",
+ "properties": {
+ "apiToken": {
+ "default": "CLOUDFLARE_API_TOKEN",
+ "description": "APIToken is the key name for the Cloudflare API token.",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secretRef": {
+ "description": "SecretRef references the Secret containing Cloudflare API credentials.\nThe secret must contain an API token (not tunnel token).",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the tunnel's namespace.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "secretRef"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either accountId or accountName must be specified",
+ "rule": "has(self.accountId) || has(self.accountName)"
+ },
+ {
+ "message": "accountId must be a 32-character hex string",
+ "rule": "!has(self.accountId) || self.accountId.matches('^[a-f0-9]{32}$')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "cloudflared": {
+ "description": "Cloudflared defines the cloudflared deployment configuration.",
+ "properties": {
+ "extraArgs": {
+ "description": "ExtraArgs are additional arguments to pass to cloudflared.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "image": {
+ "default": "ghcr.io/inherent-design/cloudflared:2026.5.0-h2c.1",
+ "description": "Image is the cloudflared container image.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "imagePullPolicy": {
+ "default": "IfNotPresent",
+ "description": "ImagePullPolicy is the pull policy for the cloudflared image.",
+ "enum": [
+ "Always",
+ "Never",
+ "IfNotPresent"
+ ],
+ "type": "string"
+ },
+ "metrics": {
+ "description": "Metrics configures the cloudflared metrics endpoint.",
+ "properties": {
+ "enabled": {
+ "default": true,
+ "description": "Enabled enables the metrics endpoint.",
+ "type": "boolean"
+ },
+ "port": {
+ "default": 44483,
+ "description": "Port is the port for the metrics endpoint.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "nodeSelector": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "NodeSelector is a selector for nodes to run cloudflared on.",
+ "maxProperties": 50,
+ "type": "object"
+ },
+ "podAnnotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "PodAnnotations are annotations to add to cloudflared pods.",
+ "maxProperties": 50,
+ "type": "object"
+ },
+ "protocol": {
+ "default": "auto",
+ "description": "Protocol is the tunnel transport protocol: auto, quic, http2.",
+ "enum": [
+ "auto",
+ "quic",
+ "http2"
+ ],
+ "type": "string"
+ },
+ "replicas": {
+ "default": 2,
+ "description": "Replicas is the number of cloudflared replicas.",
+ "format": "int32",
+ "maximum": 10,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "resources": {
+ "description": "Resources are the resource requirements for cloudflared containers.",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tolerations": {
+ "description": "Tolerations are tolerations for the cloudflared pods.",
+ "items": {
+ "description": "The pod this Toleration is attached to tolerates any taint that matches\nthe triple using the matching operator .",
+ "properties": {
+ "effect": {
+ "description": "Effect indicates the taint effect to match. Empty means match all taint effects.\nWhen specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.",
+ "type": "string"
+ },
+ "key": {
+ "description": "Key is the taint key that the toleration applies to. Empty means match all taint keys.\nIf the key is empty, operator must be Exists; this combination means to match all values and all keys.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Operator represents a key's relationship to the value.\nValid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.\nExists is equivalent to wildcard for value, so that a pod can\ntolerate all taints of a particular category.\nLt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).",
+ "type": "string"
+ },
+ "tolerationSeconds": {
+ "description": "TolerationSeconds represents the period of time the toleration (which must be\nof effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,\nit is not set, which means tolerate the taint forever (do not evict). Zero and\nnegative values will be treated as 0 (evict immediately) by the system.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "value": {
+ "description": "Value is the taint value the toleration matches to.\nIf the operator is Exists, the value should be empty, otherwise just a regular string.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 20,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fallbackCredentialsRef": {
+ "description": "FallbackCredentialsRef references a secret containing fallback Cloudflare API credentials.\nUsed during deletion when primary credentials (in Cloudflare.SecretRef) are unavailable.\nThis enables cleanup of Cloudflare resources even if the per-tunnel secret is deleted.\nThe secret must contain the same keys as the primary credentials secret.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fallbackTarget": {
+ "default": "http_status:404",
+ "description": "FallbackTarget is the service for unmatched requests.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "originDefaults": {
+ "description": "OriginDefaults defines default settings for origin connections.",
+ "properties": {
+ "caPoolSecretRef": {
+ "description": "CAPoolSecretRef references a Secret containing CA certificates for origin verification.",
+ "properties": {
+ "key": {
+ "default": "ca.crt",
+ "description": "Key is the key within the secret data.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connectTimeout": {
+ "default": "30s",
+ "description": "ConnectTimeout is the timeout for connecting to the origin.",
+ "pattern": "^[0-9]+(s|m|h)$",
+ "type": "string"
+ },
+ "h2cOrigin": {
+ "default": false,
+ "description": "H2cOrigin enables HTTP/2 cleartext (h2c) for origin connections.\nUse this for origins that speak HTTP/2 without TLS (e.g., gRPC services).\nMutually exclusive with http2Origin (TLS-based HTTP/2).",
+ "type": "boolean"
+ },
+ "http2Origin": {
+ "default": false,
+ "description": "HTTP2Origin enables HTTP/2 for origin connections.",
+ "type": "boolean"
+ },
+ "noTLSVerify": {
+ "default": false,
+ "description": "NoTLSVerify disables TLS verification for origin connections.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "http2Origin and h2cOrigin are mutually exclusive",
+ "rule": "!(self.http2Origin && self.h2cOrigin)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "tunnel": {
+ "description": "Tunnel defines the tunnel identity configuration.",
+ "properties": {
+ "name": {
+ "description": "Name is the tunnel name in Cloudflare. If tunnel with this name exists, adopt it.\nIf not, create it. Tunnel ID is stored in status after resolution/creation.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "cloudflare",
+ "tunnel"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareTunnelStatus defines the observed state of a CloudflareTunnel resource.\n\nCloudflareTunnelStatus captures the tunnel's Cloudflare-assigned identifiers, deployment\nstatus, and reconciliation state. The TunnelDomain field provides the CNAME target\n({tunnelId}.cfargotunnel.com) that CloudflareDNS uses for DNS record creation.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the resolved Cloudflare account ID.",
+ "type": "string"
+ },
+ "conditions": {
+ "description": "Conditions represent the latest available observations of the tunnel's state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "connectedRouteCount": {
+ "description": "ConnectedRouteCount is the number of routes connected to this tunnel.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "lastSyncTime": {
+ "description": "LastSyncTime is the last time the configuration was synced to Cloudflare.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the generation observed by the controller.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "readyReplicas": {
+ "description": "ReadyReplicas is the number of ready cloudflared replicas.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "replicas": {
+ "description": "Replicas is the total number of cloudflared replicas.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tunnelDomain": {
+ "description": "TunnelDomain is the tunnel's CNAME target domain (e.g., {tunnelId}.cfargotunnel.com).",
+ "type": "string"
+ },
+ "tunnelId": {
+ "description": "TunnelID is the Cloudflare tunnel ID.",
+ "type": "string"
+ },
+ "tunnelName": {
+ "description": "TunnelName is the Cloudflare tunnel name.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/ciliumcidrgroup_v2.json b/crdSchemas/cilium.io/ciliumcidrgroup_v2.json
similarity index 100%
rename from crdSchemas/ciliumcidrgroup_v2.json
rename to crdSchemas/cilium.io/ciliumcidrgroup_v2.json
diff --git a/crdSchemas/ciliumcidrgroup_v2alpha1.json b/crdSchemas/cilium.io/ciliumcidrgroup_v2alpha1.json
similarity index 100%
rename from crdSchemas/ciliumcidrgroup_v2alpha1.json
rename to crdSchemas/cilium.io/ciliumcidrgroup_v2alpha1.json
diff --git a/crdSchemas/ciliumclusterwidenetworkpolicy_v2.json b/crdSchemas/cilium.io/ciliumclusterwidenetworkpolicy_v2.json
similarity index 91%
rename from crdSchemas/ciliumclusterwidenetworkpolicy_v2.json
rename to crdSchemas/cilium.io/ciliumclusterwidenetworkpolicy_v2.json
index 4cada59..dc459e3 100644
--- a/crdSchemas/ciliumclusterwidenetworkpolicy_v2.json
+++ b/crdSchemas/cilium.io/ciliumclusterwidenetworkpolicy_v2.json
@@ -387,9 +387,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -398,18 +398,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -593,13 +597,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -622,14 +631,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -637,14 +638,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -770,57 +763,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -829,9 +771,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -1248,9 +1190,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1259,18 +1201,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -1369,13 +1315,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -1798,9 +1749,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1809,18 +1760,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2060,13 +2015,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2089,14 +2049,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -2104,14 +2056,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -2237,57 +2181,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -2296,9 +2189,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -2566,9 +2459,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -2577,18 +2470,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2743,13 +2640,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2775,13 +2677,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -3246,9 +3148,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -3257,18 +3159,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -3452,13 +3358,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -3481,14 +3392,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -3496,14 +3399,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -3629,57 +3524,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -3688,9 +3532,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -4107,9 +3951,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4118,18 +3962,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4228,13 +4076,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4657,9 +4510,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4668,18 +4521,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4919,13 +4776,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4948,14 +4810,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -4963,14 +4817,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -5096,57 +4942,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -5155,9 +4950,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -5425,9 +5220,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -5436,18 +5231,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -5602,13 +5401,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -5634,13 +5438,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -5819,5 +5623,11 @@
"required": [
"metadata"
],
- "type": "object"
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "spec or specs must be provided",
+ "rule": "has(self.spec) || has(self.specs)"
+ }
+ ]
}
diff --git a/crdSchemas/ciliumendpoint_v2.json b/crdSchemas/cilium.io/ciliumendpoint_v2.json
similarity index 100%
rename from crdSchemas/ciliumendpoint_v2.json
rename to crdSchemas/cilium.io/ciliumendpoint_v2.json
diff --git a/crdSchemas/ciliumidentity_v2.json b/crdSchemas/cilium.io/ciliumidentity_v2.json
similarity index 100%
rename from crdSchemas/ciliumidentity_v2.json
rename to crdSchemas/cilium.io/ciliumidentity_v2.json
diff --git a/crdSchemas/ciliuml2announcementpolicy_v2alpha1.json b/crdSchemas/cilium.io/ciliuml2announcementpolicy_v2alpha1.json
similarity index 100%
rename from crdSchemas/ciliuml2announcementpolicy_v2alpha1.json
rename to crdSchemas/cilium.io/ciliuml2announcementpolicy_v2alpha1.json
diff --git a/crdSchemas/ciliumloadbalancerippool_v2.json b/crdSchemas/cilium.io/ciliumloadbalancerippool_v2.json
similarity index 98%
rename from crdSchemas/ciliumloadbalancerippool_v2.json
rename to crdSchemas/cilium.io/ciliumloadbalancerippool_v2.json
index 87aedb0..87232b0 100644
--- a/crdSchemas/ciliumloadbalancerippool_v2.json
+++ b/crdSchemas/cilium.io/ciliumloadbalancerippool_v2.json
@@ -1,5 +1,5 @@
{
- "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to to allocate\nand advertise IPs for Services of type LoadBalancer.",
+ "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to allocate\nand advertise IPs for Services of type LoadBalancer.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
diff --git a/crdSchemas/ciliumloadbalancerippool_v2alpha1.json b/crdSchemas/cilium.io/ciliumloadbalancerippool_v2alpha1.json
similarity index 98%
rename from crdSchemas/ciliumloadbalancerippool_v2alpha1.json
rename to crdSchemas/cilium.io/ciliumloadbalancerippool_v2alpha1.json
index 87aedb0..87232b0 100644
--- a/crdSchemas/ciliumloadbalancerippool_v2alpha1.json
+++ b/crdSchemas/cilium.io/ciliumloadbalancerippool_v2alpha1.json
@@ -1,5 +1,5 @@
{
- "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to to allocate\nand advertise IPs for Services of type LoadBalancer.",
+ "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to allocate\nand advertise IPs for Services of type LoadBalancer.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
diff --git a/crdSchemas/ciliumnetworkpolicy_v2.json b/crdSchemas/cilium.io/ciliumnetworkpolicy_v2.json
similarity index 91%
rename from crdSchemas/ciliumnetworkpolicy_v2.json
rename to crdSchemas/cilium.io/ciliumnetworkpolicy_v2.json
index 20b88bd..b746e60 100644
--- a/crdSchemas/ciliumnetworkpolicy_v2.json
+++ b/crdSchemas/cilium.io/ciliumnetworkpolicy_v2.json
@@ -387,9 +387,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -398,18 +398,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -593,13 +597,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -622,14 +631,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -637,14 +638,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -770,57 +763,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -829,9 +771,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -1248,9 +1190,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1259,18 +1201,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -1369,13 +1315,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -1798,9 +1749,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1809,18 +1760,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2060,13 +2015,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2089,14 +2049,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -2104,14 +2056,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -2237,57 +2181,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -2296,9 +2189,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -2566,9 +2459,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -2577,18 +2470,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2743,13 +2640,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2775,13 +2677,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -3246,9 +3148,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -3257,18 +3159,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -3452,13 +3358,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -3481,14 +3392,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -3496,14 +3399,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -3629,57 +3524,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -3688,9 +3532,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -4107,9 +3951,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4118,18 +3962,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4228,13 +4076,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4657,9 +4510,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4668,18 +4521,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4919,13 +4776,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4948,14 +4810,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -4963,14 +4817,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -5096,57 +4942,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -5155,9 +4950,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -5425,9 +5220,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -5436,18 +5231,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -5602,13 +5401,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -5634,13 +5438,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -5819,5 +5623,11 @@
"required": [
"metadata"
],
- "type": "object"
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "spec or specs must be provided",
+ "rule": "has(self.spec) || has(self.specs)"
+ }
+ ]
}
diff --git a/crdSchemas/ciliumnode_v2.json b/crdSchemas/cilium.io/ciliumnode_v2.json
similarity index 93%
rename from crdSchemas/ciliumnode_v2.json
rename to crdSchemas/cilium.io/ciliumnode_v2.json
index c4c6087..f997432 100644
--- a/crdSchemas/ciliumnode_v2.json
+++ b/crdSchemas/cilium.io/ciliumnode_v2.json
@@ -43,6 +43,7 @@
},
"cidr-block": {
"description": "CIDRBlock is vpc ipv4 CIDR",
+ "format": "cidr",
"type": "string"
},
"instance-type": {
@@ -138,33 +139,14 @@
"minimum": 0,
"type": "integer"
},
- "instance-id": {
- "description": "InstanceID is the AWS InstanceId of the node. The InstanceID is used\nto retrieve AWS metadata for the node.\n\nOBSOLETE: This field is obsolete, please use Spec.InstanceID",
- "type": "string"
- },
"instance-type": {
"description": "InstanceType is the AWS EC2 instance type, e.g. \"m5.large\"",
"type": "string"
},
- "max-above-watermark": {
- "description": "MaxAboveWatermark is the maximum number of addresses to allocate\nbeyond the addresses needed to reach the PreAllocate watermark.\nGoing above the watermark can help reduce the number of API calls to\nallocate IPs, e.g. when a new ENI is allocated, as many secondary\nIPs as possible are allocated. Limiting the amount can help reduce\nwaste of IPs.\n\nOBSOLETE: This field is obsolete, please use Spec.IPAM.MaxAboveWatermark",
- "minimum": 0,
- "type": "integer"
- },
- "min-allocate": {
- "description": "MinAllocate is the minimum number of IPs that must be allocated when\nthe node is first bootstrapped. It defines the minimum base socket\nof addresses that must be available. After reaching this watermark,\nthe PreAllocate and MaxAboveWatermark logic takes over to continue\nallocating IPs.\n\nOBSOLETE: This field is obsolete, please use Spec.IPAM.MinAllocate",
- "minimum": 0,
- "type": "integer"
- },
"node-subnet-id": {
"description": "NodeSubnetID is the subnet of the primary ENI the instance was brought up\nwith. It is used as a sensible default subnet to create ENIs in.",
"type": "string"
},
- "pre-allocate": {
- "description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMspec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.\n\nOBSOLETE: This field is obsolete, please use Spec.IPAM.PreAllocate",
- "minimum": 0,
- "type": "integer"
- },
"security-group-tags": {
"additionalProperties": {
"type": "string"
@@ -277,6 +259,7 @@
"podCIDRs": {
"description": "PodCIDRs is the list of CIDRs available to the node for allocation.\nWhen an IP is used, the IP will be added to Status.IPAM.Used",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -308,10 +291,17 @@
"items": {
"description": "IPAMPoolAllocation describes an allocation of an IPAM pool from the operator to the\nnode. It contains the assigned PodCIDRs allocated from this pool",
"properties": {
+ "allowFirstIP": {
+ "description": "AllowFirstIP allows the first IP of each allocated CIDR to be used.",
+ "type": "boolean"
+ },
+ "allowLastIP": {
+ "description": "AllowLastIP allows the last IP of each allocated CIDR to be used.",
+ "type": "boolean"
+ },
"cidrs": {
"description": "CIDRs contains a list of pod CIDRs currently allocated from this pool",
"items": {
- "description": "IPAMPodCIDR is a pod CIDR",
"format": "cidr",
"type": "string"
},
@@ -369,7 +359,7 @@
"additionalProperties": false
},
"pre-allocate": {
- "description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMspec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.",
+ "description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMSpec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.",
"minimum": 0,
"type": "integer"
},
@@ -383,11 +373,6 @@
},
"type": "object",
"additionalProperties": false
- },
- "nodeidentity": {
- "description": "NodeIdentity is the Cilium numeric identity allocated for the node, if any.",
- "format": "int64",
- "type": "integer"
}
},
"type": "object",
@@ -459,15 +444,18 @@
"properties": {
"cidr": {
"description": "CIDRBlock is the VPC IPv4 CIDR",
+ "format": "cidr",
"type": "string"
},
"ipv6-cidr": {
"description": "IPv6CIDRBlock is the VPC IPv6 CIDR",
+ "format": "cidr",
"type": "string"
},
"secondary-cidrs": {
"description": "SecondaryCIDRs is the list of Secondary CIDRs associated with the VPC",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -485,10 +473,12 @@
"properties": {
"cidr": {
"description": "CIDRBlock is the vSwitch IPv4 CIDR",
+ "format": "cidr",
"type": "string"
},
"ipv6-cidr": {
"description": "IPv6CIDRBlock is the vSwitch IPv6 CIDR",
+ "format": "cidr",
"type": "string"
},
"vswitch-id": {
@@ -522,12 +512,8 @@
"items": {
"description": "AzureInterface represents an Azure Interface",
"properties": {
- "GatewayIP": {
- "description": "GatewayIP is the interface's subnet's default route\n\nOBSOLETE: This field is obsolete, please use Gateway field instead.",
- "type": "string"
- },
"addresses": {
- "description": "Addresses is the list of all IPs associated with the interface,\nincluding all secondary addresses",
+ "description": "Addresses is the list of secondary IPs associated with the interface.\nThe primary IP is tracked separately in the IP field, but is also\nincluded here when the operator is configured to expose it for\nallocation.",
"items": {
"description": "AzureAddress is an IP address assigned to an AzureInterface",
"properties": {
@@ -540,7 +526,7 @@
"type": "string"
},
"subnet": {
- "description": "Subnet is the subnet the address belongs to",
+ "description": "Subnet is the subnet the address belongs to.\n\nDeprecated: use AzureInterface.Subnet.ID. Populated as a mirror for one\nrelease so external consumers of CiliumNode.Status.Azure can migrate.",
"type": "string"
}
},
@@ -550,7 +536,8 @@
"type": "array"
},
"cidr": {
- "description": "CIDR is the range that the interface belongs to.",
+ "description": "CIDR is the range that the interface belongs to.\n\nDeprecated: use Subnet.CIDR. Retained for one release so agent/operator\nrolling upgrades work in either order.",
+ "format": "cidr",
"type": "string"
},
"gateway": {
@@ -561,6 +548,10 @@
"description": "ID is the identifier",
"type": "string"
},
+ "ip": {
+ "description": "IP is the primary IP of the interface",
+ "type": "string"
+ },
"mac": {
"description": "MAC is the mac address",
"type": "string"
@@ -576,6 +567,22 @@
"state": {
"description": "State is the provisioning state",
"type": "string"
+ },
+ "subnet": {
+ "description": "Subnet is the subnet the interface is attached to.",
+ "properties": {
+ "cidr": {
+ "description": "CIDR is the CIDR range associated with the subnet",
+ "format": "cidr",
+ "type": "string"
+ },
+ "id": {
+ "description": "ID is the resource ID of the subnet",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
}
},
"type": "object",
@@ -617,6 +624,14 @@
"description": "IP is the primary IP of the ENI",
"type": "string"
},
+ "ipv6-prefixes": {
+ "description": "IPv6Prefixes is the list of all IPv6 /80 delegated prefixes associated with the ENI",
+ "items": {
+ "format": "cidr",
+ "type": "string"
+ },
+ "type": "array"
+ },
"mac": {
"description": "MAC is the mac address of the ENI",
"type": "string"
@@ -626,8 +641,9 @@
"type": "integer"
},
"prefixes": {
- "description": "Prefixes is the list of all /28 prefixes associated with the ENI",
+ "description": "Prefixes is the list of all IPv4 /28 delegated prefixes associated with the ENI",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -648,6 +664,7 @@
"properties": {
"cidr": {
"description": "CIDR is the CIDR range associated with the subnet",
+ "format": "cidr",
"type": "string"
},
"id": {
@@ -671,6 +688,7 @@
"cidrs": {
"description": "CIDRs is the list of CIDR ranges associated with the VPC",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -681,6 +699,7 @@
},
"primary-cidr": {
"description": "PrimaryCIDR is the primary CIDR of the VPC",
+ "format": "cidr",
"type": "string"
}
},
diff --git a/crdSchemas/ciliumnodeconfig_v2.json b/crdSchemas/cilium.io/ciliumnodeconfig_v2.json
similarity index 100%
rename from crdSchemas/ciliumnodeconfig_v2.json
rename to crdSchemas/cilium.io/ciliumnodeconfig_v2.json
diff --git a/crdSchemas/ciliumnodeconfig_v2alpha1.json b/crdSchemas/cilium.io/ciliumnodeconfig_v2alpha1.json
similarity index 100%
rename from crdSchemas/ciliumnodeconfig_v2alpha1.json
rename to crdSchemas/cilium.io/ciliumnodeconfig_v2alpha1.json
diff --git a/crdSchemas/cilium.io/ciliumpodippool_v2.json b/crdSchemas/cilium.io/ciliumpodippool_v2.json
new file mode 100644
index 0000000..1d3e3b9
--- /dev/null
+++ b/crdSchemas/cilium.io/ciliumpodippool_v2.json
@@ -0,0 +1,330 @@
+{
+ "description": "CiliumPodIPPool defines an IP pool that can be used for pooled IPAM (i.e. the multi-pool IPAM\nmode).",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "properties": {
+ "allowFirstIP": {
+ "default": false,
+ "description": "AllowFirstIP allows the first IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowFirstIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "allowLastIP": {
+ "default": false,
+ "description": "AllowLastIP allows the last IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowLastIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "ipv4": {
+ "description": "IPv4 specifies the IPv4 CIDRs and mask sizes of the pool",
+ "properties": {
+ "cidrs": {
+ "description": "CIDRs is a list of IPv4 CIDRs that are part of the pool.",
+ "items": {
+ "description": "PoolCIDR is an IP pool CIDR.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "maskSize": {
+ "description": "MaskSize is the mask size of the pool.",
+ "maximum": 32,
+ "minimum": 1,
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "pool": {
+ "description": "Pool contains per-CIDR configuration for a subset of CIDRs listed in CIDRs.\nEach entry must reference a CIDR in CIDRs.",
+ "items": {
+ "properties": {
+ "cidr": {
+ "description": "CIDR references one of the CIDRs listed in the parent pool spec.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "reservedRanges": {
+ "description": "ReservedRanges is a list of IP ranges within CIDR that must not be allocated.",
+ "items": {
+ "properties": {
+ "end": {
+ "description": "The last IP in the reserved range.",
+ "type": "string"
+ },
+ "start": {
+ "description": "The first IP in the reserved range.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "cidr"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "cidr"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "cidrs",
+ "maskSize"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If pool is set, each pool entry must reference a CIDR from cidrs",
+ "rule": "!has(self.pool) || self.pool.all(p, p.cidr in self.cidrs)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "ipv6": {
+ "description": "IPv6 specifies the IPv6 CIDRs and mask sizes of the pool",
+ "properties": {
+ "cidrs": {
+ "description": "CIDRs is a list of IPv6 CIDRs that are part of the pool.",
+ "items": {
+ "description": "PoolCIDR is an IP pool CIDR.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "maskSize": {
+ "description": "MaskSize is the mask size of the pool.",
+ "maximum": 128,
+ "minimum": 1,
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "pool": {
+ "description": "Pool contains per-CIDR configuration for a subset of CIDRs listed in CIDRs.\nEach entry must reference a CIDR in CIDRs.",
+ "items": {
+ "properties": {
+ "cidr": {
+ "description": "CIDR references one of the CIDRs listed in the parent pool spec.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "reservedRanges": {
+ "description": "ReservedRanges is a list of IP ranges within CIDR that must not be allocated.",
+ "items": {
+ "properties": {
+ "end": {
+ "description": "The last IP in the reserved range.",
+ "type": "string"
+ },
+ "start": {
+ "description": "The first IP in the reserved range.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "cidr"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "cidr"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "cidrs",
+ "maskSize"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If pool is set, each pool entry must reference a CIDR from cidrs",
+ "rule": "!has(self.pool) || self.pool.all(p, p.cidr in self.cidrs)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "namespaceSelector": {
+ "description": "NamespaceSelector selects the set of Namespaces that are eligible to use\nthis pool. If both PodSelector and NamespaceSelector are specified, a Pod\nmust match both selectors to be eligible for IP allocation from this pool.\n\nIf NamespaceSelector is empty, the pool can be used by Pods in any namespace\n(subject to PodSelector constraints).",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "enum": [
+ "In",
+ "NotIn",
+ "Exists",
+ "DoesNotExist"
+ ],
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
+ "maxLength": 63,
+ "pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "podSelector": {
+ "description": "PodSelector selects the set of Pods that are eligible to receive IPs from\nthis pool when neither the Pod nor its Namespace specify an explicit\n`ipam.cilium.io/*` annotation.\n\nThe selector can match on regular Pod labels and on the following synthetic\nlabels that Cilium adds for convenience:\n\nio.kubernetes.pod.namespace \u2013 the Pod's namespace\nio.kubernetes.pod.name \u2013 the Pod's name\n\nA single Pod must not match more than one pool for the same IP family.\nIf multiple pools match, IP allocation fails for that Pod and a warning event\nis emitted in the namespace of the Pod.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "enum": [
+ "In",
+ "NotIn",
+ "Exists",
+ "DoesNotExist"
+ ],
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
+ "maxLength": 63,
+ "pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/ciliumpodippool_v2alpha1.json b/crdSchemas/cilium.io/ciliumpodippool_v2alpha1.json
similarity index 85%
rename from crdSchemas/ciliumpodippool_v2alpha1.json
rename to crdSchemas/cilium.io/ciliumpodippool_v2alpha1.json
index b5afe8c..ae09cb4 100644
--- a/crdSchemas/ciliumpodippool_v2alpha1.json
+++ b/crdSchemas/cilium.io/ciliumpodippool_v2alpha1.json
@@ -14,6 +14,28 @@
},
"spec": {
"properties": {
+ "allowFirstIP": {
+ "default": false,
+ "description": "AllowFirstIP allows the first IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowFirstIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "allowLastIP": {
+ "default": false,
+ "description": "AllowLastIP allows the last IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowLastIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
"ipv4": {
"description": "IPv4 specifies the IPv4 CIDRs and mask sizes of the pool",
"properties": {
@@ -31,7 +53,13 @@
"description": "MaskSize is the mask size of the pool.",
"maximum": 32,
"minimum": 1,
- "type": "integer"
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
}
},
"required": [
@@ -58,7 +86,13 @@
"description": "MaskSize is the mask size of the pool.",
"maximum": 128,
"minimum": 1,
- "type": "integer"
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
}
},
"required": [
diff --git a/crdSchemas/cloudeventsource_v1alpha1.json b/crdSchemas/eventing.keda.sh/cloudeventsource_v1alpha1.json
similarity index 100%
rename from crdSchemas/cloudeventsource_v1alpha1.json
rename to crdSchemas/eventing.keda.sh/cloudeventsource_v1alpha1.json
diff --git a/crdSchemas/clustercloudeventsource_v1alpha1.json b/crdSchemas/eventing.keda.sh/clustercloudeventsource_v1alpha1.json
similarity index 100%
rename from crdSchemas/clustercloudeventsource_v1alpha1.json
rename to crdSchemas/eventing.keda.sh/clustercloudeventsource_v1alpha1.json
diff --git a/crdSchemas/fluxinstance_v1.json b/crdSchemas/fluxcd.controlplane.io/fluxinstance_v1.json
similarity index 95%
rename from crdSchemas/fluxinstance_v1.json
rename to crdSchemas/fluxcd.controlplane.io/fluxinstance_v1.json
index 2d8a094..939e9e5 100644
--- a/crdSchemas/fluxinstance_v1.json
+++ b/crdSchemas/fluxcd.controlplane.io/fluxinstance_v1.json
@@ -247,7 +247,7 @@
"type": "array"
},
"storage": {
- "description": "Storage defines if the source-controller shards\nshould use an emptyDir or a persistent volume claim for storage.\nAccepted values are 'ephemeral' or 'persistent', defaults to 'ephemeral'.\nFor 'persistent' to take effect, the '.spec.storage' field must be set.",
+ "description": "Storage defines if the source-controller shards\nshould use an emptyDir or a persistent volume claim for storage.\nAccepted values are 'ephemeral' or 'persistent', defaults to 'ephemeral'.\nWhen set to 'persistent', the '.spec.storage' field must be set.",
"enum": [
"ephemeral",
"persistent"
@@ -314,7 +314,7 @@
"type": "string"
},
"provider": {
- "description": "Provider specifies OIDC provider for source authentication.\nFor OCIRepository and Bucket the provider can be set to 'aws', 'azure' or 'gcp'.\nfor GitRepository the accepted value can be set to 'azure' or 'github'.\nTo disable OIDC authentication the provider can be set to 'generic' or left empty.",
+ "description": "Provider specifies OIDC provider for source authentication.\nFor OCIRepository and Bucket the provider can be set to 'aws', 'azure' or 'gcp'.\nFor GitRepository the provider can be set to 'aws' (requires Flux 2.9 or later),\n'azure' or 'github'.\nTo disable OIDC authentication the provider can be set to 'generic' or left empty.",
"enum": [
"generic",
"aws",
@@ -344,6 +344,16 @@
"url"
],
"type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "sync.provider 'gcp' is only supported for OCIRepository and Bucket",
+ "rule": "!has(self.provider) || self.provider != 'gcp' || self.kind == 'OCIRepository' || self.kind == 'Bucket'"
+ },
+ {
+ "message": "sync.provider 'github' is only supported for GitRepository",
+ "rule": "!has(self.provider) || self.provider != 'github' || self.kind == 'GitRepository'"
+ }
+ ],
"additionalProperties": false
},
"wait": {
@@ -356,6 +366,12 @@
"distribution"
],
"type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": ".spec.storage must be set when .spec.sharding.storage is 'persistent'",
+ "rule": "!has(self.sharding) || !has(self.sharding.storage) || self.sharding.storage != 'persistent' || has(self.storage)"
+ }
+ ],
"additionalProperties": false
},
"status": {
diff --git a/crdSchemas/fluxreport_v1.json b/crdSchemas/fluxcd.controlplane.io/fluxreport_v1.json
similarity index 100%
rename from crdSchemas/fluxreport_v1.json
rename to crdSchemas/fluxcd.controlplane.io/fluxreport_v1.json
diff --git a/crdSchemas/resourceset_v1.json b/crdSchemas/fluxcd.controlplane.io/resourceset_v1.json
similarity index 86%
rename from crdSchemas/resourceset_v1.json
rename to crdSchemas/fluxcd.controlplane.io/resourceset_v1.json
index 2ec37dd..e815454 100644
--- a/crdSchemas/resourceset_v1.json
+++ b/crdSchemas/fluxcd.controlplane.io/resourceset_v1.json
@@ -204,6 +204,7 @@
"resources": {
"description": "Resources contains the list of Kubernetes resources to reconcile.",
"items": {
+ "type": "object",
"x-kubernetes-preserve-unknown-fields": true
},
"type": "array"
@@ -216,12 +217,73 @@
"description": "The name of the Kubernetes service account to impersonate\nwhen reconciling the generated resources.",
"type": "string"
},
+ "steps": {
+ "description": "Steps contains an ordered list of named steps to reconcile in sequence.\nEach step's resources are applied and health-checked before the next\nstep starts. Mutually exclusive with Resources and ResourcesTemplate.",
+ "items": {
+ "description": "ResourceSetStep defines a named step in the ResourceSet reconciliation\nsequence. The step's resources are applied and health-checked before\nthe next step starts.",
+ "properties": {
+ "name": {
+ "description": "Name of the step, must be unique within the ResourceSet.",
+ "maxLength": 63,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "resources": {
+ "description": "Resources contains the list of Kubernetes resources to reconcile.",
+ "items": {
+ "type": "object",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "type": "array"
+ },
+ "resourcesTemplate": {
+ "description": "ResourcesTemplate is a Go template that generates the list of\nKubernetes resources to reconcile. The template is rendered\nas multi-document YAML, the resources should be separated by '---'.\nWhen both Resources and ResourcesTemplate are set, the resulting\nobjects are merged and deduplicated, with the ones from Resources taking precedence.",
+ "type": "string"
+ },
+ "timeout": {
+ "description": "Timeout is the maximum time to wait for the step's resources to\nbecome ready. When not set, the ResourceSet reconciliation\ntimeout is used.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of resources or resourcesTemplate must be set",
+ "rule": "has(self.resources) || has(self.resourcesTemplate)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 20,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "step names must be unique",
+ "rule": "self.all(s, self.exists_one(t, t.name == s.name))"
+ }
+ ]
+ },
"wait": {
"description": "Wait instructs the controller to check the health\nof all the reconciled resources.",
"type": "boolean"
}
},
"type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "steps is mutually exclusive with resources and resourcesTemplate",
+ "rule": "!has(self.steps) || (!has(self.resources) && !has(self.resourcesTemplate))"
+ },
+ {
+ "message": "at least one of steps, resources or resourcesTemplate must be set",
+ "rule": "has(self.steps) || has(self.resources) || has(self.resourcesTemplate)"
+ }
+ ],
"additionalProperties": false
},
"status": {
diff --git a/crdSchemas/resourcesetinputprovider_v1.json b/crdSchemas/fluxcd.controlplane.io/resourcesetinputprovider_v1.json
similarity index 93%
rename from crdSchemas/resourcesetinputprovider_v1.json
rename to crdSchemas/fluxcd.controlplane.io/resourcesetinputprovider_v1.json
index bec2eeb..12702a5 100644
--- a/crdSchemas/resourcesetinputprovider_v1.json
+++ b/crdSchemas/fluxcd.controlplane.io/resourcesetinputprovider_v1.json
@@ -162,6 +162,9 @@
"AzureDevOpsBranch",
"AzureDevOpsTag",
"AzureDevOpsPullRequest",
+ "AWSCodeCommitBranch",
+ "AWSCodeCommitTag",
+ "AWSCodeCommitPullRequest",
"GiteaBranch",
"GiteaTag",
"GiteaPullRequest",
@@ -197,8 +200,12 @@
"rule": "!self.type.startsWith('Git') || self.url.startsWith('http')"
},
{
- "message": "spec.url must start with 'http://' or 'https://' when spec.type is a Git provider",
- "rule": "!self.type.startsWith('AzureDevOps') || self.url.startsWith('http')"
+ "message": "spec.url must start with 'http://' or 'https://' when spec.type is an AzureDevOps provider",
+ "rule": "!self.type.startsWith('AzureDevOps') || self.url.startsWith('http://') || self.url.startsWith('https://')"
+ },
+ {
+ "message": "spec.url must start with 'https://' when spec.type is a AWSCodeCommit provider",
+ "rule": "!self.type.startsWith('AWSCodeCommit') || self.url.startsWith('https://')"
},
{
"message": "spec.url must start with 'oci://' when spec.type is an OCI provider",
@@ -217,16 +224,16 @@
"rule": "self.type != 'ExternalService' || !self.url.startsWith('http://') || (has(self.insecure) && self.insecure)"
},
{
- "message": "cannot specify spec.serviceAccountName when spec.type is not one of AzureDevOps* or *ArtifactTag",
- "rule": "!has(self.serviceAccountName) || self.type.startsWith('AzureDevOps') || self.type.endsWith('ArtifactTag')"
+ "message": "cannot specify spec.serviceAccountName when spec.type is not one of AzureDevOps*, AWSCodeCommit* or *ArtifactTag",
+ "rule": "!has(self.serviceAccountName) || self.type.startsWith('AzureDevOps') || self.type.startsWith('AWSCodeCommit') || self.type.endsWith('ArtifactTag')"
},
{
- "message": "cannot specify spec.certSecretRef when spec.type is one of Static, AzureDevOps*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
- "rule": "!has(self.certSecretRef) || !(self.url == 'Static' || self.type.startsWith('AzureDevOps') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
+ "message": "cannot specify spec.certSecretRef when spec.type is one of Static, AzureDevOps*, AWSCodeCommit*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
+ "rule": "!has(self.certSecretRef) || !(self.type == 'Static' || self.type.startsWith('AzureDevOps') || self.type.startsWith('AWSCodeCommit') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
},
{
- "message": "cannot specify spec.secretRef when spec.type is one of Static, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
- "rule": "!has(self.secretRef) || !(self.url == 'Static' || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
+ "message": "cannot specify spec.secretRef when spec.type is one of Static, AWSCodeCommit*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
+ "rule": "!has(self.secretRef) || !(self.type == 'Static' || self.type.startsWith('AWSCodeCommit') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
}
],
"additionalProperties": false
diff --git a/crdSchemas/gateway.envoyproxy.io/backend_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/backend_v1alpha1.json
new file mode 100644
index 0000000..66e4d17
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/backend_v1alpha1.json
@@ -0,0 +1,418 @@
+{
+ "description": "Backend allows the user to configure the endpoints of a backend and\nthe behavior of the connection from Envoy Proxy to the backend.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of Backend.",
+ "properties": {
+ "appProtocols": {
+ "description": "AppProtocols defines the application protocols to be supported when connecting to the backend.",
+ "items": {
+ "description": "AppProtocolType defines various backend applications protocols supported by Envoy Gateway",
+ "enum": [
+ "gateway.envoyproxy.io/h2c",
+ "gateway.envoyproxy.io/ws",
+ "gateway.envoyproxy.io/wss"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "endpoints": {
+ "description": "Endpoints defines the endpoints to be used when connecting to the backend.",
+ "items": {
+ "description": "BackendEndpoint describes a backend endpoint, which can be either a fully-qualified domain name, IP address or unix domain socket\ncorresponding to Envoy's Address: https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/core/v3/address.proto#config-core-v3-address",
+ "properties": {
+ "fqdn": {
+ "description": "FQDN defines a FQDN endpoint",
+ "properties": {
+ "hostname": {
+ "description": "Hostname defines the FQDN hostname of the backend endpoint.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port defines the port of the backend endpoint.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "hostname",
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostname": {
+ "description": "Hostname defines an optional hostname for the backend endpoint.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "ip": {
+ "description": "IP defines an IP endpoint. Supports both IPv4 and IPv6 addresses.",
+ "properties": {
+ "address": {
+ "description": "Address defines the IP address of the backend endpoint.\nSupports both IPv4 and IPv6 addresses.",
+ "maxLength": 45,
+ "minLength": 3,
+ "pattern": "^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$|^(([0-9a-fA-F]{1,4}:){1,7}[0-9a-fA-F]{1,4}|::|(([0-9a-fA-F]{1,4}:){0,5})?(:[0-9a-fA-F]{1,4}){1,2})$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port defines the port of the backend endpoint.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "address",
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "unix": {
+ "description": "Unix defines the unix domain socket endpoint",
+ "properties": {
+ "path": {
+ "description": "Path defines the unix domain socket path of the backend endpoint.\nThe path length must not exceed 108 characters.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "unix domain socket path must not exceed 108 characters",
+ "rule": "size(self) <= 108"
+ }
+ ]
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "zone": {
+ "description": "Zone defines the service zone of the backend endpoint.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "one of fqdn, ip or unix must be specified",
+ "rule": "(has(self.fqdn) || has(self.ip) || has(self.unix))"
+ },
+ {
+ "message": "only one of fqdn, ip or unix can be specified",
+ "rule": "((has(self.fqdn) && !(has(self.ip) || has(self.unix))) || (has(self.ip) && !(has(self.fqdn) || has(self.unix))) || (has(self.unix) && !(has(self.ip) || has(self.fqdn))))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 256,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "fqdn addresses cannot be mixed with other address types",
+ "rule": "self.all(f, has(f.fqdn)) || !self.exists(f, has(f.fqdn))"
+ }
+ ]
+ },
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "tls": {
+ "description": "TLS defines the TLS settings for the backend.\nIf TLS is specified here and a BackendTLSPolicy is also configured for the backend, the final TLS settings will\nbe a merge of both configurations. In case of overlapping fields, the values defined in the BackendTLSPolicy will\ntake precedence.",
+ "properties": {
+ "alpnProtocols": {
+ "description": "ALPNProtocols supplies the list of ALPN protocols that should be\nexposed by the listener or used by the proxy to connect to the backend.\nDefaults:\n1. HTTPS Routes: h2 and http/1.1 are enabled in listener context.\n2. Other Routes: ALPN is disabled.\n3. Backends: proxy uses the appropriate ALPN options for the backend protocol.\nWhen an empty list is provided, the ALPN TLS extension is disabled.\n\nDefaults to [h2, http/1.1] if not specified.\n\nTypical Supported values are:\n- http/1.0\n- http/1.1\n- h2",
+ "items": {
+ "description": "ALPNProtocol specifies the protocol to be negotiated using ALPN",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes objects that\ncontain TLS certificates of the Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the backend.\n\nA single reference to a Kubernetes ConfigMap or a Kubernetes Secret,\nwith the CA certificate in a key named `ca.crt` is currently supported.\n\nIf CACertificateRefs is empty or unspecified, then WellKnownCACertificates must be\nspecified. Only one of CACertificateRefs or WellKnownCACertificates may be specified,\nnot both.",
+ "items": {
+ "description": "LocalObjectReference identifies an API object within the namespace of the\nreferrer.\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "ciphers": {
+ "description": "Ciphers specifies the set of cipher suites supported when\nnegotiating TLS 1.0 - 1.2. This setting has no effect for TLS 1.3.\nFor Envoy TLS cipher suite configuration semantics and default cipher\nlists, see the Envoy documentation:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/transport_sockets/tls/v3/common.proto#extensions-transport-sockets-tls-v3-tlsparameters\nSupported cipher suite names:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\n- ECDHE-ECDSA-CHACHA20-POLY1305\n- ECDHE-RSA-CHACHA20-POLY1305\n- ECDHE-ECDSA-AES128-SHA\n- ECDHE-RSA-AES128-SHA\n- AES128-GCM-SHA256\n- AES128-SHA\n- ECDHE-ECDSA-AES256-SHA\n- ECDHE-RSA-AES256-SHA\n- AES256-GCM-SHA384\n- AES256-SHA\nSupported IANA/RFC aliases:\n- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\n- TLS_RSA_WITH_AES_128_GCM_SHA256\n- TLS_RSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\n- TLS_RSA_WITH_AES_256_GCM_SHA384\n- TLS_RSA_WITH_AES_256_CBC_SHA\nIn non-FIPS Envoy Proxy builds the default cipher list is:\n- [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]\n- [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\nIn builds using BoringSSL FIPS the default cipher list is:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef defines the reference to a Kubernetes Secret that contains\nthe client certificate and private key for Envoy to use when connecting to\nbackend services and external services, such as ExtAuth, ALS, OpenTelemetry, etc.\nThis secret should be located within the same namespace as the Envoy proxy resource that references it.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ecdhCurves": {
+ "description": "ECDHCurves specifies the set of supported ECDH curves.\nIn non-FIPS Envoy Proxy builds the default curves are:\n- X25519\n- P-256\nIn builds using BoringSSL FIPS the default curve is:\n- P-256",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "fingerprints": {
+ "description": "Fingerprints specifies TLS client fingerprinting.\nWhen specified, a JAX fingerprint derived from the client\u2019s TLS handshake\nis generated. The fingerprint can be logged in access logs or\nforwarded to upstream services using request headers.\n\nFingerprinting is disabled if not specified.\n\nSupported values are:\n- JA3\n- JA4",
+ "items": {
+ "description": "TLSFingerprintType specifies the TLS client fingerprinting mode.",
+ "enum": [
+ "JA3",
+ "JA4"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "insecureSkipVerify": {
+ "default": false,
+ "description": "InsecureSkipVerify indicates whether the upstream's certificate verification\nshould be skipped. Defaults to \"false\".",
+ "type": "boolean"
+ },
+ "maxVersion": {
+ "description": "Max specifies the maximal TLS protocol version to allow\nThe default is TLS 1.3 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "minVersion": {
+ "description": "Min specifies the minimal TLS protocol version to allow.\nThe default is TLS 1.2 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "signatureAlgorithms": {
+ "description": "SignatureAlgorithms specifies which signature algorithms the listener should\nsupport.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "sni": {
+ "description": "SNI is specifies the SNI value used when establishing an upstream TLS connection to the backend.\n\nEnvoy Gateway will use the HTTP host header value for SNI, when all resources referenced in BackendRefs are:\n1. Backend resources that do not set SNI, or\n2. Service/ServiceImport resources that do not have a BackendTLSPolicy attached to them\n\nWhen a BackendTLSPolicy attaches to a Backend resource, the BackendTLSPolicy's Hostname value takes precedence\nover this value.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "wellKnownCACertificates": {
+ "description": "WellKnownCACertificates specifies whether system CA certificates may be used in\nthe TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(System|([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]))$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "must not contain both CACertificateRefs and WellKnownCACertificates",
+ "rule": "!(has(self.caCertificateRefs) && size(self.caCertificateRefs) > 0 && has(self.wellKnownCACertificates) && self.wellKnownCACertificates != \"\")"
+ },
+ {
+ "message": "must not contain either CACertificateRefs or WellKnownCACertificates when InsecureSkipVerify is enabled",
+ "rule": "!((has(self.insecureSkipVerify) && self.insecureSkipVerify) && ((has(self.caCertificateRefs) && size(self.caCertificateRefs) > 0) || (has(self.wellKnownCACertificates) && self.wellKnownCACertificates != \"\")))"
+ },
+ {
+ "message": "setting ciphers has no effect if the minimum possible TLS version is 1.3",
+ "rule": "has(self.minVersion) && self.minVersion == '1.3' ? !has(self.ciphers) : true"
+ },
+ {
+ "message": "minVersion must be smaller or equal to maxVersion",
+ "rule": "has(self.minVersion) && has(self.maxVersion) ? {\"Auto\":0,\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4}[self.minVersion] <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : !has(self.minVersion) && has(self.maxVersion) ? 3 <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Endpoints",
+ "description": "Type defines the type of the backend. Defaults to \"Endpoints\"",
+ "enum": [
+ "Endpoints",
+ "DynamicResolver"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "DynamicResolver type cannot have endpoints specified",
+ "rule": "self.type != 'DynamicResolver' || !has(self.endpoints)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of Backend.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describe the current conditions of the Backend.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/backendtrafficpolicy_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/backendtrafficpolicy_v1alpha1.json
new file mode 100644
index 0000000..325d9e1
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/backendtrafficpolicy_v1alpha1.json
@@ -0,0 +1,3416 @@
+{
+ "description": "BackendTrafficPolicy allows the user to configure the behavior of the connection\nbetween the Envoy Proxy listener and the backend service.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "spec defines the desired state of BackendTrafficPolicy.",
+ "properties": {
+ "admissionControl": {
+ "description": "AdmissionControl defines the admission control policy to be applied. This configuration\nprobabilistically rejects requests based on the success rate of previous requests in a\nconfigurable sliding time window.",
+ "properties": {
+ "maxRejectionPercent": {
+ "description": "MaxRejectionPercent represents the upper limit of the rejection probability,\nexpressed as a percentage in the range [0, 100]. Defaults to 80 if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "minRequestRate": {
+ "description": "MinRequestRate defines the minimum requests per second below which requests will\npass through the filter without rejection. Defaults to 0 if not specified.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "minSuccessRate": {
+ "description": "MinSuccessRate is the lowest request success rate, as a percentage in the\nrange [1, 100], at which the filter will not reject requests. Defaults to 95 if\nnot specified. Envoy rejects values below 1%, so values lower than 1 are not allowed.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "rejectionAggression": {
+ "description": "RejectionAggression controls how steeply the rejection probability rises\nas the observed success rate falls below MinSuccessRate. A value of 1\nproduces a linear curve; higher values reject more aggressively for a\ngiven drop in success rate. Must be greater than 0; values below 1 are\nclamped to 1. Defaults to 1.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "samplingWindow": {
+ "description": "SamplingWindow defines the time window over which request success rates are calculated.\nMust be at least 1s; Envoy truncates the window to whole seconds and uses it as the\ndenominator in RPS calculations, so sub-second values would produce a zero denominator.\nDefaults to 30s if not specified.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "successCriteria": {
+ "description": "SuccessCriteria defines what constitutes a successful request for both HTTP and gRPC.",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines success criteria for gRPC requests.",
+ "properties": {
+ "statusCodes": {
+ "description": "StatusCodes defines gRPC status codes that are considered successful.\nStatus codes are defined in https://github.com/grpc/grpc/blob/master/doc/statuscodes.md#status-codes-and-their-use-in-grpc.",
+ "items": {
+ "description": "GRPCSuccessCode defines gRPC status codes as defined in\nhttps://github.com/grpc/grpc/blob/master/doc/statuscodes.md#status-codes-and-their-use-in-grpc.",
+ "enum": [
+ "Ok",
+ "Cancelled",
+ "Unknown",
+ "InvalidArgument",
+ "DeadlineExceeded",
+ "NotFound",
+ "AlreadyExists",
+ "PermissionDenied",
+ "ResourceExhausted",
+ "FailedPrecondition",
+ "Aborted",
+ "OutOfRange",
+ "Unimplemented",
+ "Internal",
+ "Unavailable",
+ "DataLoss",
+ "Unauthenticated"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTP defines success criteria for HTTP requests.",
+ "properties": {
+ "statusCodes": {
+ "description": "StatusCodes defines HTTP status codes that are considered successful.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "minSuccessRate must be between 1 and 100",
+ "rule": "!has(self.minSuccessRate) || (self.minSuccessRate >= 1 && self.minSuccessRate <= 100)"
+ },
+ {
+ "message": "maxRejectionPercent must be between 0 and 100",
+ "rule": "!has(self.maxRejectionPercent) || (self.maxRejectionPercent >= 0 && self.maxRejectionPercent <= 100)"
+ },
+ {
+ "message": "samplingWindow must be at least 1s",
+ "rule": "!has(self.samplingWindow) || duration(self.samplingWindow) >= duration('1s')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "bandwidthLimit": {
+ "description": "BandwidthLimit allows the user to limit the bandwidth of traffic\nsent to and received from the backend.",
+ "properties": {
+ "request": {
+ "description": "Request configures bandwidth limits for traffic sent to the backend.",
+ "properties": {
+ "limit": {
+ "description": "Limit specifies the bandwidth limit as a bytes-per-unit throughput rate.",
+ "properties": {
+ "unit": {
+ "description": "Unit specifies the time unit for the bandwidth limit (e.g. Second, Minute, Hour).",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Value specifies the bandwidth limit.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "unit",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response configures bandwidth limits for traffic sent from the backend.",
+ "properties": {
+ "limit": {
+ "description": "Limit specifies the bandwidth limit as a bytes-per-unit throughput rate.",
+ "properties": {
+ "unit": {
+ "description": "Unit specifies the time unit for the bandwidth limit (e.g. Second, Minute, Hour).",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Value specifies the bandwidth limit.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "unit",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "responseTrailers": {
+ "description": "ResponseTrailers configures the trailer headers appended to responses\nwhen bandwidth limiting introduces delays.",
+ "properties": {
+ "prefix": {
+ "description": "Prefix is prepended to each trailer header name.\nIf not set, no prefix is added and the trailers are named as-is.\nFor example, setting \"x-eg\" produces trailers such as \"x-eg-bandwidth-request-delay-ms\",\nwhile leaving it unset produces \"bandwidth-request-delay-ms\".\n\nThe following four trailers can be added:\n\"bandwidth-request-delay-ms\" is delay time in milliseconds it took for the request stream transfer\nincluding request body transfer time and the time added by the filter.\n\"bandwidth-response-delay-ms\" is delay time in milliseconds it took for the response stream transfer\nincluding response body transfer time and the time added by the filter.\n\"bandwidth-request-filter-delay-ms\" is delay time in milliseconds in request stream transfer added by the filter.\n\"bandwidth-response-filter-delay-ms\" is delay time in milliseconds that added by the filter.",
+ "pattern": "^[^\\r\\n\\x00]*$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of request or response must be specified",
+ "rule": "has(self.request) || has(self.response)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "compression": {
+ "description": "The compression config for the http streams.\n\nDeprecated: Use Compressor instead.",
+ "items": {
+ "description": "Compression defines the config of enabling compression.\nThis can help reduce the bandwidth at the expense of higher CPU.",
+ "properties": {
+ "brotli": {
+ "description": "The configuration for Brotli compressor.",
+ "type": "object"
+ },
+ "gzip": {
+ "description": "The configuration for GZIP compressor.",
+ "type": "object"
+ },
+ "minContentLength": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinContentLength defines the minimum response size in bytes to apply compression.\nResponses smaller than this threshold will not be compressed.\nMust be at least 30 bytes as enforced by Envoy Proxy.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 30 bytes",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "CompressorType defines the compressor type to use for compression.",
+ "enum": [
+ "Gzip",
+ "Brotli",
+ "Zstd"
+ ],
+ "type": "string"
+ },
+ "zstd": {
+ "description": "The configuration for Zstd compressor.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "compressor": {
+ "description": "The compressor config for the http streams.\nThis provides more granular control over compression configuration.\nOrder matters: The first compressor in the list is preferred when q-values in Accept-Encoding are equal.",
+ "items": {
+ "description": "Compression defines the config of enabling compression.\nThis can help reduce the bandwidth at the expense of higher CPU.",
+ "properties": {
+ "brotli": {
+ "description": "The configuration for Brotli compressor.",
+ "type": "object"
+ },
+ "gzip": {
+ "description": "The configuration for GZIP compressor.",
+ "type": "object"
+ },
+ "minContentLength": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinContentLength defines the minimum response size in bytes to apply compression.\nResponses smaller than this threshold will not be compressed.\nMust be at least 30 bytes as enforced by Envoy Proxy.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 30 bytes",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "CompressorType defines the compressor type to use for compression.",
+ "enum": [
+ "Gzip",
+ "Brotli",
+ "Zstd"
+ ],
+ "type": "string"
+ },
+ "zstd": {
+ "description": "The configuration for Zstd compressor.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "faultInjection": {
+ "description": "FaultInjection defines the fault injection policy to be applied. This configuration can be used to\ninject delays and abort requests to mimic failure scenarios such as service failures and overloads",
+ "properties": {
+ "abort": {
+ "description": "If specified, the request will be aborted if it meets the configuration criteria.",
+ "properties": {
+ "grpcStatus": {
+ "description": "GrpcStatus specifies the GRPC status code to be returned",
+ "format": "int32",
+ "maximum": 16,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "httpStatus": {
+ "description": "StatusCode specifies the HTTP status code to be returned",
+ "format": "int32",
+ "maximum": 600,
+ "minimum": 200,
+ "type": "integer"
+ },
+ "percentage": {
+ "default": 100,
+ "description": "Percentage specifies the percentage of requests to be aborted. Default 100%, if set 0, no requests will be aborted. Accuracy to 0.0001%.",
+ "type": "number"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "httpStatus and grpcStatus cannot be simultaneously defined.",
+ "rule": " !(has(self.httpStatus) && has(self.grpcStatus)) "
+ },
+ {
+ "message": "httpStatus and grpcStatus are set at least one.",
+ "rule": " has(self.httpStatus) || has(self.grpcStatus) "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "delay": {
+ "description": "If specified, a delay will be injected into the request.",
+ "properties": {
+ "fixedDelay": {
+ "description": "FixedDelay specifies the fixed delay duration",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "percentage": {
+ "default": 100,
+ "description": "Percentage specifies the percentage of requests to be delayed. Default 100%, if set 0, no requests will be delayed. Accuracy to 0.0001%.",
+ "type": "number"
+ }
+ },
+ "required": [
+ "fixedDelay"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Delay and abort faults are set at least one.",
+ "rule": " has(self.delay) || has(self.abort) "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpUpgrade": {
+ "description": "HTTPUpgrade defines the configuration for HTTP protocol upgrades.\nIf not specified, the default upgrade configuration (websocket) will be used.\nHowever, if requestBuffer is configured, the default upgrade configuration\nwill be ignored.",
+ "items": {
+ "description": "ProtocolUpgradeConfig specifies the configuration for protocol upgrades.",
+ "properties": {
+ "connect": {
+ "description": "Connect specifies the configuration for the CONNECT config.\nThis is allowed only when type is CONNECT.",
+ "properties": {
+ "terminate": {
+ "description": "Terminate the CONNECT request, and forwards the payload as raw TCP data.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type is the case-insensitive type of protocol upgrade.\ne.g. `websocket`, `CONNECT`, `spdy/3.1` etc.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "The connect configuration is only allowed when the type is CONNECT.",
+ "rule": "!has(self.connect) || self.type == 'CONNECT'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "mergeType": {
+ "description": "MergeType determines how this configuration is merged with existing BackendTrafficPolicy\nconfigurations targeting a parent resource. When set, this configuration will be merged\ninto a parent BackendTrafficPolicy (i.e. the one targeting a Gateway or Listener).\nThis field cannot be set when targeting a parent resource (Gateway).\nIf unset, no merging occurs, and only the most specific configuration takes effect.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Replace is not a valid MergeType for BackendTrafficPolicySpec",
+ "rule": "self != 'Replace'"
+ }
+ ]
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "rateLimit": {
+ "description": "RateLimit allows the user to limit the number of incoming requests\nto a predefined value based on attributes within the traffic flow.",
+ "properties": {
+ "global": {
+ "description": "Global defines global rate limit configuration.",
+ "properties": {
+ "rules": {
+ "description": "Rules are a list of RateLimit selectors and limits. Each rule and its\nassociated limit is applied in a mutually exclusive way. If a request\nmatches multiple rules, each of their associated limits get applied, so a\nsingle request might increase the rate limit counters for multiple rules\nif selected. The rate limit service will return a logical OR of the individual\nrate limit decisions of all matching rules. For example, if a request\nmatches two rules, one rate limited and one not, the final decision will be\nto rate limit the request.",
+ "items": {
+ "description": "RateLimitRule defines the semantics for matching attributes\nfrom the incoming requests, and setting limits for them.",
+ "properties": {
+ "clientSelectors": {
+ "description": "ClientSelectors holds the list of select conditions to select\nspecific clients using attributes from the traffic flow.\nAll individual select conditions must hold True for this rule\nand its limit to be applied.\n\nIf no client selectors are specified, the rule applies to all traffic of\nthe targeted Route.\n\nIf the policy targets a Gateway, the rule applies to each Route of the Gateway.\nPlease note that each Route has its own rate limit counters. For example,\nif a Gateway has two Routes, and the policy has a rule with limit 10rps,\neach Route will have its own 10rps limit.",
+ "items": {
+ "description": "RateLimitSelectCondition specifies the attributes within the traffic flow that can\nbe used to select a subset of clients to be ratelimited.\nAll the individual conditions must hold True for the overall condition to hold True.\nAnd, at least one of headers or methods or path or sourceCIDR or queryParams condition must be specified.",
+ "properties": {
+ "headers": {
+ "description": "Headers is a list of request headers to match. Multiple header values are ANDed together,\nmeaning, a request MUST match all the specified headers.",
+ "items": {
+ "description": "HeaderMatch defines the match attributes within the HTTP Headers of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the HTTP header.\nThe header name is case-insensitive unless PreserveHeaderCase is set to true.\nFor example, \"Foo\" and \"foo\" are considered the same header.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the header.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value within the HTTP header.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "methods": {
+ "description": "Methods is a list of request methods to match. Multiple method values are ORed together,\nmeaning, a request can match any one of the specified methods. If not specified, it matches all methods.",
+ "items": {
+ "description": "MethodMatch defines the matching criteria for the HTTP method of a request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "value": {
+ "description": "Value specifies the HTTP method.",
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "path": {
+ "description": "Path is the request path to match.\nSupport Exact, PathPrefix and RegularExpression match types.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "PathPrefix",
+ "description": "Type specifies how to match against the value of the path.",
+ "enum": [
+ "Exact",
+ "PathPrefix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "default": "/",
+ "description": "Value specifies the HTTP path.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryParams": {
+ "description": "QueryParams is a list of query parameters to match. Multiple query parameter values are ANDed together,\nmeaning, a request MUST match all the specified query parameters.",
+ "items": {
+ "description": "QueryParamMatch defines the match attributes within the query parameters of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the query parameter.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the query parameter.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the query parameter.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "sourceCIDR": {
+ "description": "SourceCIDR is the client IP Address range to match on.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the source range match result will be inverted.\nWhen true, the rule matches when the client IP is not in the specified range(s).",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "Exact",
+ "enum": [
+ "Exact",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the IP CIDR that represents the range of Source IP Addresses of the client.\nThese could also be the intermediate addresses through which the request has flown through and is part of the `X-Forwarded-For` header.\nFor example, `192.168.0.1/32`, `192.168.0.0/24`, `001:db8::/64`.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of headers, methods, path, sourceCIDR or queryParams must be specified",
+ "rule": "has(self.headers) || has(self.methods) || has(self.path) || has(self.sourceCIDR) || has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "cost": {
+ "description": "Cost specifies the cost of requests and responses for the rule.\n\nThis is optional and if not specified, the default behavior is to reduce the rate limit counters by 1 on\nthe request path and do not reduce the rate limit counters on the response path.",
+ "properties": {
+ "request": {
+ "description": "Request specifies the number to reduce the rate limit counters\non the request path. If this is not specified, the default behavior\nis to reduce the rate limit counters by 1.\n\nWhen Envoy receives a request that matches the rule, it tries to reduce the\nrate limit counters by the specified number. If the counter doesn't have\nenough capacity, the request is rate limited.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response specifies the number to reduce the rate limit counters\nafter the response is sent back to the client or the request stream is closed.\n\nThe cost is used to reduce the rate limit counters for the matching requests.\nSince the reduction happens after the request stream is complete, the rate limit\nwon't be enforced for the current request, but for the subsequent matching requests.\n\nThis is optional and if not specified, the rate limit counters are not reduced\non the response path.\n\nCurrently, this is only supported for HTTP Global Rate Limits.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "limit": {
+ "description": "Limit holds the rate limit values.\nThis limit is applied for traffic flows when the selectors\ncompute to True, causing the request to be counted towards the limit.\nThe limit is enforced and the request is ratelimited, i.e. a response with\n429 HTTP status code is sent back to the client when\nthe selected requests have reached the limit.",
+ "properties": {
+ "requests": {
+ "description": "Requests is the number of requests (or cost units, when used with\ncost-based rate limiting) allowed per Unit.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "unit": {
+ "description": "RateLimitUnit specifies the intervals for setting rate limits.\nValid RateLimitUnit values are \"Second\", \"Minute\", \"Hour\", \"Day\", \"Month\" and \"Year\".",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour",
+ "Day",
+ "Month",
+ "Year"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "requests",
+ "unit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "shadowMode": {
+ "description": "ShadowMode indicates whether this rate-limit rule runs in shadow mode.\nWhen enabled, all rate-limiting operations are performed (cache lookups,\ncounter updates, telemetry generation), but the outcome is never enforced.\nThe request always succeeds, even if the configured limit is exceeded.\n\nOnly supported for Global Rate Limits.",
+ "type": "boolean"
+ },
+ "shared": {
+ "description": "Shared determines whether this rate limit rule applies across all the policy targets.\nIf set to true, the rule is treated as a common bucket and is shared across all policy targets (xRoutes).\nDefault: false.",
+ "type": "boolean"
+ },
+ "xRateLimitHeaders": {
+ "description": "XRateLimitHeaders controls whether X-RateLimit response headers are emitted for this rate limit rule.\nWhen set, this overrides the global DisableRateLimitHeaders setting in ClientTrafficPolicy for this rule.\nIf not set, the rule inherits the listener-level setting (default behavior).",
+ "enum": [
+ "Off",
+ "DraftVersion03"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 256,
+ "type": "array"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "local": {
+ "description": "Local defines local rate limit configuration.",
+ "properties": {
+ "rules": {
+ "description": "Rules are a list of RateLimit selectors and limits. If a request matches\nmultiple rules, the strictest limit is applied. For example, if a request\nmatches two rules, one with 10rps and one with 20rps, the final limit will\nbe based on the rule with 10rps.",
+ "items": {
+ "description": "RateLimitRule defines the semantics for matching attributes\nfrom the incoming requests, and setting limits for them.",
+ "properties": {
+ "clientSelectors": {
+ "description": "ClientSelectors holds the list of select conditions to select\nspecific clients using attributes from the traffic flow.\nAll individual select conditions must hold True for this rule\nand its limit to be applied.\n\nIf no client selectors are specified, the rule applies to all traffic of\nthe targeted Route.\n\nIf the policy targets a Gateway, the rule applies to each Route of the Gateway.\nPlease note that each Route has its own rate limit counters. For example,\nif a Gateway has two Routes, and the policy has a rule with limit 10rps,\neach Route will have its own 10rps limit.",
+ "items": {
+ "description": "RateLimitSelectCondition specifies the attributes within the traffic flow that can\nbe used to select a subset of clients to be ratelimited.\nAll the individual conditions must hold True for the overall condition to hold True.\nAnd, at least one of headers or methods or path or sourceCIDR or queryParams condition must be specified.",
+ "properties": {
+ "headers": {
+ "description": "Headers is a list of request headers to match. Multiple header values are ANDed together,\nmeaning, a request MUST match all the specified headers.",
+ "items": {
+ "description": "HeaderMatch defines the match attributes within the HTTP Headers of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the HTTP header.\nThe header name is case-insensitive unless PreserveHeaderCase is set to true.\nFor example, \"Foo\" and \"foo\" are considered the same header.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the header.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value within the HTTP header.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "methods": {
+ "description": "Methods is a list of request methods to match. Multiple method values are ORed together,\nmeaning, a request can match any one of the specified methods. If not specified, it matches all methods.",
+ "items": {
+ "description": "MethodMatch defines the matching criteria for the HTTP method of a request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "value": {
+ "description": "Value specifies the HTTP method.",
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "path": {
+ "description": "Path is the request path to match.\nSupport Exact, PathPrefix and RegularExpression match types.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "PathPrefix",
+ "description": "Type specifies how to match against the value of the path.",
+ "enum": [
+ "Exact",
+ "PathPrefix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "default": "/",
+ "description": "Value specifies the HTTP path.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryParams": {
+ "description": "QueryParams is a list of query parameters to match. Multiple query parameter values are ANDed together,\nmeaning, a request MUST match all the specified query parameters.",
+ "items": {
+ "description": "QueryParamMatch defines the match attributes within the query parameters of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the query parameter.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the query parameter.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the query parameter.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "sourceCIDR": {
+ "description": "SourceCIDR is the client IP Address range to match on.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the source range match result will be inverted.\nWhen true, the rule matches when the client IP is not in the specified range(s).",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "Exact",
+ "enum": [
+ "Exact",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the IP CIDR that represents the range of Source IP Addresses of the client.\nThese could also be the intermediate addresses through which the request has flown through and is part of the `X-Forwarded-For` header.\nFor example, `192.168.0.1/32`, `192.168.0.0/24`, `001:db8::/64`.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of headers, methods, path, sourceCIDR or queryParams must be specified",
+ "rule": "has(self.headers) || has(self.methods) || has(self.path) || has(self.sourceCIDR) || has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "cost": {
+ "description": "Cost specifies the cost of requests and responses for the rule.\n\nThis is optional and if not specified, the default behavior is to reduce the rate limit counters by 1 on\nthe request path and do not reduce the rate limit counters on the response path.",
+ "properties": {
+ "request": {
+ "description": "Request specifies the number to reduce the rate limit counters\non the request path. If this is not specified, the default behavior\nis to reduce the rate limit counters by 1.\n\nWhen Envoy receives a request that matches the rule, it tries to reduce the\nrate limit counters by the specified number. If the counter doesn't have\nenough capacity, the request is rate limited.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response specifies the number to reduce the rate limit counters\nafter the response is sent back to the client or the request stream is closed.\n\nThe cost is used to reduce the rate limit counters for the matching requests.\nSince the reduction happens after the request stream is complete, the rate limit\nwon't be enforced for the current request, but for the subsequent matching requests.\n\nThis is optional and if not specified, the rate limit counters are not reduced\non the response path.\n\nCurrently, this is only supported for HTTP Global Rate Limits.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "limit": {
+ "description": "Limit holds the rate limit values.\nThis limit is applied for traffic flows when the selectors\ncompute to True, causing the request to be counted towards the limit.\nThe limit is enforced and the request is ratelimited, i.e. a response with\n429 HTTP status code is sent back to the client when\nthe selected requests have reached the limit.",
+ "properties": {
+ "requests": {
+ "description": "Requests is the number of requests (or cost units, when used with\ncost-based rate limiting) allowed per Unit.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "unit": {
+ "description": "RateLimitUnit specifies the intervals for setting rate limits.\nValid RateLimitUnit values are \"Second\", \"Minute\", \"Hour\", \"Day\", \"Month\" and \"Year\".",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour",
+ "Day",
+ "Month",
+ "Year"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "requests",
+ "unit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "shadowMode": {
+ "description": "ShadowMode indicates whether this rate-limit rule runs in shadow mode.\nWhen enabled, all rate-limiting operations are performed (cache lookups,\ncounter updates, telemetry generation), but the outcome is never enforced.\nThe request always succeeds, even if the configured limit is exceeded.\n\nOnly supported for Global Rate Limits.",
+ "type": "boolean"
+ },
+ "shared": {
+ "description": "Shared determines whether this rate limit rule applies across all the policy targets.\nIf set to true, the rule is treated as a common bucket and is shared across all policy targets (xRoutes).\nDefault: false.",
+ "type": "boolean"
+ },
+ "xRateLimitHeaders": {
+ "description": "XRateLimitHeaders controls whether X-RateLimit response headers are emitted for this rate limit rule.\nWhen set, this overrides the global DisableRateLimitHeaders setting in ClientTrafficPolicy for this rule.\nIf not set, the rule inherits the listener-level setting (default behavior).",
+ "enum": [
+ "Off",
+ "DraftVersion03"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "response cost is not supported for Local Rate Limits",
+ "rule": "self.all(r, !has(r.cost) || !has(r.cost.response))"
+ }
+ ]
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the scope for the RateLimits.\nValid RateLimitType values are \"Global\" or \"Local\".\n\nDeprecated: Use Global and/or Local fields directly instead. Both can be specified simultaneously for combined rate limiting.",
+ "enum": [
+ "Global",
+ "Local"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestBuffer": {
+ "description": "RequestBuffer allows the gateway to buffer and fully receive each request from a client before continuing to send the request\nupstream to the backends. This can be helpful to shield your backend servers from slow clients, and also to enforce a maximum size per request\nas any requests larger than the buffer size will be rejected.\n\nThis can have a negative performance impact so should only be enabled when necessary.\n\nWhen enabling this option, you should also configure your connection buffer size to account for these request buffers. There will also be an\nincrease in memory usage for Envoy that should be accounted for in your deployment settings.\n\nRequest buffering is incompatible with streaming APIs and protocol upgrades such as gRPC streaming and WebSocket. Do not enable this option\non routes that need those protocols, because requests can hang instead of being forwarded upstream.",
+ "properties": {
+ "limit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Limit specifies the maximum allowed size in bytes for each incoming request buffer.\nIf exceeded, the request will be rejected with HTTP 413 Content Too Large.\n\nAccepts values in resource.Quantity format (e.g., \"10Mi\", \"500Ki\").",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "responseOverride": {
+ "description": "ResponseOverride defines the configuration to override specific responses with a custom one.\nIf multiple configurations are specified, the first one to match wins.",
+ "items": {
+ "description": "ResponseOverride defines the configuration to override specific responses with a custom one.",
+ "properties": {
+ "match": {
+ "description": "Match configuration.",
+ "properties": {
+ "statusCodes": {
+ "description": "Status code to match on. The match evaluates to true if any of the matches are successful.",
+ "items": {
+ "description": "StatusCodeMatch defines the configuration for matching a status code.",
+ "properties": {
+ "range": {
+ "description": "Range contains the range of status codes.",
+ "properties": {
+ "end": {
+ "description": "End of the range, including the end value.",
+ "type": "integer"
+ },
+ "start": {
+ "description": "Start of the range, including the start value.",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "end must be greater than start",
+ "rule": "self.end > self.start"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Value",
+ "Range"
+ ]
+ },
+ {
+ "enum": [
+ "Value",
+ "Range"
+ ]
+ }
+ ],
+ "default": "Value",
+ "description": "Type is the type of value.\nValid values are Value and Range, default is Value.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value contains the value of the status code.",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "value must be set for type Value",
+ "rule": "(!has(self.type) || self.type == 'Value')? has(self.value) : true"
+ },
+ {
+ "message": "range must be set for type Range",
+ "rule": "(has(self.type) && self.type == 'Range')? has(self.range) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "statusCodes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "redirect": {
+ "description": "Redirect configuration",
+ "properties": {
+ "hostname": {
+ "description": "Hostname is the hostname to be used in the value of the `Location`\nheader in the response.\nWhen empty, the hostname in the `Host` header of the request is used.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines parameters used to modify the path of the incoming request.\nThe modified path is then used to construct the `Location` header. When\nempty, the request path is used as-is.\nOnly ReplaceFullPath path modifier is supported currently.",
+ "properties": {
+ "replaceFullPath": {
+ "description": "ReplaceFullPath specifies the value with which to replace the full path\nof a request during a rewrite or redirect.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "replacePrefixMatch": {
+ "description": "ReplacePrefixMatch specifies the value with which to replace the prefix\nmatch of a request during a rewrite or redirect. For example, a request\nto \"/foo/bar\" with a prefix match of \"/foo\" and a ReplacePrefixMatch\nof \"/xyz\" would be modified to \"/xyz/bar\".\n\nNote that this matches the behavior of the PathPrefix match type. This\nmatches full path elements. A path element refers to the list of labels\nin the path split by the `/` separator. When specified, a trailing `/` is\nignored. For example, the paths `/abc`, `/abc/`, and `/abc/def` would all\nmatch the prefix `/abc`, but the path `/abcd` would not.\n\nReplacePrefixMatch is only compatible with a `PathPrefix` HTTPRouteMatch.\nUsing any other HTTPRouteMatch type on the same HTTPRouteRule will result in\nthe implementation setting the Accepted Condition for the Route to `status: False`.\n\nRequest Path | Prefix Match | Replace Prefix | Modified Path",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "type": {
+ "description": "Type defines the type of path modifier. Additional types may be\nadded in a future release of the API.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.",
+ "enum": [
+ "ReplaceFullPath",
+ "ReplacePrefixMatch"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only ReplaceFullPath is supported for path.type",
+ "rule": "self.type == 'ReplaceFullPath'"
+ },
+ {
+ "message": "replaceFullPath must be specified when type is set to 'ReplaceFullPath'",
+ "rule": "self.type == 'ReplaceFullPath' ? has(self.replaceFullPath) : true"
+ },
+ {
+ "message": "type must be 'ReplaceFullPath' when replaceFullPath is set",
+ "rule": "has(self.replaceFullPath) ? self.type == 'ReplaceFullPath' : true"
+ },
+ {
+ "message": "replacePrefixMatch must be specified when type is set to 'ReplacePrefixMatch'",
+ "rule": "self.type == 'ReplacePrefixMatch' ? has(self.replacePrefixMatch) : true"
+ },
+ {
+ "message": "type must be 'ReplacePrefixMatch' when replacePrefixMatch is set",
+ "rule": "has(self.replacePrefixMatch) ? self.type == 'ReplacePrefixMatch' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "port": {
+ "description": "Port is the port to be used in the value of the `Location`\nheader in the response.\n\nIf redirect scheme is not-empty, the well-known port associated with the redirect scheme will be used.\nSpecifically \"http\" to port 80 and \"https\" to port 443. If the redirect scheme does not have a\nwell-known port or redirect scheme is empty, the listener port of the Gateway will be used.\n\nPort will not be added in the 'Location' header if scheme is HTTP and port is 80\nor scheme is HTTPS and port is 443.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "scheme": {
+ "description": "Scheme is the scheme to be used in the value of the `Location` header in\nthe response. When empty, the scheme of the request is used.",
+ "enum": [
+ "http",
+ "https"
+ ],
+ "type": "string"
+ },
+ "statusCode": {
+ "default": 302,
+ "description": "StatusCode is the HTTP status code to be used in response.",
+ "enum": [
+ 301,
+ 302
+ ],
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response configuration.",
+ "properties": {
+ "body": {
+ "description": "Body of the Custom Response\nSupports Envoy command operators for dynamic content (see https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators).",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the value as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ },
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ }
+ ],
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the body value.\nValid values are Inline and ValueRef, default is Inline.",
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef contains the contents of the body\nspecified as a local object reference.\nOnly a reference to ConfigMap is supported.\n\nThe value of key `response.body` in the ConfigMap will be used as the response body.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "inline must be set for type Inline",
+ "rule": "(!has(self.type) || self.type == 'Inline')? has(self.inline) : true"
+ },
+ {
+ "message": "valueRef must be set for type ValueRef",
+ "rule": "(has(self.type) && self.type == 'ValueRef')? has(self.valueRef) : true"
+ },
+ {
+ "message": "only ConfigMap is supported for ValueRef",
+ "rule": "has(self.valueRef) ? self.valueRef.kind == 'ConfigMap' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "contentType": {
+ "description": "Content Type of the response. This will be set in the Content-Type header.",
+ "type": "string"
+ },
+ "header": {
+ "description": "Header defines headers to add, set or remove from the response.\nThis allows the response policy to append, add or override headers\nof the final response before it is sent to a downstream client.\nNote: Header removal is not supported for responseOverride.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Remove is not supported for header in CustomResponse",
+ "rule": "!has(self.remove) || size(self.remove) == 0"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "statusCode": {
+ "description": "Status Code of the Custom Response\nIf unset, does not override the status of response.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "source": {
+ "description": "Source specifies which responses this rule applies to.\nLocal overrides only Envoy-generated responses (e.g. auth failures).\nBackend overrides only upstream responses.\nAll (default) overrides both.",
+ "enum": [
+ "All",
+ "Local",
+ "Backend"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "match"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one of response or redirect must be specified",
+ "rule": "(has(self.response) && !has(self.redirect)) || (!has(self.response) && has(self.redirect))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "routingType": {
+ "description": "RoutingType can be set to \"Service\" to use the Service Cluster IP for routing to the backend,\nor it can be set to \"Endpoint\" to use Endpoint routing.\nWhen specified, this overrides the EnvoyProxy-level setting for the relevant targetRefs.\nIf not specified, the EnvoyProxy-level setting is used.",
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "telemetry": {
+ "description": "Telemetry configures the telemetry settings for the policy target (Gateway or xRoute).\nThis will override the telemetry settings in the EnvoyProxy resource.",
+ "properties": {
+ "metrics": {
+ "description": "Metrics defines metrics configuration for the backend or Route.",
+ "properties": {
+ "routeStatName": {
+ "description": "RouteStatName defines the value of the Route stat_prefix, determining how the route stats are named.\nFor more details, see envoy docs: https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/route/v3/route_components.proto#config-route-v3-route\nThe supported operators for this pattern are:\n%ROUTE_NAME%: name of Gateway API xRoute resource\n%ROUTE_NAMESPACE%: namespace of Gateway API xRoute resource\n%ROUTE_KIND%: kind of Gateway API xRoute resource\nExample: %ROUTE_KIND%/%ROUTE_NAMESPACE%/%ROUTE_NAME% => httproute/my-ns/my-route\nDisabled by default.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tracing": {
+ "description": "Tracing configures the tracing settings for the backend or HTTPRoute.\n\nThis takes precedence over EnvoyProxy tracing when set.",
+ "properties": {
+ "customTags": {
+ "additionalProperties": {
+ "properties": {
+ "environment": {
+ "description": "Environment adds value from environment variable to each span.\nIt's required when the type is \"Environment\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the environment variable is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the environment variable which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "literal": {
+ "description": "Literal adds hard-coded value to each span.\nIt's required when the type is \"Literal\".",
+ "properties": {
+ "value": {
+ "description": "Value defines the hard-coded value to add to each span.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestHeader": {
+ "description": "RequestHeader adds value from request header to each span.\nIt's required when the type is \"RequestHeader\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the request header is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the request header which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Literal",
+ "description": "Type defines the type of custom tag.",
+ "enum": [
+ "Literal",
+ "Environment",
+ "RequestHeader"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "description": "CustomTags defines the custom tags to add to each span.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nDeprecated: Use Tags instead.",
+ "type": "object"
+ },
+ "samplingFraction": {
+ "description": "SamplingFraction represents the fraction of requests that should be\nselected for tracing if no prior sampling decision has been made.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "spanName": {
+ "description": "SpanName defines the name of the span which will be used for tracing.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\n\nIf not set, the span name is provider specific.\ne.g. Datadog use `ingress` as the default client span name,\nand `router egress` as the server span name.",
+ "properties": {
+ "client": {
+ "description": "Client defines operation name of the span which will be used for tracing.",
+ "type": "string"
+ },
+ "server": {
+ "description": "Server defines the operation name of the upstream span which will be used for tracing.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "client",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tags": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Tags defines the custom tags to add to each span.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nSame keys take precedence over CustomTags.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "useClientProtocol": {
+ "description": "UseClientProtocol configures Envoy to prefer sending requests to backends using\nthe same HTTP protocol that the incoming request used. Defaults to false, which means\nthat Envoy will use the protocol indicated by the attached BackendRef.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true "
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRef) ? self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute'] : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true "
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute']) : true "
+ },
+ {
+ "message": "either compression or compressor can be set, not both",
+ "rule": "!has(self.compression) || !has(self.compressor)"
+ },
+ {
+ "message": "requestBuffer cannot be used together with httpUpgrade",
+ "rule": "!has(self.requestBuffer) || !has(self.httpUpgrade) || self.httpUpgrade.size() == 0"
+ },
+ {
+ "message": "admissionControl can only be used with HTTPRoute, GRPCRoute, or Gateway targets",
+ "rule": "!has(self.admissionControl) || ((!has(self.targetRef) || self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute']) && (!has(self.targetRefs) || self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute'])) && (!has(self.targetSelectors) || self.targetSelectors.all(sel, sel.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute'])))"
+ },
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "status defines the current status of BackendTrafficPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/clienttrafficpolicy_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/clienttrafficpolicy_v1alpha1.json
new file mode 100644
index 0000000..87dc29b
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/clienttrafficpolicy_v1alpha1.json
@@ -0,0 +1,1662 @@
+{
+ "description": "ClientTrafficPolicy allows the user to configure the behavior of the connection\nbetween the downstream client and Envoy Proxy listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of ClientTrafficPolicy.",
+ "properties": {
+ "clientIPDetection": {
+ "description": "ClientIPDetectionSettings provides configuration for determining the original client IP address for requests.",
+ "properties": {
+ "customHeader": {
+ "description": "CustomHeader provides configuration for determining the client IP address for a request based on\na trusted custom HTTP header. This uses the custom_header original IP detection extension.\nRefer to https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/http/original_ip_detection/custom_header/v3/custom_header.proto\nfor more details.",
+ "properties": {
+ "failClosed": {
+ "description": "FailClosed is a switch used to control the flow of traffic when client IP detection\nfails. If set to true, the listener will respond with 403 Forbidden when the client\nIP address cannot be determined.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the header containing the original downstream remote address, if present.",
+ "maxLength": 255,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9-]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "xForwardedFor": {
+ "description": "XForwardedForSettings provides configuration for using X-Forwarded-For headers for determining the client IP address.",
+ "properties": {
+ "numTrustedHops": {
+ "description": "NumTrustedHops specifies how many trusted hops to count from the rightmost side of\nthe X-Forwarded-For (XFF) header when determining the original client\u2019s IP address.\n\nIf NumTrustedHops is set to N, the client IP is taken from the Nth address from the\nright end of the XFF header.\n\nExample:\n XFF = \"203.0.113.128, 203.0.113.10, 203.0.113.1\"\n NumTrustedHops = 2\n \u2192 Trusted client address = 203.0.113.10\n\nOnly one of NumTrustedHops or TrustedCIDRs should be configured.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "trustedCIDRs": {
+ "description": "TrustedCIDRs is a list of CIDR ranges to trust when evaluating\nthe remote IP address to determine the original client\u2019s IP address.\nWhen the remote IP address matches a trusted CIDR and the x-forwarded-for header was sent,\neach entry in the x-forwarded-for header is evaluated from right to left\nand the first public non-trusted address is used as the original client address.\nIf all addresses in x-forwarded-for are within the trusted list, the first (leftmost) entry is used.\nOnly one of NumTrustedHops and TrustedCIDRs must be set.",
+ "items": {
+ "description": "CIDR defines a CIDR Address range.\nA CIDR can be an IPv4 address range such as \"192.168.1.0/24\" or an IPv6 address range such as \"2001:0db8:11a3:09d7::/64\".",
+ "pattern": "((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]+))|((([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))\\/([0-9]+))",
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of numTrustedHops or trustedCIDRs must be set",
+ "rule": "(has(self.numTrustedHops) && !has(self.trustedCIDRs)) || (!has(self.numTrustedHops) && has(self.trustedCIDRs))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "customHeader cannot be used in conjunction with xForwardedFor",
+ "rule": "!(has(self.xForwardedFor) && has(self.customHeader))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes client connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit provides configuration for the maximum buffer size in bytes for each incoming connection.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 32768 bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "connectionLimit": {
+ "description": "ConnectionLimit defines limits related to connections",
+ "properties": {
+ "closeDelay": {
+ "description": "CloseDelay defines the delay to use before closing connections that are rejected\nonce the limit value is reached.\nDefault: none.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "MaxConnectionDuration is the maximum amount of time a connection can remain established\n(usually via TCP/HTTP Keepalive packets) before being drained and/or closed.\nIf not specified, there is no limit.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxRequestsPerConnection": {
+ "description": "MaxRequestsPerConnection defines the maximum number of requests allowed over a single connection.\nIf not specified, there is no limit. Setting this parameter to 1 will effectively disable keep alive.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum amount of time to keep alive an http stream. When the limit is reached\nthe stream will be reset independent of any other timeouts. If not specified, no value is set.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the maximum concurrent connections limit.\nWhen the limit is reached, incoming connections will be closed after the CloseDelay duration.",
+ "format": "int64",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "closeDelay can only be configured when value is set",
+ "rule": "!has(self.closeDelay) || has(self.value)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxAcceptPerSocketEvent": {
+ "default": 1,
+ "description": "MaxAcceptPerSocketEvent provides configuration for the maximum number of connections to accept from the kernel\nper socket event. If there are more than MaxAcceptPerSocketEvent connections pending accept, connections over\nthis threshold will be accepted in later event loop iterations.\nDefaults to 1 and can be disabled by setting to 0 for allowing unlimited accepted connections.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each incoming socket.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "enableProxyProtocol": {
+ "description": "EnableProxyProtocol interprets the ProxyProtocol header and adds the\nClient Address into the X-Forwarded-For header.\nNote Proxy Protocol must be present when this field is set, else the connection\nis closed.\n\nDeprecated: Use ProxyProtocol instead.",
+ "type": "boolean"
+ },
+ "grpc": {
+ "description": "GRPC provides gRPC configuration on the listener.",
+ "properties": {
+ "enableWeb": {
+ "description": "EnableWeb configures the gRPC-web filter on the listener.\nThe gRPC-web filter allows clients (typically browsers) to make gRPC calls\nusing HTTP/1.1 or HTTP/2.\n\nThis is enabled by default for GRPCRoute and opt-in for HTTPRoute.\nIn general, gRPC traffic should be handled via GRPCRoute, but there are cases where\nusers want to route gRPC using HTTPRoute for its richer matching capabilities.\nTherefore, we enable this behavior only when it is explicitly opted in.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "HeaderSettings provides configuration for header management.",
+ "properties": {
+ "disableRateLimitHeaders": {
+ "description": "DisableRateLimitHeaders configures Envoy Proxy to omit the \"X-RateLimit-\" response headers\nwhen rate limiting is enabled.",
+ "type": "boolean"
+ },
+ "earlyRequestHeaders": {
+ "description": "EarlyRequestHeaders defines settings for early request header modification, before envoy performs\nrouting, tracing and built-in header manipulation.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "addIfAbsent": {
+ "description": "AddIfAbsent adds the given header(s) (name, value) to the request/response\nonly if the header does not already exist. Unlike Add which appends to\nexisting values, this is a no-op if the header is already present.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n addIfAbsent:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "removeOnMatch": {
+ "description": "RemoveOnMatch removes headers whose names match the specified string matchers.\nMatching is performed on the header name (case-insensitive).",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "enableEnvoyHeaders": {
+ "description": "EnableEnvoyHeaders configures Envoy Proxy to add the \"X-Envoy-\" headers to requests\nand responses.",
+ "type": "boolean"
+ },
+ "lateResponseHeaders": {
+ "description": "LateResponseHeaders defines settings for global response header modification.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "addIfAbsent": {
+ "description": "AddIfAbsent adds the given header(s) (name, value) to the request/response\nonly if the header does not already exist. Unlike Add which appends to\nexisting values, this is a no-op if the header is already present.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n addIfAbsent:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "removeOnMatch": {
+ "description": "RemoveOnMatch removes headers whose names match the specified string matchers.\nMatching is performed on the header name (case-insensitive).",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "preserveXRequestID": {
+ "description": "PreserveXRequestID configures Envoy to keep the X-Request-ID header if passed for a request that is edge\n(Edge request is the request from external clients to front Envoy) and not reset it, which is the current Envoy behaviour.\nDefaults to false and cannot be combined with RequestID.\n\nDeprecated: use RequestID=PreserveOrGenerate instead",
+ "type": "boolean"
+ },
+ "requestID": {
+ "description": "RequestID configures Envoy's behavior for handling the `X-Request-ID` header.\nWhen omitted default behavior is `Generate` which builds the `X-Request-ID` for every request\n and ignores pre-existing values from the edge.\n(An \"edge request\" refers to a request from an external client to the Envoy entrypoint.)",
+ "enum": [
+ "PreserveOrGenerate",
+ "Preserve",
+ "Generate",
+ "Disable"
+ ],
+ "type": "string"
+ },
+ "withUnderscoresAction": {
+ "description": "WithUnderscoresAction configures the action to take when an HTTP header with underscores\nis encountered. The default action is to reject the request.",
+ "enum": [
+ "Allow",
+ "RejectRequest",
+ "DropHeader"
+ ],
+ "type": "string"
+ },
+ "xForwardedClientCert": {
+ "description": "XForwardedClientCert configures how Envoy Proxy handle the x-forwarded-client-cert (XFCC) HTTP header.\n\nx-forwarded-client-cert (XFCC) is an HTTP header used to forward the certificate\ninformation of part or all of the clients or proxies that a request has flowed through,\non its way from the client to the server.\n\nEnvoy proxy may choose to sanitize/append/forward the XFCC header before proxying the request.\n\nIf not set, the default behavior is sanitizing the XFCC header.",
+ "properties": {
+ "certDetailsToAdd": {
+ "description": "CertDetailsToAdd specifies the fields in the client certificate to be forwarded in the XFCC header.\n\nHash(the SHA 256 digest of the current client certificate) and By(the Subject Alternative Name)\nare always included if the client certificate is forwarded.\n\nThis field is only applicable when the mode is set to `AppendForward` or\n`SanitizeSet` and the client connection is mTLS.",
+ "items": {
+ "description": "XFCCCertData specifies the fields in the client certificate to be forwarded in the XFCC header.",
+ "enum": [
+ "Subject",
+ "Cert",
+ "Chain",
+ "DNS",
+ "URI"
+ ],
+ "type": "string"
+ },
+ "maxItems": 5,
+ "type": "array"
+ },
+ "mode": {
+ "description": "Mode defines how XFCC header is handled by Envoy Proxy.\nIf not set, the default mode is `Sanitize`.",
+ "enum": [
+ "Sanitize",
+ "ForwardOnly",
+ "AppendForward",
+ "SanitizeSet",
+ "AlwaysForwardOnly"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "certDetailsToAdd can only be set when mode is AppendForward or SanitizeSet",
+ "rule": "(has(self.certDetailsToAdd) && self.certDetailsToAdd.size() > 0) ? (self.mode == 'AppendForward' || self.mode == 'SanitizeSet') : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "preserveXRequestID and requestID cannot both be set.",
+ "rule": "!(has(self.preserveXRequestID) && has(self.requestID))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck provides configuration for determining whether the HTTP/HTTPS listener is healthy.",
+ "properties": {
+ "path": {
+ "description": "Path specifies the HTTP path to match on for health check requests.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http1": {
+ "description": "HTTP1 provides HTTP/1 configuration on the listener.",
+ "properties": {
+ "disableSafeMaxConnectionDuration": {
+ "description": "DisableSafeMaxConnectionDuration controls the close behavior for HTTP/1 connections.\nBy default, connection closure is delayed until the next request arrives after maxConnectionDuration is exceeded.\nIt then adds a Connection: close header and gracefully closes the connection after the response completes.\nWhen set to true (disabled), Envoy uses its default drain behavior, closing the connection shortly after maxConnectionDuration elapses.\nHas no effect unless maxConnectionDuration is set.",
+ "type": "boolean"
+ },
+ "enableTrailers": {
+ "description": "EnableTrailers defines if HTTP/1 trailers should be proxied by Envoy.",
+ "type": "boolean"
+ },
+ "http10": {
+ "description": "HTTP10 turns on support for HTTP/1.0 and HTTP/0.9 requests.",
+ "properties": {
+ "useDefaultHost": {
+ "description": "UseDefaultHost specifies whether a default Host header should be injected\ninto HTTP/1.0 requests that do not include one.\n\nWhen set to true, Envoy Gateway injects the hostname associated with the\nlistener or route into the request, in the following order:\n\n 1. If the targeted listener has a non-wildcard hostname, use that hostname.\n 2. If there is exactly one HTTPRoute with a non-wildcard hostname under\n the targeted listener, use that hostname.\n\n Note: Setting this field to true without a non-wildcard hostname makes the\nClientTrafficPolicy invalid.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ignoredUpgradeTypes": {
+ "description": "IgnoredUpgradeTypes specifies a list of upgrade types for which\nHTTP/1.1 Upgrade requests should be ignored by Envoy instead of being\nrejected with a 403 response. When a client sends an HTTP/1.1 request\nwith Connection: Upgrade and an Upgrade header matching one of these\nmatchers, Envoy will strip the upgrade headers and process the request\nas a normal HTTP/1.1 request.\n\nExample: To ignore TLS upgrade requests (RFC 2817), use a Prefix match with value \"TLS/\".",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "preserveHeaderCase": {
+ "description": "PreserveHeaderCase defines if Envoy should preserve the letter case of headers.\nBy default, Envoy will lowercase all the headers.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration on the listener.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http3": {
+ "description": "HTTP3 provides HTTP/3 configuration on the listener.",
+ "type": "object"
+ },
+ "path": {
+ "description": "Path enables managing how the incoming path set by clients can be normalized.",
+ "properties": {
+ "disableMergeSlashes": {
+ "description": "DisableMergeSlashes allows disabling the default configuration of merging adjacent\nslashes in the path.\nNote that slash merging is not part of the HTTP spec and is provided for convenience.",
+ "type": "boolean"
+ },
+ "escapedSlashesAction": {
+ "description": "EscapedSlashesAction determines how %2f, %2F, %5c, or %5C sequences in the path URI\nshould be handled.\nThe default is UnescapeAndRedirect.",
+ "enum": [
+ "KeepUnchanged",
+ "RejectRequest",
+ "UnescapeAndForward",
+ "UnescapeAndRedirect"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol configures the Proxy Protocol settings. When configured,\nthe Proxy Protocol header will be interpreted and the Client Address\nwill be added into the X-Forwarded-For header.\nIf both EnableProxyProtocol and ProxyProtocol are set, ProxyProtocol takes precedence.",
+ "minProperties": 0,
+ "properties": {
+ "optional": {
+ "description": "Optional allows requests without a Proxy Protocol header to be proxied.\nIf set to true, the listener will accept requests without a Proxy Protocol header.\nIf set to false, the listener will reject requests without a Proxy Protocol header.\nIf not set, the default behavior is to reject requests without a Proxy Protocol header.\nWarning: Optional breaks conformance with the specification. Only enable if ALL traffic to the listener comes from a trusted source.\nFor more information on security implications, see haproxy.org/download/2.1/doc/proxy-protocol.txt",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scheme": {
+ "description": "Scheme configures how the :scheme pseudo-header is set for requests forwarded to backends.\n\n- Preserve (default): Preserves the :scheme from the original client request.\n Use this when backends need to know the original client scheme for URL generation or redirects.\n\n- MatchBackend: Sets the :scheme to match the backend transport protocol.\n If the backend uses TLS, the scheme is \"https\", otherwise \"http\".\n Use this when backends require the scheme to match the actual transport protocol,\n such as strictly HTTPS services that validate the :scheme header.",
+ "enum": [
+ "Preserve",
+ "MatchBackend"
+ ],
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the downstream client connection.\nIf defined, sets SO_KEEPALIVE on the listener socket to enable TCP Keepalives.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the client connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "idleTimeout": {
+ "description": "IdleTimeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestReceivedTimeout": {
+ "description": "RequestReceivedTimeout is the duration envoy waits for the complete request reception. This timer starts upon request\ninitiation and stops when either the last byte of the request is sent upstream or when the response begins.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n Default: 5 minutes.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "idleTimeout": {
+ "description": "IdleTimeout for a TCP connection. Idle time is defined as a period in which there are no\nbytes sent or received on either the upstream or downstream connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tls": {
+ "description": "TLS settings configure TLS termination settings with the downstream client.",
+ "properties": {
+ "alpnProtocols": {
+ "description": "ALPNProtocols supplies the list of ALPN protocols that should be\nexposed by the listener or used by the proxy to connect to the backend.\nDefaults:\n1. HTTPS Routes: h2 and http/1.1 are enabled in listener context.\n2. Other Routes: ALPN is disabled.\n3. Backends: proxy uses the appropriate ALPN options for the backend protocol.\nWhen an empty list is provided, the ALPN TLS extension is disabled.\n\nDefaults to [h2, http/1.1] if not specified.\n\nTypical Supported values are:\n- http/1.0\n- http/1.1\n- h2",
+ "items": {
+ "description": "ALPNProtocol specifies the protocol to be negotiated using ALPN",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "ciphers": {
+ "description": "Ciphers specifies the set of cipher suites supported when\nnegotiating TLS 1.0 - 1.2. This setting has no effect for TLS 1.3.\nFor Envoy TLS cipher suite configuration semantics and default cipher\nlists, see the Envoy documentation:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/transport_sockets/tls/v3/common.proto#extensions-transport-sockets-tls-v3-tlsparameters\nSupported cipher suite names:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\n- ECDHE-ECDSA-CHACHA20-POLY1305\n- ECDHE-RSA-CHACHA20-POLY1305\n- ECDHE-ECDSA-AES128-SHA\n- ECDHE-RSA-AES128-SHA\n- AES128-GCM-SHA256\n- AES128-SHA\n- ECDHE-ECDSA-AES256-SHA\n- ECDHE-RSA-AES256-SHA\n- AES256-GCM-SHA384\n- AES256-SHA\nSupported IANA/RFC aliases:\n- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\n- TLS_RSA_WITH_AES_128_GCM_SHA256\n- TLS_RSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\n- TLS_RSA_WITH_AES_256_GCM_SHA384\n- TLS_RSA_WITH_AES_256_CBC_SHA\nIn non-FIPS Envoy Proxy builds the default cipher list is:\n- [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]\n- [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\nIn builds using BoringSSL FIPS the default cipher list is:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "clientValidation": {
+ "description": "ClientValidation specifies the configuration to validate the client\ninitiating the TLS connection to the Gateway listener.",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to\nKubernetes objects that contain TLS certificates of\nthe Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the client.\n\nA single reference to a Kubernetes ConfigMap or a Kubernetes Secret,\nwith the CA certificate in a key named `ca.crt` is currently supported.\n\nReferences to a resource in different namespace are invalid UNLESS there\nis a ReferenceGrant in the target namespace that allows the certificate\nto be attached.",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "certificateHashes": {
+ "description": "An optional list of hex-encoded SHA-256 hashes. If specified, Envoy will\nverify that the SHA-256 of the DER-encoded presented certificate matches\none of the specified values.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "crl": {
+ "description": "Crl specifies the crl configuration that can be used to validate the client initiating the TLS connection",
+ "properties": {
+ "onlyVerifyLeafCertificate": {
+ "description": "If this option is set to true, Envoy will only verify the certificate at the end of the certificate chain against the CRL.\nDefaults to false, which will verify the entire certificate chain against the CRL.",
+ "type": "boolean"
+ },
+ "refs": {
+ "description": "Refs contains one or more references to a Kubernetes ConfigMap or a Kubernetes Secret,\ncontaining the certificate revocation list in PEM format\nExpects the content in a key named `ca.crl`.\n\nReferences to a resource in different namespace are invalid UNLESS there\nis a ReferenceGrant in the target namespace that allows the crl\nto be attached.",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "refs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Mode defines how the Gateway or Listener validates client certificates.\nIf not specified, defaults to RequireAndVerify.",
+ "enum": [
+ "Request",
+ "RequireAny",
+ "VerifyIfGiven",
+ "RequireAndVerify"
+ ],
+ "type": "string"
+ },
+ "optional": {
+ "description": "Optional set to true accepts connections even when a client doesn't present a certificate.\nDefaults to false, which rejects connections without a valid client certificate.\n\nDeprecated: Use Mode instead.",
+ "type": "boolean"
+ },
+ "spkiHashes": {
+ "description": "An optional list of base64-encoded SHA-256 hashes. If specified, Envoy will\nverify that the SHA-256 of the DER-encoded Subject Public Key Information\n(SPKI) of the presented certificate matches one of the specified values.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "subjectAltNames": {
+ "description": "An optional list of Subject Alternative name matchers. If specified, Envoy\nwill verify that the Subject Alternative Name of the presented certificate\nmatches one of the specified matchers",
+ "properties": {
+ "dnsNames": {
+ "description": "DNS names matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "emailAddresses": {
+ "description": "Email addresses matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "ipAddresses": {
+ "description": "IP addresses matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "otherNames": {
+ "description": "Other names matchers",
+ "items": {
+ "properties": {
+ "oid": {
+ "description": "OID Value",
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "oid",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "uris": {
+ "description": "URIs matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ecdhCurves": {
+ "description": "ECDHCurves specifies the set of supported ECDH curves.\nIn non-FIPS Envoy Proxy builds the default curves are:\n- X25519\n- P-256\nIn builds using BoringSSL FIPS the default curve is:\n- P-256",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "fingerprints": {
+ "description": "Fingerprints specifies TLS client fingerprinting.\nWhen specified, a JAX fingerprint derived from the client\u2019s TLS handshake\nis generated. The fingerprint can be logged in access logs or\nforwarded to upstream services using request headers.\n\nFingerprinting is disabled if not specified.\n\nSupported values are:\n- JA3\n- JA4",
+ "items": {
+ "description": "TLSFingerprintType specifies the TLS client fingerprinting mode.",
+ "enum": [
+ "JA3",
+ "JA4"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "maxVersion": {
+ "description": "Max specifies the maximal TLS protocol version to allow\nThe default is TLS 1.3 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "minVersion": {
+ "description": "Min specifies the minimal TLS protocol version to allow.\nThe default is TLS 1.2 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "session": {
+ "description": "Session defines settings related to TLS session management.",
+ "properties": {
+ "resumption": {
+ "description": "Resumption determines the proxy's supported TLS session resumption option.\nBy default, Envoy Gateway does not enable session resumption. Use sessionResumption to\nenable stateful and stateless session resumption. Users should consider security impacts\nof different resumption methods. Performance gains from resumption are diminished when\nEnvoy proxy is deployed with more than one replica.",
+ "properties": {
+ "stateful": {
+ "description": "Stateful defines setting for stateful (session-id based) session resumption",
+ "type": "object"
+ },
+ "stateless": {
+ "description": "Stateless defines setting for stateless (session-ticket based) session resumption",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "signatureAlgorithms": {
+ "description": "SignatureAlgorithms specifies which signature algorithms the listener should\nsupport.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "setting ciphers has no effect if the minimum possible TLS version is 1.3",
+ "rule": "has(self.minVersion) && self.minVersion == '1.3' ? !has(self.ciphers) : true"
+ },
+ {
+ "message": "minVersion must be smaller or equal to maxVersion",
+ "rule": "has(self.minVersion) && has(self.maxVersion) ? {\"Auto\":0,\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4}[self.minVersion] <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : !has(self.minVersion) && has(self.maxVersion) ? 3 <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true"
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway",
+ "rule": "has(self.targetRef) ? self.targetRef.kind == 'Gateway' : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind == 'Gateway') : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of ClientTrafficPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/envoyextensionpolicy_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/envoyextensionpolicy_v1alpha1.json
new file mode 100644
index 0000000..6834ef8
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/envoyextensionpolicy_v1alpha1.json
@@ -0,0 +1,2259 @@
+{
+ "description": "EnvoyExtensionPolicy allows the user to configure various envoy extensibility options for the Gateway.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of EnvoyExtensionPolicy.",
+ "properties": {
+ "dynamicModule": {
+ "description": "DynamicModule is an ordered list of dynamic module HTTP filters\nthat should be added to the envoy filter chain.\nEach module must be registered in the EnvoyProxy resource's dynamicModules\nallowlist.\nOrder matters, as the filters will be loaded in the order they are\ndefined in this list.",
+ "items": {
+ "description": "DynamicModule defines a dynamic module HTTP filter to be loaded by Envoy.\nThe module must be registered in the EnvoyProxy resource's dynamicModules\nallowlist by the infrastructure operator.",
+ "properties": {
+ "config": {
+ "description": "Config is the configuration for the dynamic module filter.\nThis is serialized as JSON and passed to the module's initialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "filterName": {
+ "description": "FilterName identifies a specific filter implementation within the dynamic\nmodule. A single shared library can contain multiple filter implementations.\nThis value is passed to the module's HTTP filter config init function to\nselect the appropriate implementation.\nIf not specified, defaults to an empty string.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "terminalFilter": {
+ "default": false,
+ "description": "TerminalFilter indicates that this dynamic module handles requests without\nrequiring an upstream backend. The module is responsible for generating and\nsending the response to downstream directly.\nDefaults to false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "extProc": {
+ "description": "ExtProc is an ordered list of external processing filters\nthat should be added to the envoy filter chain",
+ "items": {
+ "description": "ExtProc defines the configuration for External Processing filter.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "failOpen": {
+ "default": false,
+ "description": "FailOpen is a switch used to control the behavior when failing to call the external processor.\n\nIf FailOpen is set to true, the system bypasses the ExtProc extension and\nallows the traffic to pass through. If it is set to false or\nnot set (defaulting to false), the system blocks the traffic and returns\nan HTTP 5xx error.\n\nIf set to true, the ExtProc extension will also be bypassed if the configuration is invalid.",
+ "type": "boolean"
+ },
+ "messageTimeout": {
+ "description": "MessageTimeout is the timeout for a response to be returned from the external processor\nDefault: 200ms",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata defines options related to the sending and receiving of dynamic metadata.\nThese options define which metadata namespaces would be sent to the processor and which dynamic metadata\nnamespaces the processor would be permitted to emit metadata to.\nUsers can specify custom namespaces or well-known envoy metadata namespace (such as envoy.filters.http.ext_authz)\ndocumented here: https://www.envoyproxy.io/docs/envoy/latest/configuration/advanced/well_known_dynamic_metadata#well-known-dynamic-metadata\nDefault: no metadata context is sent or received from the external processor",
+ "properties": {
+ "accessibleNamespaces": {
+ "description": "AccessibleNamespaces are metadata namespaces that are sent to the external processor as context",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "writableNamespaces": {
+ "description": "WritableNamespaces are metadata namespaces that the external processor can write to",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "writableNamespaces cannot contain well-known Envoy HTTP filter namespaces",
+ "rule": "self.all(f, !f.startsWith('envoy.filters.http'))"
+ }
+ ]
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "processingMode": {
+ "description": "ProcessingMode defines how request and response body is processed\nDefault: header and body are not sent to the external processor",
+ "properties": {
+ "allowModeOverride": {
+ "description": "AllowModeOverride allows the external processor to override the processing mode set via the\n`mode_override` field in the gRPC response message. This defaults to false.",
+ "type": "boolean"
+ },
+ "request": {
+ "description": "Defines processing mode for requests. If present, request headers are sent. Request body is processed according\nto the specified mode.",
+ "properties": {
+ "attributes": {
+ "description": "Defines which attributes are sent to the external processor. Envoy Gateway currently\nsupports only the following attribute prefixes: connection, source, destination,\nrequest, response, upstream and xds.route.\nhttps://www.envoyproxy.io/docs/envoy/latest/intro/arch_overview/advanced/attributes",
+ "items": {
+ "pattern": "^(connection\\.|source\\.|destination\\.|request\\.|response\\.|upstream\\.|xds\\.route_)[a-z_1-9]*$",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "body": {
+ "description": "Defines body processing mode",
+ "enum": [
+ "Streamed",
+ "Buffered",
+ "BufferedPartial",
+ "FullDuplexStreamed"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Defines processing mode for responses. If present, response headers are sent. Response body is processed according\nto the specified mode.",
+ "properties": {
+ "attributes": {
+ "description": "Defines which attributes are sent to the external processor. Envoy Gateway currently\nsupports only the following attribute prefixes: connection, source, destination,\nrequest, response, upstream and xds.route.\nhttps://www.envoyproxy.io/docs/envoy/latest/intro/arch_overview/advanced/attributes",
+ "items": {
+ "pattern": "^(connection\\.|source\\.|destination\\.|request\\.|response\\.|upstream\\.|xds\\.route_)[a-z_1-9]*$",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "body": {
+ "description": "Defines body processing mode",
+ "enum": [
+ "Streamed",
+ "Buffered",
+ "BufferedPartial",
+ "FullDuplexStreamed"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only supports Service, ServiceImport, and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'ServiceImport' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only supports Core, multicluster.x-k8s.io, and gateway.envoyproxy.io groups.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'multicluster.x-k8s.io' || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "If FullDuplexStreamed body processing mode is used, FailOpen must be false.",
+ "rule": "!(has(self.failOpen) && self.failOpen == true && has(self.processingMode) && ((has(self.processingMode.request) && has(self.processingMode.request.body) && self.processingMode.request.body == 'FullDuplexStreamed') || (has(self.processingMode.response) && has(self.processingMode.response.body) && self.processingMode.response.body == 'FullDuplexStreamed')))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "lua": {
+ "description": "Lua is an ordered list of Lua filters\nthat should be added to the envoy filter chain",
+ "items": {
+ "description": "Lua defines a Lua extension\nOnly one of Inline or ValueRef must be set",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the source code as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the Lua value.\nValid values are Inline and ValueRef, default is Inline.",
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ],
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef has the source code specified as a local object reference.\nOnly a reference to ConfigMap is supported.\nThe value of key `lua` in the ConfigMap will be used.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Only a reference to an object of kind ConfigMap belonging to default v1 API group is supported.",
+ "rule": "self.kind == 'ConfigMap' && (self.group == 'v1' || self.group == '')"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Exactly one of inline or valueRef must be set with correct type.",
+ "rule": "(self.type == 'Inline' && has(self.inline) && !has(self.valueRef)) || (self.type == 'ValueRef' && !has(self.inline) && has(self.valueRef))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "wasm": {
+ "description": "Wasm is a list of Wasm extensions to be loaded by the Gateway.\nOrder matters, as the extensions will be loaded in the order they are\ndefined in this list.",
+ "items": {
+ "description": "Wasm defines a Wasm extension.\n\nNote: at the moment, Envoy Gateway does not support configuring Wasm runtime.\nv8 is used as the VM runtime for the Wasm extensions.",
+ "properties": {
+ "code": {
+ "description": "Code is the Wasm code for the extension.",
+ "properties": {
+ "http": {
+ "description": "HTTP is the HTTP URL containing the Wasm code.\n\nNote that the HTTP server must be accessible from the Envoy proxy.",
+ "properties": {
+ "sha256": {
+ "description": "SHA256 checksum that will be used to verify the Wasm code.\n\nIf not specified, Envoy Gateway will not verify the downloaded Wasm code.\nkubebuilder:validation:Pattern=`^[a-f0-9]{64}$`",
+ "type": "string"
+ },
+ "tls": {
+ "description": "TLS configuration when connecting to the Wasm code source.",
+ "properties": {
+ "caCertificateRef": {
+ "description": "CACertificateRef contains a reference to\nKubernetes objects that contain TLS certificates of\nthe Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the Wasm code source.\n\nKubernetes ConfigMap, Kubernetes Secret, and Kubernetes ClusterTrustBundle are supported.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "caCertificateRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "url": {
+ "description": "URL is the URL containing the Wasm code.",
+ "pattern": "^((https?:)(\\/\\/\\/?)([\\w]*(?::[\\w]*)?@)?([\\d\\w\\.-]+)(?::(\\d+))?)?([\\/\\\\\\w\\.()-]*)?(?:([?][^#]*)?(#.*)?)*",
+ "type": "string"
+ }
+ },
+ "required": [
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "image": {
+ "description": "Image is the OCI image containing the Wasm code.\n\nNote that the image must be accessible from the Envoy Gateway.",
+ "properties": {
+ "pullSecretRef": {
+ "description": "PullSecretRef is a reference to the secret containing the credentials to pull the image.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only support Secret kind.",
+ "rule": "self.kind == 'Secret'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "sha256": {
+ "description": "SHA256 checksum that will be used to verify the OCI image.\n\nIt must match the digest of the OCI image.\n\nIf not specified, Envoy Gateway will not verify the downloaded OCI image.\nkubebuilder:validation:Pattern=`^[a-f0-9]{64}$`",
+ "type": "string"
+ },
+ "tls": {
+ "description": "TLS configuration when connecting to the Wasm code source.",
+ "properties": {
+ "caCertificateRef": {
+ "description": "CACertificateRef contains a reference to\nKubernetes objects that contain TLS certificates of\nthe Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the Wasm code source.\n\nKubernetes ConfigMap, Kubernetes Secret, and Kubernetes ClusterTrustBundle are supported.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "caCertificateRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "url": {
+ "description": "URL is the URL of the OCI image.\nURL can be in the format of `registry/image:tag` or `registry/image@sha256:digest`.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pullPolicy": {
+ "description": "PullPolicy is the policy to use when pulling the Wasm module by either the HTTP or Image source.\nThis field is only applicable when the SHA256 field is not set.\n\nIf not specified, the default policy is IfNotPresent except for OCI images whose tag is latest.\n\nNote: EG does not update the Wasm module every time an Envoy proxy requests\nthe Wasm module even if the pull policy is set to Always.\nIt only updates the Wasm module when the EnvoyExtension resource version changes.",
+ "enum": [
+ "IfNotPresent",
+ "Always"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "Image"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "Image",
+ "ConfigMap"
+ ]
+ }
+ ],
+ "description": "Type is the type of the source of the Wasm code.\nValid WasmCodeSourceType values are \"HTTP\" or \"Image\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If type is Image, image field needs to be set.",
+ "rule": "self.type == 'Image' ? has(self.image) : !has(self.image)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "config": {
+ "description": "Config is the configuration for the Wasm extension.\nThis configuration will be passed as a JSON string to the Wasm extension.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "env": {
+ "description": "Env configures the environment for the Wasm extension",
+ "properties": {
+ "hostKeys": {
+ "description": "HostKeys is a list of keys for environment variables from the host envoy process\nthat should be passed into the Wasm VM. This is useful for passing secrets to to Wasm extensions.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failOpen": {
+ "default": false,
+ "description": "FailOpen is a switch used to control the behavior when a fatal error occurs\nduring the initialization or the execution of the Wasm extension.\n\nIf FailOpen is set to true, the system bypasses the Wasm extension and\nallows the traffic to pass through. If it is set to false or\nnot set (defaulting to false), the system blocks the traffic and returns\nan HTTP 5xx error.\n\nIf set to true, the Wasm extension will also be bypassed if the configuration is invalid.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name is a unique name for this Wasm extension. It is used to identify the\nWasm extension if multiple extensions are handled by the same vm_id and root_id.\nIt's also used for logging/debugging.\nIf not specified, EG will generate a unique name for the Wasm extension.",
+ "type": "string"
+ },
+ "rootID": {
+ "description": "RootID is a unique ID for a set of extensions in a VM which will share a\nRootContext and Contexts if applicable (e.g., an Wasm HttpFilter and an Wasm AccessLog).\nIf left blank, all extensions with a blank root_id with the same vm_id will share Context(s).\n\nNote: RootID must match the root_id parameter used to register the Context in the Wasm code.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "code"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true"
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRef) ? self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute'] : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true "
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute']) : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of EnvoyExtensionPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/envoypatchpolicy_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/envoypatchpolicy_v1alpha1.json
new file mode 100644
index 0000000..0e87e08
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/envoypatchpolicy_v1alpha1.json
@@ -0,0 +1,292 @@
+{
+ "description": "EnvoyPatchPolicy allows the user to modify the generated Envoy xDS\nresources by Envoy Gateway using this patch API",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of EnvoyPatchPolicy.",
+ "properties": {
+ "jsonPatches": {
+ "description": "JSONPatch defines the JSONPatch configuration.",
+ "items": {
+ "description": "EnvoyJSONPatchConfig defines the configuration for patching a Envoy xDS Resource\nusing JSONPatch semantic",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the resource",
+ "type": "string"
+ },
+ "operation": {
+ "description": "Patch defines the JSON Patch Operation",
+ "properties": {
+ "from": {
+ "description": "From is the source location of the value to be copied or moved. Only valid\nfor move or copy operations\nRefer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.",
+ "type": "string"
+ },
+ "jsonPath": {
+ "description": "JSONPath is a JSONPath expression. Refer to https://datatracker.ietf.org/doc/rfc9535/ for more details.\nIt produces one or more JSONPointer expressions based on the given JSON document.\nIf no JSONPointer is found, it will result in an error.\nIf the 'Path' property is also set, it will be appended to the resulting JSONPointer expressions from the JSONPath evaluation.\nThis is useful when creating a property that does not yet exist in the JSON document.\nThe final JSONPointer expressions specifies the locations in the target document/field where the operation will be applied.",
+ "type": "string"
+ },
+ "op": {
+ "description": "Op is the type of operation to perform",
+ "enum": [
+ "add",
+ "remove",
+ "replace",
+ "move",
+ "copy",
+ "test"
+ ],
+ "type": "string"
+ },
+ "path": {
+ "description": "Path is a JSONPointer expression. Refer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.\nIt specifies the location of the target document/field where the operation will be performed",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the new value of the path location. The value is only used by\nthe `add` and `replace` operations.",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "op"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type is the typed URL of the Envoy xDS Resource",
+ "enum": [
+ "type.googleapis.com/envoy.config.listener.v3.Listener",
+ "type.googleapis.com/envoy.config.route.v3.RouteConfiguration",
+ "type.googleapis.com/envoy.config.cluster.v3.Cluster",
+ "type.googleapis.com/envoy.config.endpoint.v3.ClusterLoadAssignment",
+ "type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.Secret"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "operation",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "priority": {
+ "description": "Priority of the EnvoyPatchPolicy.\nIf multiple EnvoyPatchPolicies are applied to the same\nTargetRef, they will be applied in the ascending order of\nthe priority i.e. int32.min has the highest priority and\nint32.max has the lowest priority.\nDefaults to 0.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the Gateway API resource this policy\nis being attached to.\nBy default, attaching to Gateway is supported and\nwhen mergeGateways is enabled it should attach to GatewayClass.\nThis Policy and the TargetRef MUST be in the same namespace\nfor this Policy to have effect and be applied to the Gateway\nTargetRef",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of patch.\nValid EnvoyPatchType values are \"JSONPatch\".",
+ "enum": [
+ "JSONPatch"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "targetRef",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of EnvoyPatchPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/envoyproxy_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/envoyproxy_v1alpha1.json
new file mode 100644
index 0000000..891e25b
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/envoyproxy_v1alpha1.json
@@ -0,0 +1,15702 @@
+{
+ "description": "EnvoyProxy is the schema for the envoyproxies API.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "EnvoyProxySpec defines the desired state of EnvoyProxy.",
+ "properties": {
+ "backendTLS": {
+ "description": "BackendTLS is the TLS configuration for the Envoy proxy to use when connecting to backends.\nThese settings are applied on backends for which TLS policies are specified.",
+ "properties": {
+ "alpnProtocols": {
+ "description": "ALPNProtocols supplies the list of ALPN protocols that should be\nexposed by the listener or used by the proxy to connect to the backend.\nDefaults:\n1. HTTPS Routes: h2 and http/1.1 are enabled in listener context.\n2. Other Routes: ALPN is disabled.\n3. Backends: proxy uses the appropriate ALPN options for the backend protocol.\nWhen an empty list is provided, the ALPN TLS extension is disabled.\n\nDefaults to [h2, http/1.1] if not specified.\n\nTypical Supported values are:\n- http/1.0\n- http/1.1\n- h2",
+ "items": {
+ "description": "ALPNProtocol specifies the protocol to be negotiated using ALPN",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "ciphers": {
+ "description": "Ciphers specifies the set of cipher suites supported when\nnegotiating TLS 1.0 - 1.2. This setting has no effect for TLS 1.3.\nFor Envoy TLS cipher suite configuration semantics and default cipher\nlists, see the Envoy documentation:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/transport_sockets/tls/v3/common.proto#extensions-transport-sockets-tls-v3-tlsparameters\nSupported cipher suite names:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\n- ECDHE-ECDSA-CHACHA20-POLY1305\n- ECDHE-RSA-CHACHA20-POLY1305\n- ECDHE-ECDSA-AES128-SHA\n- ECDHE-RSA-AES128-SHA\n- AES128-GCM-SHA256\n- AES128-SHA\n- ECDHE-ECDSA-AES256-SHA\n- ECDHE-RSA-AES256-SHA\n- AES256-GCM-SHA384\n- AES256-SHA\nSupported IANA/RFC aliases:\n- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\n- TLS_RSA_WITH_AES_128_GCM_SHA256\n- TLS_RSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\n- TLS_RSA_WITH_AES_256_GCM_SHA384\n- TLS_RSA_WITH_AES_256_CBC_SHA\nIn non-FIPS Envoy Proxy builds the default cipher list is:\n- [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]\n- [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\nIn builds using BoringSSL FIPS the default cipher list is:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef defines the reference to a Kubernetes Secret that contains\nthe client certificate and private key for Envoy to use when connecting to\nbackend services and external services, such as ExtAuth, ALS, OpenTelemetry, etc.\nThis secret should be located within the same namespace as the Envoy proxy resource that references it.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ecdhCurves": {
+ "description": "ECDHCurves specifies the set of supported ECDH curves.\nIn non-FIPS Envoy Proxy builds the default curves are:\n- X25519\n- P-256\nIn builds using BoringSSL FIPS the default curve is:\n- P-256",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "fingerprints": {
+ "description": "Fingerprints specifies TLS client fingerprinting.\nWhen specified, a JAX fingerprint derived from the client\u2019s TLS handshake\nis generated. The fingerprint can be logged in access logs or\nforwarded to upstream services using request headers.\n\nFingerprinting is disabled if not specified.\n\nSupported values are:\n- JA3\n- JA4",
+ "items": {
+ "description": "TLSFingerprintType specifies the TLS client fingerprinting mode.",
+ "enum": [
+ "JA3",
+ "JA4"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "maxVersion": {
+ "description": "Max specifies the maximal TLS protocol version to allow\nThe default is TLS 1.3 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "minVersion": {
+ "description": "Min specifies the minimal TLS protocol version to allow.\nThe default is TLS 1.2 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "signatureAlgorithms": {
+ "description": "SignatureAlgorithms specifies which signature algorithms the listener should\nsupport.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "setting ciphers has no effect if the minimum possible TLS version is 1.3",
+ "rule": "has(self.minVersion) && self.minVersion == '1.3' ? !has(self.ciphers) : true"
+ },
+ {
+ "message": "minVersion must be smaller or equal to maxVersion",
+ "rule": "has(self.minVersion) && has(self.maxVersion) ? {\"Auto\":0,\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4}[self.minVersion] <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : !has(self.minVersion) && has(self.maxVersion) ? 3 <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "bootstrap": {
+ "description": "Bootstrap defines the Envoy Bootstrap as a YAML string.\nVisit https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/bootstrap/v3/bootstrap.proto#envoy-v3-api-msg-config-bootstrap-v3-bootstrap\nto learn more about the syntax.\nIf set, this is the Bootstrap configuration used for the managed Envoy Proxy fleet instead of the default Bootstrap configuration\nset by Envoy Gateway.\nSome fields within the Bootstrap that are required to communicate with the xDS Server (Envoy Gateway) and receive xDS resources\nfrom it are not configurable and will result in the `EnvoyProxy` resource being rejected.\nBackward compatibility across minor versions is not guaranteed.\nWe strongly recommend using `egctl x translate` to generate a `EnvoyProxy` resource with the `Bootstrap` field set to the default\nBootstrap configuration used. You can edit this configuration, and rerun `egctl x translate` to ensure there are no validation errors.",
+ "properties": {
+ "jsonPatches": {
+ "description": "JSONPatches is an array of JSONPatches to be applied to the default bootstrap. Patches are\napplied in the order in which they are defined.",
+ "items": {
+ "description": "JSONPatchOperation defines the JSON Patch Operation as defined in\nhttps://datatracker.ietf.org/doc/html/rfc6902",
+ "properties": {
+ "from": {
+ "description": "From is the source location of the value to be copied or moved. Only valid\nfor move or copy operations\nRefer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.",
+ "type": "string"
+ },
+ "jsonPath": {
+ "description": "JSONPath is a JSONPath expression. Refer to https://datatracker.ietf.org/doc/rfc9535/ for more details.\nIt produces one or more JSONPointer expressions based on the given JSON document.\nIf no JSONPointer is found, it will result in an error.\nIf the 'Path' property is also set, it will be appended to the resulting JSONPointer expressions from the JSONPath evaluation.\nThis is useful when creating a property that does not yet exist in the JSON document.\nThe final JSONPointer expressions specifies the locations in the target document/field where the operation will be applied.",
+ "type": "string"
+ },
+ "op": {
+ "description": "Op is the type of operation to perform",
+ "enum": [
+ "add",
+ "remove",
+ "replace",
+ "move",
+ "copy",
+ "test"
+ ],
+ "type": "string"
+ },
+ "path": {
+ "description": "Path is a JSONPointer expression. Refer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.\nIt specifies the location of the target document/field where the operation will be performed",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the new value of the path location. The value is only used by\nthe `add` and `replace` operations.",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "op"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "type": {
+ "default": "Replace",
+ "description": "Type is the type of the bootstrap configuration, it should be either **Replace**, **Merge**, or **JSONPatch**.\nIf unspecified, it defaults to Replace.",
+ "enum": [
+ "Merge",
+ "Replace",
+ "JSONPatch"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is a YAML string of the bootstrap.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "provided bootstrap patch doesn't match the configured patch type",
+ "rule": "self.type == 'JSONPatch' ? self.jsonPatches.size() > 0 : has(self.value)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "concurrency": {
+ "description": "Concurrency defines the number of worker threads to run. If unset, it defaults to\nthe number of cpuset threads on the platform.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "dynamicModules": {
+ "description": "DynamicModules defines the set of dynamic modules that are allowed to be\nused by EnvoyExtensionPolicy resources and dynamic module load balancer\npolicies. Each entry registers a module by a logical name and specifies\nthe shared library that Envoy will load.\n\nThe EnvoyProxy owner is responsible for ensuring the module .so files are available\non the proxy container's filesystem (e.g., via init containers, custom images,\nor shared volumes).",
+ "items": {
+ "description": "DynamicModuleEntry defines a dynamic module that is registered and allowed\nfor use by EnvoyExtensionPolicy resources.",
+ "properties": {
+ "doNotClose": {
+ "default": false,
+ "description": "DoNotClose prevents the module from being unloaded with dlclose when no\nmore references exist. This is useful for modules that maintain global\nstate that should not be destroyed on configuration updates.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "loadGlobally": {
+ "default": false,
+ "description": "LoadGlobally loads the dynamic module with the RTLD_GLOBAL flag.\nBy default, modules are loaded with RTLD_LOCAL to avoid symbol conflicts.\nSet this to true when the module needs to share symbols with other\ndynamic libraries it loads.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name is the logical name for this module. EnvoyExtensionPolicy resources\nreference modules by this name.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "source": {
+ "description": "Source defines where the dynamic module code is loaded from.",
+ "properties": {
+ "local": {
+ "description": "Local specifies a module loaded from the proxy's local filesystem\nby absolute path.",
+ "properties": {
+ "path": {
+ "description": "Path is the absolute filesystem path to the dynamic module shared library (.so file).",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "remote": {
+ "description": "Remote specifies a module fetched from a remote source.\nThe module binary is downloaded and cached by Envoy.",
+ "properties": {
+ "sha256": {
+ "description": "SHA256 checksum that Envoy will use to verify the downloaded module binary.",
+ "pattern": "^[a-f0-9]{64}$",
+ "type": "string"
+ },
+ "url": {
+ "description": "URL is the HTTP or HTTPS URL of the dynamic module shared library (.so file).",
+ "maxLength": 4096,
+ "minLength": 1,
+ "pattern": "^https?://[^/?#]+(?:[/?#].*)?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "sha256",
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Local",
+ "description": "Type is the type of the source of the dynamic module code.\nDefaults to Local.",
+ "enum": [
+ "Local",
+ "Remote"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If type is Remote, remote field needs to be set.",
+ "rule": "self.type == 'Remote' ? has(self.remote) : !has(self.remote)"
+ },
+ {
+ "message": "If type is Local, local field needs to be set.",
+ "rule": "self.type != 'Local' || has(self.local)"
+ },
+ {
+ "message": "If type is Remote, local field must not be set.",
+ "rule": "self.type == 'Remote' ? !has(self.local) : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "source"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "extraArgs": {
+ "description": "ExtraArgs defines additional command line options that are provided to Envoy.\nMore info: https://www.envoyproxy.io/docs/envoy/latest/operations/cli#command-line-options\nNote: some command line options are used internally(e.g. --log-level) so they cannot be provided here.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "filterOrder": {
+ "description": "FilterOrder defines the order of filters in the Envoy proxy's HTTP filter chain.\nThe FilterPosition in the list will be applied in the order they are defined.\nIf unspecified, the default filter order is applied.\nDefault filter order is:\n\n- envoy.filters.http.custom_response\n\n- envoy.filters.http.health_check\n\n- envoy.filters.http.fault\n\n- envoy.filters.http.cors\n\n- envoy.filters.http.header_mutation\n\n- envoy.filters.http.ext_authz\n\n- envoy.filters.http.api_key_auth\n\n- envoy.filters.http.basic_auth\n\n- envoy.filters.http.oauth2\n\n- envoy.filters.http.jwt_authn\n\n- envoy.filters.http.stateful_session\n\n- envoy.filters.http.buffer\n\n- envoy.filters.http.lua\n\n- envoy.filters.http.ext_proc\n\n- envoy.filters.http.wasm\n\n- envoy.filters.http.dynamic_modules\n\n- envoy.filters.http.geoip\n\n- envoy.filters.http.rbac\n\n- envoy.filters.http.local_ratelimit\n\n- envoy.filters.http.ratelimit\n\n- envoy.filters.http.bandwidth_limit\n\n- envoy.filters.http.grpc_web\n\n- envoy.filters.http.grpc_stats\n\n- envoy.filters.http.credential_injector\n\n- envoy.filters.http.compressor\n\n- envoy.filters.http.dynamic_forward_proxy\n\n- envoy.filters.http.router\n\nNote: \"envoy.filters.http.router\" cannot be reordered, it's always the last filter in the chain.",
+ "items": {
+ "description": "FilterPosition defines the position of an Envoy HTTP filter in the filter chain.",
+ "properties": {
+ "after": {
+ "description": "After defines the filter that should come after the filter.\nOnly one of Before or After must be set.",
+ "enum": [
+ "envoy.filters.http.custom_response",
+ "envoy.filters.http.health_check",
+ "envoy.filters.http.fault",
+ "envoy.filters.http.cors",
+ "envoy.filters.http.header_mutation",
+ "envoy.filters.http.ext_authz",
+ "envoy.filters.http.api_key_auth",
+ "envoy.filters.http.basic_auth",
+ "envoy.filters.http.oauth2",
+ "envoy.filters.http.jwt_authn",
+ "envoy.filters.http.stateful_session",
+ "envoy.filters.http.buffer",
+ "envoy.filters.http.lua",
+ "envoy.filters.http.ext_proc",
+ "envoy.filters.http.wasm",
+ "envoy.filters.http.dynamic_modules",
+ "envoy.filters.http.geoip",
+ "envoy.filters.http.rbac",
+ "envoy.filters.http.local_ratelimit",
+ "envoy.filters.http.ratelimit",
+ "envoy.filters.http.bandwidth_limit",
+ "envoy.filters.http.grpc_web",
+ "envoy.filters.http.grpc_stats",
+ "envoy.filters.http.credential_injector",
+ "envoy.filters.http.compressor",
+ "envoy.filters.http.dynamic_forward_proxy"
+ ],
+ "type": "string"
+ },
+ "before": {
+ "description": "Before defines the filter that should come before the filter.\nOnly one of Before or After must be set.",
+ "enum": [
+ "envoy.filters.http.custom_response",
+ "envoy.filters.http.health_check",
+ "envoy.filters.http.fault",
+ "envoy.filters.http.cors",
+ "envoy.filters.http.header_mutation",
+ "envoy.filters.http.ext_authz",
+ "envoy.filters.http.api_key_auth",
+ "envoy.filters.http.basic_auth",
+ "envoy.filters.http.oauth2",
+ "envoy.filters.http.jwt_authn",
+ "envoy.filters.http.stateful_session",
+ "envoy.filters.http.buffer",
+ "envoy.filters.http.lua",
+ "envoy.filters.http.ext_proc",
+ "envoy.filters.http.wasm",
+ "envoy.filters.http.dynamic_modules",
+ "envoy.filters.http.geoip",
+ "envoy.filters.http.rbac",
+ "envoy.filters.http.local_ratelimit",
+ "envoy.filters.http.ratelimit",
+ "envoy.filters.http.bandwidth_limit",
+ "envoy.filters.http.grpc_web",
+ "envoy.filters.http.grpc_stats",
+ "envoy.filters.http.credential_injector",
+ "envoy.filters.http.compressor",
+ "envoy.filters.http.dynamic_forward_proxy"
+ ],
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the filter.",
+ "enum": [
+ "envoy.filters.http.custom_response",
+ "envoy.filters.http.health_check",
+ "envoy.filters.http.fault",
+ "envoy.filters.http.cors",
+ "envoy.filters.http.header_mutation",
+ "envoy.filters.http.ext_authz",
+ "envoy.filters.http.api_key_auth",
+ "envoy.filters.http.basic_auth",
+ "envoy.filters.http.oauth2",
+ "envoy.filters.http.jwt_authn",
+ "envoy.filters.http.stateful_session",
+ "envoy.filters.http.buffer",
+ "envoy.filters.http.lua",
+ "envoy.filters.http.ext_proc",
+ "envoy.filters.http.wasm",
+ "envoy.filters.http.dynamic_modules",
+ "envoy.filters.http.geoip",
+ "envoy.filters.http.rbac",
+ "envoy.filters.http.local_ratelimit",
+ "envoy.filters.http.ratelimit",
+ "envoy.filters.http.bandwidth_limit",
+ "envoy.filters.http.grpc_web",
+ "envoy.filters.http.grpc_stats",
+ "envoy.filters.http.credential_injector",
+ "envoy.filters.http.compressor",
+ "envoy.filters.http.dynamic_forward_proxy"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "one of before or after must be specified",
+ "rule": "(has(self.before) || has(self.after))"
+ },
+ {
+ "message": "only one of before or after can be specified",
+ "rule": "(has(self.before) && !has(self.after)) || (!has(self.before) && has(self.after))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "geoIP": {
+ "description": "GeoIP defines shared GeoIP provider configuration for this EnvoyProxy fleet.",
+ "properties": {
+ "provider": {
+ "description": "Provider defines the GeoIP provider configuration used by GeoIP filter instances.",
+ "properties": {
+ "maxMind": {
+ "description": "MaxMind configures the MaxMind provider.",
+ "properties": {
+ "anonymousIpDbSource": {
+ "description": "AnonymousIPDBSource configures the Anonymous IP database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "asnDbSource": {
+ "description": "ASNDBSource configures the ASN database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cityDbSource": {
+ "description": "CityDBSource configures the City database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "countryDbSource": {
+ "description": "CountryDBSource configures the Country database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ispDbSource": {
+ "description": "ISPDBSource configures the ISP database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one MaxMind database source must be specified",
+ "rule": "has(self.cityDbSource) || has(self.countryDbSource) || has(self.asnDbSource) || has(self.ispDbSource) || has(self.anonymousIpDbSource)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "GeoIPProviderType enumerates GeoIP providers supported by Envoy Gateway.",
+ "enum": [
+ "MaxMind"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "maxMind must be set when type is MaxMind",
+ "rule": "self.type == 'MaxMind' ? has(self.maxMind) : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipFamily": {
+ "description": "IPFamily specifies the IP family for the EnvoyProxy fleet.\nThis setting only affects the Gateway listener port and does not impact\nother aspects of the Envoy proxy configuration.\nIf not specified, the system will operate as follows:\n- It defaults to IPv4 only.\n- IPv6 and dual-stack environments are not supported in this default configuration.\nNote: To enable IPv6 or dual-stack functionality, explicit configuration is required.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "DualStack"
+ ],
+ "type": "string"
+ },
+ "logging": {
+ "default": {
+ "level": {
+ "default": "warn"
+ }
+ },
+ "description": "Logging defines logging parameters for managed proxies.",
+ "properties": {
+ "level": {
+ "additionalProperties": {
+ "description": "LogLevel defines a log level for Envoy Gateway and EnvoyProxy system logs.",
+ "enum": [
+ "trace",
+ "debug",
+ "info",
+ "warn",
+ "error"
+ ],
+ "type": "string"
+ },
+ "default": {
+ "default": "warn"
+ },
+ "description": "Level is a map of logging level per component, where the component is the key\nand the log level is the value. If unspecified, defaults to \"default: warn\".",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "luaValidation": {
+ "description": "LuaValidation determines strictness of the Lua script validation for Lua EnvoyExtensionPolicies\nDefault: Strict",
+ "enum": [
+ "Strict",
+ "InsecureSyntax",
+ "Disabled"
+ ],
+ "type": "string"
+ },
+ "mergeGateways": {
+ "description": "MergeGateways defines if Gateway resources should be merged onto the same Envoy Proxy Infrastructure.\nSetting this field to true would merge all Gateway Listeners under the parent Gateway Class.\nThis means that the port, protocol and hostname tuple must be unique for every listener.\nIf a duplicate listener is detected, the newer listener (based on timestamp) will be rejected and its status will be updated with a \"Accepted=False\" condition.",
+ "type": "boolean"
+ },
+ "mergeType": {
+ "description": "MergeType controls how this EnvoyProxy merges with less specific configurations\nin the hierarchy (EnvoyGateway defaults < GatewayClass < Gateway).\nIf unset, this EnvoyProxy completely replaces less specific settings.\nNote: this field has no effect when set in EnvoyGateway's default EnvoyProxySpec.",
+ "enum": [
+ "Replace",
+ "StrategicMerge",
+ "JSONMerge"
+ ],
+ "type": "string"
+ },
+ "preserveRouteOrder": {
+ "description": "PreserveRouteOrder determines if the order of matching for HTTPRoutes is determined by Gateway-API\nspecification (https://gateway-api.sigs.k8s.io/reference/1.4/spec/#httprouterule)\nor preserves the order defined by users in the HTTPRoute's HTTPRouteRule list.\nDefault: False",
+ "type": "boolean"
+ },
+ "provider": {
+ "description": "Provider defines the desired resource provider and provider-specific configuration.\nIf unspecified, the \"Kubernetes\" resource provider is used with default configuration\nparameters.",
+ "properties": {
+ "host": {
+ "description": "Host provides runtime deployment of the data plane as a child process on the\nhost environment.\nIf unspecified and type is \"Host\", default settings for the custom provider\nare applied.",
+ "properties": {
+ "envoyVersion": {
+ "description": "EnvoyVersion is the version of Envoy to use. If unspecified, the version\nagainst which Envoy Gateway is built will be used.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "kubernetes": {
+ "description": "Kubernetes defines the desired state of the Kubernetes resource provider.\nKubernetes provides infrastructure resources for running the data plane,\ne.g. Envoy proxy. If unspecified and type is \"Kubernetes\", default settings\nfor managed Kubernetes resources are applied.",
+ "properties": {
+ "envoyDaemonSet": {
+ "description": "EnvoyDaemonSet defines the desired state of the Envoy daemonset resource.\nDisabled by default, a deployment resource is used instead to provision the Envoy Proxy fleet",
+ "properties": {
+ "container": {
+ "description": "Container defines the desired specification of main container.",
+ "properties": {
+ "env": {
+ "description": "List of environment variables to set in the container.",
+ "items": {
+ "description": "EnvVar represents an environment variable present in a Container.",
+ "properties": {
+ "name": {
+ "description": "Name of the environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Variable references $(VAR_NAME) are expanded\nusing the previously defined environment variables in the container and\nany service environment variables. If a variable cannot be resolved,\nthe reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.\n\"$$(VAR_NAME)\" will produce the string literal \"$(VAR_NAME)\".\nEscaped references will never be expanded, regardless of whether the variable\nexists or not.\nDefaults to \"\".",
+ "type": "string"
+ },
+ "valueFrom": {
+ "description": "Source for the environment variable's value. Cannot be used if value is not empty.",
+ "properties": {
+ "configMapKeyRef": {
+ "description": "Selects a key of a ConfigMap.",
+ "properties": {
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fieldRef": {
+ "description": "Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`,\nspec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fileKeyRef": {
+ "description": "FileKeyRef selects a key of the env file.\nRequires the EnvFiles feature gate to be enabled.",
+ "properties": {
+ "key": {
+ "description": "The key within the env file. An invalid key will prevent the pod from starting.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nDuring Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.",
+ "type": "string"
+ },
+ "optional": {
+ "default": false,
+ "description": "Specify whether the file or its key must be defined. If the file or key\ndoes not exist, then the env var is not published.\nIf optional is set to true and the specified key does not exist,\nthe environment variable will not be set in the Pod's containers.\n\nIf optional is set to false and the specified key does not exist,\nan error will be returned during Pod creation.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "The path within the volume from which to select the file.\nMust be relative and may not contain the '..' path or start with '..'.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "The name of the volume mount containing the env file.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path",
+ "volumeName"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "secretKeyRef": {
+ "description": "Selects a key of a secret in the pod's namespace",
+ "properties": {
+ "key": {
+ "description": "The key of the secret to select from. Must be a valid secret key.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "image": {
+ "description": "Image specifies the EnvoyProxy container image to be used including a tag, instead of the default image.\nThis field is mutually exclusive with ImageRepository.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Image must include a tag and allowed characters only (e.g., 'repo:tag').",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?(/[a-zA-Z0-9._/-]+)?(:[a-zA-Z0-9._-]+)?(@sha256:[a-z0-9]+)?$')"
+ }
+ ]
+ },
+ "imageRepository": {
+ "description": "ImageRepository specifies the container image repository to be used without specifying a tag.\nThe default tag will be used.\nThis field is mutually exclusive with Image.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "ImageRepository must contain only allowed characters and must not include a tag.",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?[a-zA-Z0-9._/-]+$')"
+ }
+ ]
+ },
+ "resources": {
+ "description": "Resources required by this container.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "securityContext": {
+ "description": "SecurityContext defines the security options the container should be run with.\nIf set, the fields of SecurityContext override the equivalent fields of PodSecurityContext.\nMore info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/",
+ "properties": {
+ "allowPrivilegeEscalation": {
+ "description": "AllowPrivilegeEscalation controls whether a process can gain more\nprivileges than its parent process. This bool directly controls if\nthe no_new_privs flag will be set on the container process.\nAllowPrivilegeEscalation is true always when the container is:\n1) run as Privileged\n2) has CAP_SYS_ADMIN\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by this container. If set, this profile\noverrides the pod's appArmorProfile.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "capabilities": {
+ "description": "The capabilities to add/drop when running containers.\nDefaults to the default set of capabilities granted by the container runtime.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "add": {
+ "description": "Added capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "drop": {
+ "description": "Removed capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "privileged": {
+ "description": "Run container in privileged mode.\nProcesses in privileged containers are essentially equivalent to root on the host.\nDefaults to false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "procMount": {
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "readOnlyRootFilesystem": {
+ "description": "Whether this container has a read-only root filesystem.\nDefault is false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to the container.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by this container. If seccomp options are\nprovided at both the pod & container level, the container options\noverride the pod options.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options from the PodSecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "volumeMounts": {
+ "description": "VolumeMounts are volumes to mount into the container's filesystem.\nCannot be updated.",
+ "items": {
+ "description": "VolumeMount describes a mounting of a Volume within a container.",
+ "properties": {
+ "mountPath": {
+ "description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
+ "type": "string"
+ },
+ "mountPropagation": {
+ "description": "mountPropagation determines how mounts are propagated from the host\nto container and the other way around.\nWhen not set, MountPropagationNone is used.\nThis field is beta in 1.10.\nWhen RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified\n(which defaults to None).",
+ "type": "string"
+ },
+ "name": {
+ "description": "This must match the Name of a Volume.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "Mounted read-only if true, read-write otherwise (false or unspecified).\nDefaults to false.",
+ "type": "boolean"
+ },
+ "recursiveReadOnly": {
+ "description": "RecursiveReadOnly specifies whether read-only mounts should be handled\nrecursively.\n\nIf ReadOnly is false, this field has no meaning and must be unspecified.\n\nIf ReadOnly is true, and this field is set to Disabled, the mount is not made\nrecursively read-only. If this field is set to IfPossible, the mount is made\nrecursively read-only, if it is supported by the container runtime. If this\nfield is set to Enabled, the mount is made recursively read-only if it is\nsupported by the container runtime, otherwise the pod will not be started and\nan error will be generated to indicate the reason.\n\nIf this field is set to IfPossible or Enabled, MountPropagation must be set to\nNone (or be unspecified, which defaults to None).\n\nIf this field is not specified, it is treated as an equivalent of Disabled.",
+ "type": "string"
+ },
+ "subPath": {
+ "description": "Path within the volume from which the container's volume should be mounted.\nDefaults to \"\" (volume's root).",
+ "type": "string"
+ },
+ "subPathExpr": {
+ "description": "Expanded path within the volume from which the container's volume should be mounted.\nBehaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.\nDefaults to \"\" (volume's root).\nSubPathExpr and SubPath are mutually exclusive.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "mountPath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Either image or imageRepository can be set.",
+ "rule": "!has(self.image) || !has(self.imageRepository)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Name of the daemonSet.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to daemonset",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pod": {
+ "description": "Pod defines the desired specification of pod.",
+ "properties": {
+ "affinity": {
+ "description": "If specified, the pod's scheduling constraints.",
+ "properties": {
+ "nodeAffinity": {
+ "description": "Describes node affinity scheduling rules for the pod.",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node matches the corresponding matchExpressions; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "An empty preferred scheduling term matches all objects with implicit weight 0\n(i.e. it's a no-op). A null preferred scheduling term matches no objects (i.e. is also a no-op).",
+ "properties": {
+ "preference": {
+ "description": "A node selector term, associated with the corresponding weight.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "Weight associated with matching the corresponding nodeSelectorTerm, in the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "preference",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to an update), the system\nmay or may not try to eventually evict the pod from its node.",
+ "properties": {
+ "nodeSelectorTerms": {
+ "description": "Required. A list of node selector terms. The terms are ORed.",
+ "items": {
+ "description": "A null or empty node selector term matches no objects. The requirements of\nthem are ANDed.\nThe TopologySelectorTerm type implements a subset of the NodeSelectorTerm.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "nodeSelectorTerms"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAffinity": {
+ "description": "Describes pod affinity scheduling rules (e.g. co-locate this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAntiAffinity": {
+ "description": "Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe anti-affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling anti-affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and subtracting\n\"weight\" from the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the anti-affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the anti-affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "annotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Annotations are the annotations that should be appended to the pods.\nBy default, no pod annotations are appended.",
+ "type": "object"
+ },
+ "imagePullSecrets": {
+ "description": "ImagePullSecrets is an optional list of references to secrets\nin the same namespace to use for pulling any of the images used by this PodSpec.\nIf specified, these secrets will be passed to individual puller implementations for them to use.\nMore info: https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod",
+ "items": {
+ "description": "LocalObjectReference contains enough information to let you locate the\nreferenced object inside the same namespace.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "labels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Labels are the additional labels that should be tagged to the pods.\nBy default, no additional pod labels are tagged.",
+ "type": "object"
+ },
+ "nodeSelector": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "NodeSelector is a selector which must be true for the pod to fit on a node.\nSelector which must match a node's labels for the pod to be scheduled on that node.\nMore info: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/",
+ "type": "object"
+ },
+ "priorityClassName": {
+ "description": "PriorityClassName indicates the importance of a Pod relative to other Pods.\nIf a PriorityClassName is not specified, the pod priority will be default or zero if there is no default.\nMore info: https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/",
+ "type": "string"
+ },
+ "securityContext": {
+ "description": "SecurityContext holds pod-level security attributes and common container settings.\nOptional: Defaults to empty. See type description for default values of each field.",
+ "properties": {
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fsGroup": {
+ "description": "A special supplemental group that applies to all containers in a pod.\nSome volume types allow the Kubelet to change the ownership of that volume\nto be owned by the pod:\n\n1. The owning GID will be the FSGroup\n2. The setgid bit is set (new files created in the volume will be owned by FSGroup)\n3. The permission bits are OR'd with rw-rw----\n\nIf unset, the Kubelet will not modify the ownership and permissions of any volume.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "fsGroupChangePolicy": {
+ "description": "fsGroupChangePolicy defines behavior of changing ownership and permission of the volume\nbefore being exposed inside Pod. This field will only apply to\nvolume types which support fsGroup based ownership(and permissions).\nIt will have no effect on ephemeral volume types such as: secret, configmaps\nand emptydir.\nValid values are \"OnRootMismatch\" and \"Always\". If not specified, \"Always\" is used.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxChangePolicy": {
+ "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to all containers.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in SecurityContext. If set in\nboth SecurityContext and PodSecurityContext, the value specified in SecurityContext\ntakes precedence for that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "supplementalGroups": {
+ "description": "A list of groups applied to the first process run in each container, in\naddition to the container's primary GID and fsGroup (if specified). If\nthe SupplementalGroupsPolicy feature is enabled, the\nsupplementalGroupsPolicy field determines whether these are in addition\nto or instead of any group memberships defined in the container image.\nIf unspecified, no additional groups are added, though group memberships\ndefined in the container image may still be used, depending on the\nsupplementalGroupsPolicy field.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "format": "int64",
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "supplementalGroupsPolicy": {
+ "description": "Defines how supplemental groups of the first container processes are calculated.\nValid values are \"Merge\" and \"Strict\". If not specified, \"Merge\" is used.\n(Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled\nand the container runtime must implement support for this feature.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "sysctls": {
+ "description": "Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported\nsysctls (by the container runtime) might fail to launch.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "description": "Sysctl defines a kernel parameter to be set",
+ "properties": {
+ "name": {
+ "description": "Name of a property to set",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of a property to set",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options within a container's SecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tolerations": {
+ "description": "If specified, the pod's tolerations.",
+ "items": {
+ "description": "The pod this Toleration is attached to tolerates any taint that matches\nthe triple using the matching operator .",
+ "properties": {
+ "effect": {
+ "description": "Effect indicates the taint effect to match. Empty means match all taint effects.\nWhen specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.",
+ "type": "string"
+ },
+ "key": {
+ "description": "Key is the taint key that the toleration applies to. Empty means match all taint keys.\nIf the key is empty, operator must be Exists; this combination means to match all values and all keys.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Operator represents a key's relationship to the value.\nValid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.\nExists is equivalent to wildcard for value, so that a pod can\ntolerate all taints of a particular category.\nLt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).",
+ "type": "string"
+ },
+ "tolerationSeconds": {
+ "description": "TolerationSeconds represents the period of time the toleration (which must be\nof effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,\nit is not set, which means tolerate the taint forever (do not evict). Zero and\nnegative values will be treated as 0 (evict immediately) by the system.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "value": {
+ "description": "Value is the taint value the toleration matches to.\nIf the operator is Exists, the value should be empty, otherwise just a regular string.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "topologySpreadConstraints": {
+ "description": "TopologySpreadConstraints describes how a group of pods ought to spread across topology\ndomains. Scheduler will schedule pods in a way which abides by the constraints.\nAll topologySpreadConstraints are ANDed.",
+ "items": {
+ "description": "TopologySpreadConstraint specifies how to spread matching pods among the given topology.",
+ "properties": {
+ "labelSelector": {
+ "description": "LabelSelector is used to find matching pods.\nPods that match this label selector are counted to determine the number of pods\nin their corresponding topology domain.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select the pods over which\nspreading will be calculated. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are ANDed with labelSelector\nto select the group of existing pods over which spreading will be calculated\nfor the incoming pod. The same key is forbidden to exist in both MatchLabelKeys and LabelSelector.\nMatchLabelKeys cannot be set when LabelSelector isn't set.\nKeys that don't exist in the incoming pod labels will\nbe ignored. A null or empty list means only match against labelSelector.\n\nThis is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate to be enabled (enabled by default).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "maxSkew": {
+ "description": "MaxSkew describes the degree to which pods may be unevenly distributed.\nWhen `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference\nbetween the number of matching pods in the target topology and the global minimum.\nThe global minimum is the minimum number of matching pods in an eligible domain\nor zero if the number of eligible domains is less than MinDomains.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 2/2/1:\nIn this case, the global minimum is 1.\n| zone1 | zone2 | zone3 |\n| P P | P P | P |\n- if MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2;\nscheduling it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2)\nviolate MaxSkew(1).\n- if MaxSkew is 2, incoming pod can be scheduled onto any zone.\nWhen `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence\nto topologies that satisfy it.\nIt's a required field. Default value is 1 and 0 is not allowed.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "minDomains": {
+ "description": "MinDomains indicates a minimum number of eligible domains.\nWhen the number of eligible domains with matching topology keys is less than minDomains,\nPod Topology Spread treats \"global minimum\" as 0, and then the calculation of Skew is performed.\nAnd when the number of eligible domains with matching topology keys equals or greater than minDomains,\nthis value has no effect on scheduling.\nAs a result, when the number of eligible domains is less than minDomains,\nscheduler won't schedule more than maxSkew Pods to those domains.\nIf value is nil, the constraint behaves as if MinDomains is equal to 1.\nValid values are integers greater than 0.\nWhen value is not nil, WhenUnsatisfiable must be DoNotSchedule.\n\nFor example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and pods with the same\nlabelSelector spread as 2/2/2:\n| zone1 | zone2 | zone3 |\n| P P | P P | P P |\nThe number of domains is less than 5(MinDomains), so \"global minimum\" is treated as 0.\nIn this situation, new pod with the same labelSelector cannot be scheduled,\nbecause computed skew will be 3(3 - 0) if new Pod is scheduled to any of the three zones,\nit will violate MaxSkew.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "nodeAffinityPolicy": {
+ "description": "NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector\nwhen calculating pod topology spread skew. Options are:\n- Honor: only nodes matching nodeAffinity/nodeSelector are included in the calculations.\n- Ignore: nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.\n\nIf this value is nil, the behavior is equivalent to the Honor policy.",
+ "type": "string"
+ },
+ "nodeTaintsPolicy": {
+ "description": "NodeTaintsPolicy indicates how we will treat node taints when calculating\npod topology spread skew. Options are:\n- Honor: nodes without taints, along with tainted nodes for which the incoming pod\nhas a toleration, are included.\n- Ignore: node taints are ignored. All nodes are included.\n\nIf this value is nil, the behavior is equivalent to the Ignore policy.",
+ "type": "string"
+ },
+ "topologyKey": {
+ "description": "TopologyKey is the key of node labels. Nodes that have a label with this key\nand identical values are considered to be in the same topology.\nWe consider each as a \"bucket\", and try to put balanced number\nof pods into each bucket.\nWe define a domain as a particular instance of a topology.\nAlso, we define an eligible domain as a domain whose nodes meet the requirements of\nnodeAffinityPolicy and nodeTaintsPolicy.\ne.g. If TopologyKey is \"kubernetes.io/hostname\", each Node is a domain of that topology.\nAnd, if TopologyKey is \"topology.kubernetes.io/zone\", each zone is a domain of that topology.\nIt's a required field.",
+ "type": "string"
+ },
+ "whenUnsatisfiable": {
+ "description": "WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy\nthe spread constraint.\n- DoNotSchedule (default) tells the scheduler not to schedule it.\n- ScheduleAnyway tells the scheduler to schedule the pod in any location,\n but giving higher precedence to topologies that would help reduce the\n skew.\nA constraint is considered \"Unsatisfiable\" for an incoming pod\nif and only if every possible node assignment for that pod would violate\n\"MaxSkew\" on some topology.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 3/1/1:\n| zone1 | zone2 | zone3 |\n| P P P | P | P |\nIf WhenUnsatisfiable is set to DoNotSchedule, incoming pod can only be scheduled\nto zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies\nMaxSkew(1). In other words, the cluster can still be imbalanced, but scheduler\nwon't make it *more* imbalanced.\nIt's a required field.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "maxSkew",
+ "topologyKey",
+ "whenUnsatisfiable"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "volumes": {
+ "description": "Volumes that can be mounted by containers belonging to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes",
+ "items": {
+ "description": "Volume represents a named volume in a pod that may be accessed by any container in the pod.",
+ "properties": {
+ "awsElasticBlockStore": {
+ "description": "awsElasticBlockStore represents an AWS Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: AWSElasticBlockStore is deprecated. All operations for the in-tree\nawsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly value true will force the readOnly setting in VolumeMounts.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureDisk": {
+ "description": "azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.\nDeprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type\nare redirected to the disk.csi.azure.com CSI driver.",
+ "properties": {
+ "cachingMode": {
+ "description": "cachingMode is the Host Caching mode: None, Read Only, Read Write.",
+ "type": "string"
+ },
+ "diskName": {
+ "description": "diskName is the Name of the data disk in the blob storage",
+ "type": "string"
+ },
+ "diskURI": {
+ "description": "diskURI is the URI of data disk in the blob storage",
+ "type": "string"
+ },
+ "fsType": {
+ "default": "ext4",
+ "description": "fsType is Filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "kind expected values are Shared: multiple blob disks per storage account Dedicated: single blob disk per storage account Managed: azure managed data disk (only in managed availability set). defaults to shared",
+ "type": "string"
+ },
+ "readOnly": {
+ "default": false,
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "diskName",
+ "diskURI"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureFile": {
+ "description": "azureFile represents an Azure File Service mount on the host and bind mount to the pod.\nDeprecated: AzureFile is deprecated. All operations for the in-tree azureFile type\nare redirected to the file.csi.azure.com CSI driver.",
+ "properties": {
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of secret that contains Azure Storage Account Name and Key",
+ "type": "string"
+ },
+ "shareName": {
+ "description": "shareName is the azure share Name",
+ "type": "string"
+ }
+ },
+ "required": [
+ "secretName",
+ "shareName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cephfs": {
+ "description": "cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.\nDeprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.",
+ "properties": {
+ "monitors": {
+ "description": "monitors is Required: Monitors is a collection of Ceph monitors\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretFile": {
+ "description": "secretFile is Optional: SecretFile is the path to key ring for User, default is /etc/ceph/user.secret\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: SecretRef is reference to the authentication secret for User, default is empty.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "description": "user is optional: User is the rados user name, default is admin\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cinder": {
+ "description": "cinder represents a cinder volume attached and mounted on kubelets host machine.\nDeprecated: Cinder is deprecated. All operations for the in-tree cinder type\nare redirected to the cinder.csi.openstack.org CSI driver.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is optional: points to a secret object containing parameters used to connect\nto OpenStack.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeID": {
+ "description": "volumeID used to identify the volume in cinder.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap represents a configMap that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "csi": {
+ "description": "csi (Container Storage Interface) represents ephemeral storage that is handled by certain external CSI drivers.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the CSI driver that handles this volume.\nConsult with your admin for the correct name as registered in the cluster.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType to mount. Ex. \"ext4\", \"xfs\", \"ntfs\".\nIf not provided, the empty value is passed to the associated CSI driver\nwhich will determine the default filesystem to apply.",
+ "type": "string"
+ },
+ "nodePublishSecretRef": {
+ "description": "nodePublishSecretRef is a reference to the secret object containing\nsensitive information to pass to the CSI driver to complete the CSI\nNodePublishVolume and NodeUnpublishVolume calls.\nThis field is optional, and may be empty if no secret is required. If the\nsecret object contains more than one secret, all secret references are passed.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "readOnly": {
+ "description": "readOnly specifies a read-only configuration for the volume.\nDefaults to false (read/write).",
+ "type": "boolean"
+ },
+ "volumeAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "volumeAttributes stores driver-specific properties that are passed to the CSI\ndriver. Consult your driver's documentation for supported values.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI represents downward API about the pod that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "Optional: mode bits to use on created files by default. Must be a\nOptional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "Items is a list of downward API volume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emptyDir": {
+ "description": "emptyDir represents a temporary directory that shares a pod's lifetime.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "properties": {
+ "medium": {
+ "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "type": "string"
+ },
+ "sizeLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "sizeLimit is the total amount of local storage required for this EmptyDir volume.\nThe size limit is also applicable for memory medium.\nThe maximum usage on memory medium EmptyDir would be the minimum value between\nthe SizeLimit specified here and the sum of memory limits of all containers in a pod.\nThe default is nil which means that the limit is undefined.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ephemeral": {
+ "description": "ephemeral represents a volume that is handled by a cluster storage driver.\nThe volume's lifecycle is tied to the pod that defines it - it will be created before the pod starts,\nand deleted when the pod is removed.\n\nUse this if:\na) the volume is only needed while the pod runs,\nb) features of normal volumes like restoring from snapshot or capacity\n tracking are needed,\nc) the storage driver is specified through a storage class, and\nd) the storage driver supports dynamic volume provisioning through\n a PersistentVolumeClaim (see EphemeralVolumeSource for more\n information on the connection between this volume type\n and PersistentVolumeClaim).\n\nUse PersistentVolumeClaim or one of the vendor-specific\nAPIs for volumes that persist for longer than the lifecycle\nof an individual pod.\n\nUse CSI for light-weight local ephemeral volumes if the CSI driver is meant to\nbe used that way - see the documentation of the driver for\nmore information.\n\nA pod can use both types of ephemeral volumes and\npersistent volumes at the same time.",
+ "properties": {
+ "volumeClaimTemplate": {
+ "description": "Will be used to create a stand-alone PVC to provision the volume.\nThe pod in which this EphemeralVolumeSource is embedded will be the\nowner of the PVC, i.e. the PVC will be deleted together with the\npod. The name of the PVC will be `-` where\n`` is the name from the `PodSpec.Volumes` array\nentry. Pod validation will reject the pod if the concatenated name\nis not valid for a PVC (for example, too long).\n\nAn existing PVC with that name that is not owned by the pod\nwill *not* be used for the pod to avoid using an unrelated\nvolume by mistake. Starting the pod is then blocked until\nthe unrelated PVC is removed. If such a pre-created PVC is\nmeant to be used by the pod, the PVC has to updated with an\nowner reference to the pod once the pod exists. Normally\nthis should not be necessary, but it may be useful when\nmanually reconstructing a broken cluster.\n\nThis field is read-only and no changes will be made by Kubernetes\nto the PVC after it has been created.\n\nRequired, must not be nil.",
+ "properties": {
+ "metadata": {
+ "description": "May contain labels and annotations that will be copied into the PVC\nwhen creating it. No other fields are allowed and will be rejected during\nvalidation.",
+ "type": "object"
+ },
+ "spec": {
+ "description": "The specification for the PersistentVolumeClaim. The entire content is\ncopied unchanged into the PVC that gets created from this\ntemplate. The same fields as in a PersistentVolumeClaim\nare also valid here.",
+ "properties": {
+ "accessModes": {
+ "description": "accessModes contains the desired access modes the volume should have.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "dataSource": {
+ "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "dataSourceRef": {
+ "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of resource being referenced\nNote that when a namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is required in the referent namespace to allow that namespace's owner to accept the reference. See the ReferenceGrant documentation for details.\n(Alpha) This field requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resources": {
+ "description": "resources represents the minimum resources the volume should have.\nUsers are allowed to specify resource requirements\nthat are lower than previous value but must still be higher than capacity recorded in the\nstatus field of the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources",
+ "properties": {
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "selector": {
+ "description": "selector is a label query over volumes to consider for binding.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "storageClassName": {
+ "description": "storageClassName is the name of the StorageClass required by the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1",
+ "type": "string"
+ },
+ "volumeAttributesClassName": {
+ "description": "volumeAttributesClassName may be used to set the VolumeAttributesClass used by this claim.\nIf specified, the CSI driver will create or update the volume with the attributes defined\nin the corresponding VolumeAttributesClass. This has a different purpose than storageClassName,\nit can be changed after the claim is created. An empty string or nil value indicates that no\nVolumeAttributesClass will be applied to the claim. If the claim enters an Infeasible error state,\nthis field can be reset to its previous value (including nil) to cancel the modification.\nIf the resource referred to by volumeAttributesClass does not exist, this PersistentVolumeClaim will be\nset to a Pending state, as reflected by the modifyVolumeStatus field, until such as a resource\nexists.\nMore info: https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/",
+ "type": "string"
+ },
+ "volumeMode": {
+ "description": "volumeMode defines what type of volume is required by the claim.\nValue of Filesystem is implied when not included in claim spec.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the binding reference to the PersistentVolume backing this claim.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fc": {
+ "description": "fc represents a Fibre Channel resource that is attached to a kubelet's host machine and then exposed to the pod.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun is Optional: FC target lun number",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "targetWWNs": {
+ "description": "targetWWNs is Optional: FC target worldwide names (WWNs)",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "wwids": {
+ "description": "wwids Optional: FC volume world wide identifiers (wwids)\nEither wwids or combination of targetWWNs and lun must be set, but not both simultaneously.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flexVolume": {
+ "description": "flexVolume represents a generic volume resource that is\nprovisioned/attached using an exec based plugin.\nDeprecated: FlexVolume is deprecated. Consider using a CSIDriver instead.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the driver to use for this volume.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". The default filesystem depends on FlexVolume script.",
+ "type": "string"
+ },
+ "options": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "options is Optional: this field holds extra command options if any.",
+ "type": "object"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: secretRef is reference to the secret object containing\nsensitive information to pass to the plugin scripts. This may be\nempty if no secret object is specified. If the secret object\ncontains more than one secret, all secrets are passed to the plugin\nscripts.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flocker": {
+ "description": "flocker represents a Flocker volume attached to a kubelet's host machine. This depends on the Flocker control service being running.\nDeprecated: Flocker is deprecated and the in-tree flocker type is no longer supported.",
+ "properties": {
+ "datasetName": {
+ "description": "datasetName is Name of the dataset stored as metadata -> name on the dataset for Flocker\nshould be considered as deprecated",
+ "type": "string"
+ },
+ "datasetUUID": {
+ "description": "datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker dataset",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gcePersistentDisk": {
+ "description": "gcePersistentDisk represents a GCE Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: GCEPersistentDisk is deprecated. All operations for the in-tree\ngcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "format": "int32",
+ "type": "integer"
+ },
+ "pdName": {
+ "description": "pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "pdName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gitRepo": {
+ "description": "gitRepo represents a git repository at a particular revision.\nDeprecated: GitRepo is deprecated. To provision a container with a git repo, mount an\nEmptyDir into an InitContainer that clones the repo using git, then mount the EmptyDir\ninto the Pod's container.",
+ "properties": {
+ "directory": {
+ "description": "directory is the target directory name.\nMust not contain or start with '..'. If '.' is supplied, the volume directory will be the\ngit repository. Otherwise, if specified, the volume will contain the git repository in\nthe subdirectory with the given name.",
+ "type": "string"
+ },
+ "repository": {
+ "description": "repository is the URL",
+ "type": "string"
+ },
+ "revision": {
+ "description": "revision is the commit hash for the specified revision.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "repository"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "glusterfs": {
+ "description": "glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.\nDeprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer supported.",
+ "properties": {
+ "endpoints": {
+ "description": "endpoints is the endpoint name that details Glusterfs topology.",
+ "type": "string"
+ },
+ "path": {
+ "description": "path is the Glusterfs volume path.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Glusterfs volume to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "endpoints",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostPath": {
+ "description": "hostPath represents a pre-existing file or directory on the host\nmachine that is directly exposed to the container. This is generally\nused for system agents or other privileged things that are allowed\nto see the host machine. Most containers will NOT need this.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "properties": {
+ "path": {
+ "description": "path of the directory on the host.\nIf the path is a symlink, it will follow the link to the real path.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ },
+ "type": {
+ "description": "type for HostPath Volume\nDefaults to \"\"\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "image": {
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "properties": {
+ "pullPolicy": {
+ "description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
+ "type": "string"
+ },
+ "reference": {
+ "description": "Required: Image or artifact reference to be used.\nBehaves in the same way as pod.spec.containers[*].image.\nPull secrets will be assembled in the same way as for the container image by looking up node credentials, SA image pull secrets, and pod spec image pull secrets.\nMore info: https://kubernetes.io/docs/concepts/containers/images\nThis field is optional to allow higher level config management to default or override\ncontainer images in workload controllers like Deployments and StatefulSets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "iscsi": {
+ "description": "iscsi represents an ISCSI Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes/#iscsi",
+ "properties": {
+ "chapAuthDiscovery": {
+ "description": "chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication",
+ "type": "boolean"
+ },
+ "chapAuthSession": {
+ "description": "chapAuthSession defines whether support iSCSI Session CHAP authentication",
+ "type": "boolean"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#iscsi",
+ "type": "string"
+ },
+ "initiatorName": {
+ "description": "initiatorName is the custom iSCSI Initiator Name.\nIf initiatorName is specified with iscsiInterface simultaneously, new iSCSI interface\n: will be created for the connection.",
+ "type": "string"
+ },
+ "iqn": {
+ "description": "iqn is the target iSCSI Qualified Name.",
+ "type": "string"
+ },
+ "iscsiInterface": {
+ "default": "default",
+ "description": "iscsiInterface is the interface Name that uses an iSCSI transport.\nDefaults to 'default' (tcp).",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun represents iSCSI Target Lun number.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "portals": {
+ "description": "portals is the iSCSI Target Portal List. The portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is the CHAP Secret for iSCSI target and initiator authentication",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "targetPortal": {
+ "description": "targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "iqn",
+ "lun",
+ "targetPortal"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "name of the volume.\nMust be a DNS_LABEL and unique within the pod.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "nfs": {
+ "description": "nfs represents an NFS mount on the host that shares a pod's lifetime\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "properties": {
+ "path": {
+ "description": "path that is exported by the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the NFS export to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "boolean"
+ },
+ "server": {
+ "description": "server is the hostname or IP address of the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "persistentVolumeClaim": {
+ "description": "persistentVolumeClaimVolumeSource represents a reference to a\nPersistentVolumeClaim in the same namespace.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "properties": {
+ "claimName": {
+ "description": "claimName is the name of a PersistentVolumeClaim in the same namespace as the pod using this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Will force the ReadOnly setting in VolumeMounts.\nDefault false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "claimName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "photonPersistentDisk": {
+ "description": "photonPersistentDisk represents a PhotonController persistent disk attached and mounted on kubelets host machine.\nDeprecated: PhotonPersistentDisk is deprecated and the in-tree photonPersistentDisk type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "pdID": {
+ "description": "pdID is the ID that identifies Photon Controller persistent disk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "pdID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "portworxVolume": {
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID uniquely identifies a Portworx volume",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "projected": {
+ "description": "projected items for all in one resources secrets, configmaps, and downward API",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode are the mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "sources": {
+ "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
+ "items": {
+ "description": "Projection that may be projected along with other supported volume types.\nExactly one of these fields must be set.",
+ "properties": {
+ "clusterTrustBundle": {
+ "description": "ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field\nof ClusterTrustBundle objects in an auto-updating file.\n\nAlpha, gated by the ClusterTrustBundleProjection feature gate.\n\nClusterTrustBundle objects can either be selected by name, or by the\ncombination of signer name and a label selector.\n\nKubelet performs aggressive normalization of the PEM contents written\ninto the pod filesystem. Esoteric PEM features such as inter-block\ncomments and block headers are stripped. Certificates are deduplicated.\nThe ordering of certificates within the file is arbitrary, and Kubelet\nmay change the order over time.",
+ "properties": {
+ "labelSelector": {
+ "description": "Select all ClusterTrustBundles that match this label selector. Only has\neffect if signerName is set. Mutually-exclusive with name. If unset,\ninterpreted as \"match nothing\". If set but empty, interpreted as \"match\neverything\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Select a single ClusterTrustBundle by object name. Mutually-exclusive\nwith signerName and labelSelector.",
+ "type": "string"
+ },
+ "optional": {
+ "description": "If true, don't block pod startup if the referenced ClusterTrustBundle(s)\naren't available. If using name, then the named ClusterTrustBundle is\nallowed not to exist. If using signerName, then the combination of\nsignerName and labelSelector is allowed to match zero\nClusterTrustBundles.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "Relative path from the volume root to write the bundle.",
+ "type": "string"
+ },
+ "signerName": {
+ "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap information about the configMap data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI information about the downwardAPI data to project",
+ "properties": {
+ "items": {
+ "description": "Items is a list of DownwardAPIVolume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podCertificate": {
+ "description": "Projects an auto-rotating credential bundle (private key and certificate\nchain) that the pod can use either as a TLS client or server.\n\nKubelet generates a private key and uses it to send a\nPodCertificateRequest to the named signer. Once the signer approves the\nrequest and issues a certificate chain, Kubelet writes the key and\ncertificate chain to the pod filesystem. The pod does not start until\ncertificates have been issued for each podCertificate projected volume\nsource in its spec.\n\nKubelet will begin trying to rotate the certificate at the time indicated\nby the signer using the PodCertificateRequest.Status.BeginRefreshAt\ntimestamp.\n\nKubelet can write a single file, indicated by the credentialBundlePath\nfield, or separate files, indicated by the keyPath and\ncertificateChainPath fields.\n\nThe credential bundle is a single file in PEM format. The first PEM\nentry is the private key (in PKCS#8 format), and the remaining PEM\nentries are the certificate chain issued by the signer (typically,\nsigners will return their certificate chain in leaf-to-root order).\n\nPrefer using the credential bundle format, since your application code\ncan read it atomically. If you use keyPath and certificateChainPath,\nyour application must make two separate file reads. If these coincide\nwith a certificate rotation, it is possible that the private key and leaf\ncertificate you read may not correspond to each other. Your application\nwill need to check for this condition, and re-read until they are\nconsistent.\n\nThe named signer controls chooses the format of the certificate it\nissues; consult the signer implementation's documentation to learn how to\nuse the certificates it issues.",
+ "properties": {
+ "certificateChainPath": {
+ "description": "Write the certificate chain at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "credentialBundlePath": {
+ "description": "Write the credential bundle at this path in the projected volume.\n\nThe credential bundle is a single file that contains multiple PEM blocks.\nThe first PEM block is a PRIVATE KEY block, containing a PKCS#8 private\nkey.\n\nThe remaining blocks are CERTIFICATE blocks, containing the issued\ncertificate chain from the signer (leaf and any intermediates).\n\nUsing credentialBundlePath lets your Pod's application code make a single\natomic read that retrieves a consistent key and certificate chain. If you\nproject them to separate files, your application code will need to\nadditionally check that the leaf certificate was issued to the key.",
+ "type": "string"
+ },
+ "keyPath": {
+ "description": "Write the key at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "keyType": {
+ "description": "The type of keypair Kubelet will generate for the pod.\n\nValid values are \"RSA3072\", \"RSA4096\", \"ECDSAP256\", \"ECDSAP384\",\n\"ECDSAP521\", and \"ED25519\".",
+ "type": "string"
+ },
+ "maxExpirationSeconds": {
+ "description": "maxExpirationSeconds is the maximum lifetime permitted for the\ncertificate.\n\nKubelet copies this value verbatim into the PodCertificateRequests it\ngenerates for this projection.\n\nIf omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver\nwill reject values shorter than 3600 (1 hour). The maximum allowable\nvalue is 7862400 (91 days).\n\nThe signer implementation is then free to issue a certificate with any\nlifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600\nseconds (1 hour). This constraint is enforced by kube-apiserver.\n`kubernetes.io` signers will never issue certificates with a lifetime\nlonger than 24 hours.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "signerName": {
+ "description": "Kubelet's generated CSRs will be addressed to this signer.",
+ "type": "string"
+ },
+ "userAnnotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "userAnnotations allow pod authors to pass additional information to\nthe signer implementation. Kubernetes does not restrict or validate this\nmetadata in any way.\n\nThese values are copied verbatim into the `spec.unverifiedUserAnnotations` field of\nthe PodCertificateRequest objects that Kubelet creates.\n\nEntries are subject to the same validation as object metadata annotations,\nwith the addition that all keys must be domain-prefixed. No restrictions\nare placed on values, except an overall size limitation on the entire field.\n\nSigners should document the keys and values they support. Signers should\ndeny requests that contain keys they do not recognize.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "keyType",
+ "signerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret information about the secret data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "serviceAccountToken": {
+ "description": "serviceAccountToken is information about the serviceAccountToken data to project",
+ "properties": {
+ "audience": {
+ "description": "audience is the intended audience of the token. A recipient of a token\nmust identify itself with an identifier specified in the audience of the\ntoken, and otherwise should reject the token. The audience defaults to the\nidentifier of the apiserver.",
+ "type": "string"
+ },
+ "expirationSeconds": {
+ "description": "expirationSeconds is the requested duration of validity of the service\naccount token. As the token approaches expiration, the kubelet volume\nplugin will proactively rotate the service account token. The kubelet will\nstart trying to rotate the token if the token is older than 80 percent of\nits time to live or if the token is older than 24 hours.Defaults to 1 hour\nand must be at least 10 minutes.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "quobyte": {
+ "description": "quobyte represents a Quobyte mount on the host that shares a pod's lifetime.\nDeprecated: Quobyte is deprecated and the in-tree quobyte type is no longer supported.",
+ "properties": {
+ "group": {
+ "description": "group to map volume access to\nDefault is no group",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Quobyte volume to be mounted with read-only permissions.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "registry": {
+ "description": "registry represents a single or multiple Quobyte Registry services\nspecified as a string as host:port pair (multiple entries are separated with commas)\nwhich acts as the central registry for volumes",
+ "type": "string"
+ },
+ "tenant": {
+ "description": "tenant owning the given Quobyte volume in the Backend\nUsed with dynamically provisioned Quobyte volumes, value is set by the plugin",
+ "type": "string"
+ },
+ "user": {
+ "description": "user to map volume access to\nDefaults to serivceaccount user",
+ "type": "string"
+ },
+ "volume": {
+ "description": "volume is a string that references an already created Quobyte volume by name.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "registry",
+ "volume"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "rbd": {
+ "description": "rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.\nDeprecated: RBD is deprecated and the in-tree rbd type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#rbd",
+ "type": "string"
+ },
+ "image": {
+ "description": "image is the rados image name.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "keyring": {
+ "default": "/etc/ceph/keyring",
+ "description": "keyring is the path to key ring for RBDUser.\nDefault is /etc/ceph/keyring.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "monitors": {
+ "description": "monitors is a collection of Ceph monitors.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "pool": {
+ "default": "rbd",
+ "description": "pool is the rados pool name.\nDefault is rbd.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is name of the authentication secret for RBDUser. If provided\noverrides keyring.\nDefault is nil.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "default": "admin",
+ "description": "user is the rados user name.\nDefault is admin.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "image",
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scaleIO": {
+ "description": "scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes nodes.\nDeprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "default": "xfs",
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\".\nDefault is \"xfs\".",
+ "type": "string"
+ },
+ "gateway": {
+ "description": "gateway is the host address of the ScaleIO API Gateway.",
+ "type": "string"
+ },
+ "protectionDomain": {
+ "description": "protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef references to the secret for ScaleIO user and other\nsensitive information. If this is not provided, Login operation will fail.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "sslEnabled": {
+ "description": "sslEnabled Flag enable/disable SSL communication with Gateway, default false",
+ "type": "boolean"
+ },
+ "storageMode": {
+ "default": "ThinProvisioned",
+ "description": "storageMode indicates whether the storage for a volume should be ThickProvisioned or ThinProvisioned.\nDefault is ThinProvisioned.",
+ "type": "string"
+ },
+ "storagePool": {
+ "description": "storagePool is the ScaleIO Storage Pool associated with the protection domain.",
+ "type": "string"
+ },
+ "system": {
+ "description": "system is the name of the storage system as configured in ScaleIO.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the name of a volume already created in the ScaleIO system\nthat is associated with this volume source.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "gateway",
+ "secretRef",
+ "system"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret represents a secret that should populate this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is Optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values\nfor mode bits. Defaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its keys must be defined",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of the secret in the pod's namespace to use.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "storageos": {
+ "description": "storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.\nDeprecated: StorageOS is deprecated and the in-tree storageos type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef specifies the secret to use for obtaining the StorageOS API\ncredentials. If not specified, default values will be attempted.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeName": {
+ "description": "volumeName is the human-readable name of the StorageOS volume. Volume\nnames are only unique within a namespace.",
+ "type": "string"
+ },
+ "volumeNamespace": {
+ "description": "volumeNamespace specifies the scope of the volume within StorageOS. If no\nnamespace is specified then the Pod's namespace will be used. This allows the\nKubernetes name scoping to be mirrored within StorageOS for tighter integration.\nSet VolumeName to any name to override the default behaviour.\nSet to \"default\" if you are not using namespaces within StorageOS.\nNamespaces that do not pre-exist within StorageOS will be created.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "vsphereVolume": {
+ "description": "vsphereVolume represents a vSphere volume attached and mounted on kubelets host machine.\nDeprecated: VsphereVolume is deprecated. All operations for the in-tree vsphereVolume type\nare redirected to the csi.vsphere.vmware.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "storagePolicyID": {
+ "description": "storagePolicyID is the storage Policy Based Management (SPBM) profile ID associated with the StoragePolicyName.",
+ "type": "string"
+ },
+ "storagePolicyName": {
+ "description": "storagePolicyName is the storage Policy Based Management (SPBM) profile name.",
+ "type": "string"
+ },
+ "volumePath": {
+ "description": "volumePath is the path that identifies vSphere volume vmdk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumePath"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "strategy": {
+ "description": "The daemonset strategy to use to replace existing pods with new ones.",
+ "properties": {
+ "rollingUpdate": {
+ "description": "Rolling update config params. Present only if type = \"RollingUpdate\".",
+ "properties": {
+ "maxSurge": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of nodes with an existing available DaemonSet pod that\ncan have an updated DaemonSet pod during during an update.\nValue can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%).\nThis can not be 0 if MaxUnavailable is 0.\nAbsolute number is calculated from percentage by rounding up to a minimum of 1.\nDefault value is 0.\nExample: when this is set to 30%, at most 30% of the total number of nodes\nthat should be running the daemon pod (i.e. status.desiredNumberScheduled)\ncan have their a new pod created before the old pod is marked as deleted.\nThe update starts by launching new pods on 30% of nodes. Once an updated\npod is available (Ready for at least minReadySeconds) the old DaemonSet pod\non that node is marked deleted. If the old pod becomes unavailable for any\nreason (Ready transitions to false, is evicted, or is drained) an updated\npod is immediately created on that node without considering surge limits.\nAllowing surge implies the possibility that the resources consumed by the\ndaemonset on any given node can double if the readiness check fails, and\nso resource intensive daemonsets should take into account that they may\ncause evictions during disruption.",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxUnavailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of DaemonSet pods that can be unavailable during the\nupdate. Value can be an absolute number (ex: 5) or a percentage of total\nnumber of DaemonSet pods at the start of the update (ex: 10%). Absolute\nnumber is calculated from percentage by rounding up.\nThis cannot be 0 if MaxSurge is 0\nDefault value is 1.\nExample: when this is set to 30%, at most 30% of the total number of nodes\nthat should be running the daemon pod (i.e. status.desiredNumberScheduled)\ncan have their pods stopped for an update at any given time. The update\nstarts by stopping at most 30% of those DaemonSet pods and then brings\nup new DaemonSet pods in their place. Once the new pods are available,\nit then proceeds onto other DaemonSet pods, thus ensuring that at least\n70% of original number of DaemonSet pods are available at all times during\nthe update.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type of daemon set update. Can be \"RollingUpdate\" or \"OnDelete\". Default is RollingUpdate.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "envoyDeployment": {
+ "description": "EnvoyDeployment defines the desired state of the Envoy deployment resource.\nIf unspecified, default settings for the managed Envoy deployment resource\nare applied.",
+ "properties": {
+ "container": {
+ "description": "Container defines the desired specification of main container.",
+ "properties": {
+ "env": {
+ "description": "List of environment variables to set in the container.",
+ "items": {
+ "description": "EnvVar represents an environment variable present in a Container.",
+ "properties": {
+ "name": {
+ "description": "Name of the environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Variable references $(VAR_NAME) are expanded\nusing the previously defined environment variables in the container and\nany service environment variables. If a variable cannot be resolved,\nthe reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.\n\"$$(VAR_NAME)\" will produce the string literal \"$(VAR_NAME)\".\nEscaped references will never be expanded, regardless of whether the variable\nexists or not.\nDefaults to \"\".",
+ "type": "string"
+ },
+ "valueFrom": {
+ "description": "Source for the environment variable's value. Cannot be used if value is not empty.",
+ "properties": {
+ "configMapKeyRef": {
+ "description": "Selects a key of a ConfigMap.",
+ "properties": {
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fieldRef": {
+ "description": "Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`,\nspec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fileKeyRef": {
+ "description": "FileKeyRef selects a key of the env file.\nRequires the EnvFiles feature gate to be enabled.",
+ "properties": {
+ "key": {
+ "description": "The key within the env file. An invalid key will prevent the pod from starting.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nDuring Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.",
+ "type": "string"
+ },
+ "optional": {
+ "default": false,
+ "description": "Specify whether the file or its key must be defined. If the file or key\ndoes not exist, then the env var is not published.\nIf optional is set to true and the specified key does not exist,\nthe environment variable will not be set in the Pod's containers.\n\nIf optional is set to false and the specified key does not exist,\nan error will be returned during Pod creation.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "The path within the volume from which to select the file.\nMust be relative and may not contain the '..' path or start with '..'.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "The name of the volume mount containing the env file.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path",
+ "volumeName"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "secretKeyRef": {
+ "description": "Selects a key of a secret in the pod's namespace",
+ "properties": {
+ "key": {
+ "description": "The key of the secret to select from. Must be a valid secret key.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "image": {
+ "description": "Image specifies the EnvoyProxy container image to be used including a tag, instead of the default image.\nThis field is mutually exclusive with ImageRepository.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Image must include a tag and allowed characters only (e.g., 'repo:tag').",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?(/[a-zA-Z0-9._/-]+)?(:[a-zA-Z0-9._-]+)?(@sha256:[a-z0-9]+)?$')"
+ }
+ ]
+ },
+ "imageRepository": {
+ "description": "ImageRepository specifies the container image repository to be used without specifying a tag.\nThe default tag will be used.\nThis field is mutually exclusive with Image.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "ImageRepository must contain only allowed characters and must not include a tag.",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?[a-zA-Z0-9._/-]+$')"
+ }
+ ]
+ },
+ "resources": {
+ "description": "Resources required by this container.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "securityContext": {
+ "description": "SecurityContext defines the security options the container should be run with.\nIf set, the fields of SecurityContext override the equivalent fields of PodSecurityContext.\nMore info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/",
+ "properties": {
+ "allowPrivilegeEscalation": {
+ "description": "AllowPrivilegeEscalation controls whether a process can gain more\nprivileges than its parent process. This bool directly controls if\nthe no_new_privs flag will be set on the container process.\nAllowPrivilegeEscalation is true always when the container is:\n1) run as Privileged\n2) has CAP_SYS_ADMIN\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by this container. If set, this profile\noverrides the pod's appArmorProfile.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "capabilities": {
+ "description": "The capabilities to add/drop when running containers.\nDefaults to the default set of capabilities granted by the container runtime.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "add": {
+ "description": "Added capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "drop": {
+ "description": "Removed capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "privileged": {
+ "description": "Run container in privileged mode.\nProcesses in privileged containers are essentially equivalent to root on the host.\nDefaults to false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "procMount": {
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "readOnlyRootFilesystem": {
+ "description": "Whether this container has a read-only root filesystem.\nDefault is false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to the container.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by this container. If seccomp options are\nprovided at both the pod & container level, the container options\noverride the pod options.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options from the PodSecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "volumeMounts": {
+ "description": "VolumeMounts are volumes to mount into the container's filesystem.\nCannot be updated.",
+ "items": {
+ "description": "VolumeMount describes a mounting of a Volume within a container.",
+ "properties": {
+ "mountPath": {
+ "description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
+ "type": "string"
+ },
+ "mountPropagation": {
+ "description": "mountPropagation determines how mounts are propagated from the host\nto container and the other way around.\nWhen not set, MountPropagationNone is used.\nThis field is beta in 1.10.\nWhen RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified\n(which defaults to None).",
+ "type": "string"
+ },
+ "name": {
+ "description": "This must match the Name of a Volume.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "Mounted read-only if true, read-write otherwise (false or unspecified).\nDefaults to false.",
+ "type": "boolean"
+ },
+ "recursiveReadOnly": {
+ "description": "RecursiveReadOnly specifies whether read-only mounts should be handled\nrecursively.\n\nIf ReadOnly is false, this field has no meaning and must be unspecified.\n\nIf ReadOnly is true, and this field is set to Disabled, the mount is not made\nrecursively read-only. If this field is set to IfPossible, the mount is made\nrecursively read-only, if it is supported by the container runtime. If this\nfield is set to Enabled, the mount is made recursively read-only if it is\nsupported by the container runtime, otherwise the pod will not be started and\nan error will be generated to indicate the reason.\n\nIf this field is set to IfPossible or Enabled, MountPropagation must be set to\nNone (or be unspecified, which defaults to None).\n\nIf this field is not specified, it is treated as an equivalent of Disabled.",
+ "type": "string"
+ },
+ "subPath": {
+ "description": "Path within the volume from which the container's volume should be mounted.\nDefaults to \"\" (volume's root).",
+ "type": "string"
+ },
+ "subPathExpr": {
+ "description": "Expanded path within the volume from which the container's volume should be mounted.\nBehaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.\nDefaults to \"\" (volume's root).\nSubPathExpr and SubPath are mutually exclusive.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "mountPath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Either image or imageRepository can be set.",
+ "rule": "!has(self.image) || !has(self.imageRepository)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initContainers": {
+ "description": "List of initialization containers belonging to the pod.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/",
+ "items": {
+ "description": "A single application container that you want to run within a pod.",
+ "properties": {
+ "args": {
+ "description": "Arguments to the entrypoint.\nThe container image's CMD is used if this is not provided.\nVariable references $(VAR_NAME) are expanded using the container's environment. If a variable\ncannot be resolved, the reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e. \"$$(VAR_NAME)\" will\nproduce the string literal \"$(VAR_NAME)\". Escaped references will never be expanded, regardless\nof whether the variable exists or not. Cannot be updated.\nMore info: https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "command": {
+ "description": "Entrypoint array. Not executed within a shell.\nThe container image's ENTRYPOINT is used if this is not provided.\nVariable references $(VAR_NAME) are expanded using the container's environment. If a variable\ncannot be resolved, the reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e. \"$$(VAR_NAME)\" will\nproduce the string literal \"$(VAR_NAME)\". Escaped references will never be expanded, regardless\nof whether the variable exists or not. Cannot be updated.\nMore info: https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "env": {
+ "description": "List of environment variables to set in the container.\nCannot be updated.",
+ "items": {
+ "description": "EnvVar represents an environment variable present in a Container.",
+ "properties": {
+ "name": {
+ "description": "Name of the environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Variable references $(VAR_NAME) are expanded\nusing the previously defined environment variables in the container and\nany service environment variables. If a variable cannot be resolved,\nthe reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.\n\"$$(VAR_NAME)\" will produce the string literal \"$(VAR_NAME)\".\nEscaped references will never be expanded, regardless of whether the variable\nexists or not.\nDefaults to \"\".",
+ "type": "string"
+ },
+ "valueFrom": {
+ "description": "Source for the environment variable's value. Cannot be used if value is not empty.",
+ "properties": {
+ "configMapKeyRef": {
+ "description": "Selects a key of a ConfigMap.",
+ "properties": {
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fieldRef": {
+ "description": "Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`,\nspec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fileKeyRef": {
+ "description": "FileKeyRef selects a key of the env file.\nRequires the EnvFiles feature gate to be enabled.",
+ "properties": {
+ "key": {
+ "description": "The key within the env file. An invalid key will prevent the pod from starting.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nDuring Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.",
+ "type": "string"
+ },
+ "optional": {
+ "default": false,
+ "description": "Specify whether the file or its key must be defined. If the file or key\ndoes not exist, then the env var is not published.\nIf optional is set to true and the specified key does not exist,\nthe environment variable will not be set in the Pod's containers.\n\nIf optional is set to false and the specified key does not exist,\nan error will be returned during Pod creation.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "The path within the volume from which to select the file.\nMust be relative and may not contain the '..' path or start with '..'.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "The name of the volume mount containing the env file.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path",
+ "volumeName"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "secretKeyRef": {
+ "description": "Selects a key of a secret in the pod's namespace",
+ "properties": {
+ "key": {
+ "description": "The key of the secret to select from. Must be a valid secret key.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "envFrom": {
+ "description": "List of sources to populate environment variables in the container.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nWhen a key exists in multiple\nsources, the value associated with the last source will take precedence.\nValues defined by an Env with a duplicate key will take precedence.\nCannot be updated.",
+ "items": {
+ "description": "EnvFromSource represents the source of a set of ConfigMaps or Secrets",
+ "properties": {
+ "configMapRef": {
+ "description": "The ConfigMap to select from",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "prefix": {
+ "description": "Optional text to prepend to the name of each environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "The Secret to select from",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "image": {
+ "description": "Container image name.\nMore info: https://kubernetes.io/docs/concepts/containers/images\nThis field is optional to allow higher level config management to default or override\ncontainer images in workload controllers like Deployments and StatefulSets.",
+ "type": "string"
+ },
+ "imagePullPolicy": {
+ "description": "Image pull policy.\nOne of Always, Never, IfNotPresent.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/containers/images#updating-images",
+ "type": "string"
+ },
+ "lifecycle": {
+ "description": "Actions that the management system should take in response to container lifecycle events.\nCannot be updated.",
+ "properties": {
+ "postStart": {
+ "description": "PostStart is called immediately after a container is created. If the handler fails,\nthe container is terminated and restarted according to its restart policy.\nOther management of the container blocks until the hook completes.\nMore info: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sleep": {
+ "description": "Sleep represents a duration that the container should sleep.",
+ "properties": {
+ "seconds": {
+ "description": "Seconds is the number of seconds to sleep.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "seconds"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpSocket": {
+ "description": "Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept\nfor backward compatibility. There is no validation of this field and\nlifecycle hooks will fail at runtime when it is specified.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "preStop": {
+ "description": "PreStop is called immediately before a container is terminated due to an\nAPI request or management event such as liveness/startup probe failure,\npreemption, resource contention, etc. The handler is not called if the\ncontainer crashes or exits. The Pod's termination grace period countdown begins before the\nPreStop hook is executed. Regardless of the outcome of the handler, the\ncontainer will eventually terminate within the Pod's termination grace\nperiod (unless delayed by finalizers). Other management of the container blocks until the hook completes\nor until the termination grace period is reached.\nMore info: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sleep": {
+ "description": "Sleep represents a duration that the container should sleep.",
+ "properties": {
+ "seconds": {
+ "description": "Seconds is the number of seconds to sleep.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "seconds"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpSocket": {
+ "description": "Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept\nfor backward compatibility. There is no validation of this field and\nlifecycle hooks will fail at runtime when it is specified.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "stopSignal": {
+ "description": "StopSignal defines which signal will be sent to a container when it is being stopped.\nIf not specified, the default is defined by the container runtime in use.\nStopSignal can only be set for Pods with a non-empty .spec.os.name",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "livenessProbe": {
+ "description": "Periodic probe of container liveness.\nContainer will be restarted if the probe fails.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failureThreshold": {
+ "description": "Minimum consecutive failures for the probe to be considered failed after having succeeded.\nDefaults to 3. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "grpc": {
+ "description": "GRPC specifies a GRPC HealthCheckRequest.",
+ "properties": {
+ "port": {
+ "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "service": {
+ "default": "",
+ "description": "Service is the name of the service to place in the gRPC HealthCheckRequest\n(see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).\n\nIf this is not specified, the default behavior is defined by gRPC.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialDelaySeconds": {
+ "description": "Number of seconds after the container has started before liveness probes are initiated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ },
+ "periodSeconds": {
+ "description": "How often (in seconds) to perform the probe.\nDefault to 10 seconds. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "successThreshold": {
+ "description": "Minimum consecutive successes for the probe to be considered successful after having failed.\nDefaults to 1. Must be 1 for liveness and startup. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tcpSocket": {
+ "description": "TCPSocket specifies a connection to a TCP port.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "terminationGracePeriodSeconds": {
+ "description": "Optional duration in seconds the pod needs to terminate gracefully upon probe failure.\nThe grace period is the duration in seconds after the processes running in the pod are sent\na termination signal and the time when the processes are forcibly halted with a kill signal.\nSet this value longer than the expected cleanup time for your process.\nIf this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this\nvalue overrides the value provided by the pod spec.\nValue must be non-negative integer. The value zero indicates stop immediately via\nthe kill signal (no opportunity to shut down).\nThis is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.\nMinimum value is 1. spec.terminationGracePeriodSeconds is used if unset.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "description": "Number of seconds after which the probe times out.\nDefaults to 1 second. Minimum value is 1.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Name of the container specified as a DNS_LABEL.\nEach container in a pod must have a unique name (DNS_LABEL).\nCannot be updated.",
+ "type": "string"
+ },
+ "ports": {
+ "description": "List of ports to expose from the container. Not specifying a port here\nDOES NOT prevent that port from being exposed. Any port which is\nlistening on the default \"0.0.0.0\" address inside a container will be\naccessible from the network.\nModifying this array with strategic merge patch may corrupt the data.\nFor more information See https://github.com/kubernetes/kubernetes/issues/108255.\nCannot be updated.",
+ "items": {
+ "description": "ContainerPort represents a network port in a single container.",
+ "properties": {
+ "containerPort": {
+ "description": "Number of port to expose on the pod's IP address.\nThis must be a valid port number, 0 < x < 65536.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "hostIP": {
+ "description": "What host IP to bind the external port to.",
+ "type": "string"
+ },
+ "hostPort": {
+ "description": "Number of port to expose on the host.\nIf specified, this must be a valid port number, 0 < x < 65536.\nIf HostNetwork is specified, this must match ContainerPort.\nMost containers do not need this.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "name": {
+ "description": "If specified, this must be an IANA_SVC_NAME and unique within the pod. Each\nnamed port in a pod must have a unique name. Name for the port that can be\nreferred to by services.",
+ "type": "string"
+ },
+ "protocol": {
+ "default": "TCP",
+ "description": "Protocol for port. Must be UDP, TCP, or SCTP.\nDefaults to \"TCP\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "containerPort"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "containerPort",
+ "protocol"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "readinessProbe": {
+ "description": "Periodic probe of container service readiness.\nContainer will be removed from service endpoints if the probe fails.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failureThreshold": {
+ "description": "Minimum consecutive failures for the probe to be considered failed after having succeeded.\nDefaults to 3. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "grpc": {
+ "description": "GRPC specifies a GRPC HealthCheckRequest.",
+ "properties": {
+ "port": {
+ "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "service": {
+ "default": "",
+ "description": "Service is the name of the service to place in the gRPC HealthCheckRequest\n(see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).\n\nIf this is not specified, the default behavior is defined by gRPC.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialDelaySeconds": {
+ "description": "Number of seconds after the container has started before liveness probes are initiated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ },
+ "periodSeconds": {
+ "description": "How often (in seconds) to perform the probe.\nDefault to 10 seconds. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "successThreshold": {
+ "description": "Minimum consecutive successes for the probe to be considered successful after having failed.\nDefaults to 1. Must be 1 for liveness and startup. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tcpSocket": {
+ "description": "TCPSocket specifies a connection to a TCP port.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "terminationGracePeriodSeconds": {
+ "description": "Optional duration in seconds the pod needs to terminate gracefully upon probe failure.\nThe grace period is the duration in seconds after the processes running in the pod are sent\na termination signal and the time when the processes are forcibly halted with a kill signal.\nSet this value longer than the expected cleanup time for your process.\nIf this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this\nvalue overrides the value provided by the pod spec.\nValue must be non-negative integer. The value zero indicates stop immediately via\nthe kill signal (no opportunity to shut down).\nThis is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.\nMinimum value is 1. spec.terminationGracePeriodSeconds is used if unset.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "description": "Number of seconds after which the probe times out.\nDefaults to 1 second. Minimum value is 1.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resizePolicy": {
+ "description": "Resources resize policy for the container.\nThis field cannot be set on ephemeral containers.",
+ "items": {
+ "description": "ContainerResizePolicy represents resource resize policy for the container.",
+ "properties": {
+ "resourceName": {
+ "description": "Name of the resource to which this resource resize policy applies.\nSupported values: cpu, memory.",
+ "type": "string"
+ },
+ "restartPolicy": {
+ "description": "Restart policy to apply when specified resource is resized.\nIf not specified, it defaults to NotRequired.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resourceName",
+ "restartPolicy"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "resources": {
+ "description": "Compute Resources required by this container.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "restartPolicy": {
+ "description": "RestartPolicy defines the restart behavior of individual containers in a pod.\nThis overrides the pod-level restart policy. When this field is not specified,\nthe restart behavior is defined by the Pod's restart policy and the container type.\nAdditionally, setting the RestartPolicy as \"Always\" for the init container will\nhave the following effect:\nthis init container will be continually restarted on\nexit until all regular containers have terminated. Once all regular\ncontainers have completed, all init containers with restartPolicy \"Always\"\nwill be shut down. This lifecycle differs from normal init containers and\nis often referred to as a \"sidecar\" container. Although this init\ncontainer still starts in the init container sequence, it does not wait\nfor the container to complete before proceeding to the next init\ncontainer. Instead, the next init container starts immediately after this\ninit container is started, or after any startupProbe has successfully\ncompleted.",
+ "type": "string"
+ },
+ "restartPolicyRules": {
+ "description": "Represents a list of rules to be checked to determine if the\ncontainer should be restarted on exit. The rules are evaluated in\norder. Once a rule matches a container exit condition, the remaining\nrules are ignored. If no rule matches the container exit condition,\nthe Container-level restart policy determines the whether the container\nis restarted or not. Constraints on the rules:\n- At most 20 rules are allowed.\n- Rules can have the same action.\n- Identical rules are not forbidden in validations.\nWhen rules are specified, container MUST set RestartPolicy explicitly\neven it if matches the Pod's RestartPolicy.",
+ "items": {
+ "description": "ContainerRestartRule describes how a container exit is handled.",
+ "properties": {
+ "action": {
+ "description": "Specifies the action taken on a container exit if the requirements\nare satisfied. The only possible value is \"Restart\" to restart the\ncontainer.",
+ "type": "string"
+ },
+ "exitCodes": {
+ "description": "Represents the exit codes to check on container exits.",
+ "properties": {
+ "operator": {
+ "description": "Represents the relationship between the container exit code(s) and the\nspecified values. Possible values are:\n- In: the requirement is satisfied if the container exit code is in the\n set of specified values.\n- NotIn: the requirement is satisfied if the container exit code is\n not in the set of specified values.",
+ "type": "string"
+ },
+ "values": {
+ "description": "Specifies the set of values to check for container exit codes.\nAt most 255 elements are allowed.",
+ "items": {
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "required": [
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "action"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "securityContext": {
+ "description": "SecurityContext defines the security options the container should be run with.\nIf set, the fields of SecurityContext override the equivalent fields of PodSecurityContext.\nMore info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/",
+ "properties": {
+ "allowPrivilegeEscalation": {
+ "description": "AllowPrivilegeEscalation controls whether a process can gain more\nprivileges than its parent process. This bool directly controls if\nthe no_new_privs flag will be set on the container process.\nAllowPrivilegeEscalation is true always when the container is:\n1) run as Privileged\n2) has CAP_SYS_ADMIN\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by this container. If set, this profile\noverrides the pod's appArmorProfile.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "capabilities": {
+ "description": "The capabilities to add/drop when running containers.\nDefaults to the default set of capabilities granted by the container runtime.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "add": {
+ "description": "Added capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "drop": {
+ "description": "Removed capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "privileged": {
+ "description": "Run container in privileged mode.\nProcesses in privileged containers are essentially equivalent to root on the host.\nDefaults to false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "procMount": {
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "readOnlyRootFilesystem": {
+ "description": "Whether this container has a read-only root filesystem.\nDefault is false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to the container.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by this container. If seccomp options are\nprovided at both the pod & container level, the container options\noverride the pod options.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options from the PodSecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "startupProbe": {
+ "description": "StartupProbe indicates that the Pod has successfully initialized.\nIf specified, no other probes are executed until this completes successfully.\nIf this probe fails, the Pod will be restarted, just as if the livenessProbe failed.\nThis can be used to provide different probe parameters at the beginning of a Pod's lifecycle,\nwhen it might take a long time to load data or warm a cache, than during steady-state operation.\nThis cannot be updated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failureThreshold": {
+ "description": "Minimum consecutive failures for the probe to be considered failed after having succeeded.\nDefaults to 3. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "grpc": {
+ "description": "GRPC specifies a GRPC HealthCheckRequest.",
+ "properties": {
+ "port": {
+ "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "service": {
+ "default": "",
+ "description": "Service is the name of the service to place in the gRPC HealthCheckRequest\n(see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).\n\nIf this is not specified, the default behavior is defined by gRPC.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialDelaySeconds": {
+ "description": "Number of seconds after the container has started before liveness probes are initiated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ },
+ "periodSeconds": {
+ "description": "How often (in seconds) to perform the probe.\nDefault to 10 seconds. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "successThreshold": {
+ "description": "Minimum consecutive successes for the probe to be considered successful after having failed.\nDefaults to 1. Must be 1 for liveness and startup. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tcpSocket": {
+ "description": "TCPSocket specifies a connection to a TCP port.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "terminationGracePeriodSeconds": {
+ "description": "Optional duration in seconds the pod needs to terminate gracefully upon probe failure.\nThe grace period is the duration in seconds after the processes running in the pod are sent\na termination signal and the time when the processes are forcibly halted with a kill signal.\nSet this value longer than the expected cleanup time for your process.\nIf this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this\nvalue overrides the value provided by the pod spec.\nValue must be non-negative integer. The value zero indicates stop immediately via\nthe kill signal (no opportunity to shut down).\nThis is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.\nMinimum value is 1. spec.terminationGracePeriodSeconds is used if unset.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "description": "Number of seconds after which the probe times out.\nDefaults to 1 second. Minimum value is 1.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "stdin": {
+ "description": "Whether this container should allocate a buffer for stdin in the container runtime. If this\nis not set, reads from stdin in the container will always result in EOF.\nDefault is false.",
+ "type": "boolean"
+ },
+ "stdinOnce": {
+ "description": "Whether the container runtime should close the stdin channel after it has been opened by\na single attach. When stdin is true the stdin stream will remain open across multiple attach\nsessions. If stdinOnce is set to true, stdin is opened on container start, is empty until the\nfirst client attaches to stdin, and then remains open and accepts data until the client disconnects,\nat which time stdin is closed and remains closed until the container is restarted. If this\nflag is false, a container processes that reads from stdin will never receive an EOF.\nDefault is false",
+ "type": "boolean"
+ },
+ "terminationMessagePath": {
+ "description": "Optional: Path at which the file to which the container's termination message\nwill be written is mounted into the container's filesystem.\nMessage written is intended to be brief final status, such as an assertion failure message.\nWill be truncated by the node if greater than 4096 bytes. The total message length across\nall containers will be limited to 12kb.\nDefaults to /dev/termination-log.\nCannot be updated.",
+ "type": "string"
+ },
+ "terminationMessagePolicy": {
+ "description": "Indicate how the termination message should be populated. File will use the contents of\nterminationMessagePath to populate the container status message on both success and failure.\nFallbackToLogsOnError will use the last chunk of container log output if the termination\nmessage file is empty and the container exited with an error.\nThe log output is limited to 2048 bytes or 80 lines, whichever is smaller.\nDefaults to File.\nCannot be updated.",
+ "type": "string"
+ },
+ "tty": {
+ "description": "Whether this container should allocate a TTY for itself, also requires 'stdin' to be true.\nDefault is false.",
+ "type": "boolean"
+ },
+ "volumeDevices": {
+ "description": "volumeDevices is the list of block devices to be used by the container.",
+ "items": {
+ "description": "volumeDevice describes a mapping of a raw block device within a container.",
+ "properties": {
+ "devicePath": {
+ "description": "devicePath is the path inside of the container that the device will be mapped to.",
+ "type": "string"
+ },
+ "name": {
+ "description": "name must match the name of a persistentVolumeClaim in the pod",
+ "type": "string"
+ }
+ },
+ "required": [
+ "devicePath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "devicePath"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "volumeMounts": {
+ "description": "Pod volumes to mount into the container's filesystem.\nCannot be updated.",
+ "items": {
+ "description": "VolumeMount describes a mounting of a Volume within a container.",
+ "properties": {
+ "mountPath": {
+ "description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
+ "type": "string"
+ },
+ "mountPropagation": {
+ "description": "mountPropagation determines how mounts are propagated from the host\nto container and the other way around.\nWhen not set, MountPropagationNone is used.\nThis field is beta in 1.10.\nWhen RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified\n(which defaults to None).",
+ "type": "string"
+ },
+ "name": {
+ "description": "This must match the Name of a Volume.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "Mounted read-only if true, read-write otherwise (false or unspecified).\nDefaults to false.",
+ "type": "boolean"
+ },
+ "recursiveReadOnly": {
+ "description": "RecursiveReadOnly specifies whether read-only mounts should be handled\nrecursively.\n\nIf ReadOnly is false, this field has no meaning and must be unspecified.\n\nIf ReadOnly is true, and this field is set to Disabled, the mount is not made\nrecursively read-only. If this field is set to IfPossible, the mount is made\nrecursively read-only, if it is supported by the container runtime. If this\nfield is set to Enabled, the mount is made recursively read-only if it is\nsupported by the container runtime, otherwise the pod will not be started and\nan error will be generated to indicate the reason.\n\nIf this field is set to IfPossible or Enabled, MountPropagation must be set to\nNone (or be unspecified, which defaults to None).\n\nIf this field is not specified, it is treated as an equivalent of Disabled.",
+ "type": "string"
+ },
+ "subPath": {
+ "description": "Path within the volume from which the container's volume should be mounted.\nDefaults to \"\" (volume's root).",
+ "type": "string"
+ },
+ "subPathExpr": {
+ "description": "Expanded path within the volume from which the container's volume should be mounted.\nBehaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.\nDefaults to \"\" (volume's root).\nSubPathExpr and SubPath are mutually exclusive.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "mountPath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "mountPath"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "workingDir": {
+ "description": "Container's working directory.\nIf not specified, the container runtime's default will be used, which\nmight be configured in the container image.\nCannot be updated.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "name": {
+ "description": "Name of the deployment.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to deployment",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pod": {
+ "description": "Pod defines the desired specification of pod.",
+ "properties": {
+ "affinity": {
+ "description": "If specified, the pod's scheduling constraints.",
+ "properties": {
+ "nodeAffinity": {
+ "description": "Describes node affinity scheduling rules for the pod.",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node matches the corresponding matchExpressions; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "An empty preferred scheduling term matches all objects with implicit weight 0\n(i.e. it's a no-op). A null preferred scheduling term matches no objects (i.e. is also a no-op).",
+ "properties": {
+ "preference": {
+ "description": "A node selector term, associated with the corresponding weight.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "Weight associated with matching the corresponding nodeSelectorTerm, in the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "preference",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to an update), the system\nmay or may not try to eventually evict the pod from its node.",
+ "properties": {
+ "nodeSelectorTerms": {
+ "description": "Required. A list of node selector terms. The terms are ORed.",
+ "items": {
+ "description": "A null or empty node selector term matches no objects. The requirements of\nthem are ANDed.\nThe TopologySelectorTerm type implements a subset of the NodeSelectorTerm.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "nodeSelectorTerms"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAffinity": {
+ "description": "Describes pod affinity scheduling rules (e.g. co-locate this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAntiAffinity": {
+ "description": "Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe anti-affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling anti-affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and subtracting\n\"weight\" from the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the anti-affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the anti-affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "annotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Annotations are the annotations that should be appended to the pods.\nBy default, no pod annotations are appended.",
+ "type": "object"
+ },
+ "imagePullSecrets": {
+ "description": "ImagePullSecrets is an optional list of references to secrets\nin the same namespace to use for pulling any of the images used by this PodSpec.\nIf specified, these secrets will be passed to individual puller implementations for them to use.\nMore info: https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod",
+ "items": {
+ "description": "LocalObjectReference contains enough information to let you locate the\nreferenced object inside the same namespace.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "labels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Labels are the additional labels that should be tagged to the pods.\nBy default, no additional pod labels are tagged.",
+ "type": "object"
+ },
+ "nodeSelector": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "NodeSelector is a selector which must be true for the pod to fit on a node.\nSelector which must match a node's labels for the pod to be scheduled on that node.\nMore info: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/",
+ "type": "object"
+ },
+ "priorityClassName": {
+ "description": "PriorityClassName indicates the importance of a Pod relative to other Pods.\nIf a PriorityClassName is not specified, the pod priority will be default or zero if there is no default.\nMore info: https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/",
+ "type": "string"
+ },
+ "securityContext": {
+ "description": "SecurityContext holds pod-level security attributes and common container settings.\nOptional: Defaults to empty. See type description for default values of each field.",
+ "properties": {
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fsGroup": {
+ "description": "A special supplemental group that applies to all containers in a pod.\nSome volume types allow the Kubelet to change the ownership of that volume\nto be owned by the pod:\n\n1. The owning GID will be the FSGroup\n2. The setgid bit is set (new files created in the volume will be owned by FSGroup)\n3. The permission bits are OR'd with rw-rw----\n\nIf unset, the Kubelet will not modify the ownership and permissions of any volume.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "fsGroupChangePolicy": {
+ "description": "fsGroupChangePolicy defines behavior of changing ownership and permission of the volume\nbefore being exposed inside Pod. This field will only apply to\nvolume types which support fsGroup based ownership(and permissions).\nIt will have no effect on ephemeral volume types such as: secret, configmaps\nand emptydir.\nValid values are \"OnRootMismatch\" and \"Always\". If not specified, \"Always\" is used.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxChangePolicy": {
+ "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to all containers.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in SecurityContext. If set in\nboth SecurityContext and PodSecurityContext, the value specified in SecurityContext\ntakes precedence for that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "supplementalGroups": {
+ "description": "A list of groups applied to the first process run in each container, in\naddition to the container's primary GID and fsGroup (if specified). If\nthe SupplementalGroupsPolicy feature is enabled, the\nsupplementalGroupsPolicy field determines whether these are in addition\nto or instead of any group memberships defined in the container image.\nIf unspecified, no additional groups are added, though group memberships\ndefined in the container image may still be used, depending on the\nsupplementalGroupsPolicy field.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "format": "int64",
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "supplementalGroupsPolicy": {
+ "description": "Defines how supplemental groups of the first container processes are calculated.\nValid values are \"Merge\" and \"Strict\". If not specified, \"Merge\" is used.\n(Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled\nand the container runtime must implement support for this feature.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "sysctls": {
+ "description": "Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported\nsysctls (by the container runtime) might fail to launch.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "description": "Sysctl defines a kernel parameter to be set",
+ "properties": {
+ "name": {
+ "description": "Name of a property to set",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of a property to set",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options within a container's SecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tolerations": {
+ "description": "If specified, the pod's tolerations.",
+ "items": {
+ "description": "The pod this Toleration is attached to tolerates any taint that matches\nthe triple using the matching operator .",
+ "properties": {
+ "effect": {
+ "description": "Effect indicates the taint effect to match. Empty means match all taint effects.\nWhen specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.",
+ "type": "string"
+ },
+ "key": {
+ "description": "Key is the taint key that the toleration applies to. Empty means match all taint keys.\nIf the key is empty, operator must be Exists; this combination means to match all values and all keys.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Operator represents a key's relationship to the value.\nValid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.\nExists is equivalent to wildcard for value, so that a pod can\ntolerate all taints of a particular category.\nLt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).",
+ "type": "string"
+ },
+ "tolerationSeconds": {
+ "description": "TolerationSeconds represents the period of time the toleration (which must be\nof effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,\nit is not set, which means tolerate the taint forever (do not evict). Zero and\nnegative values will be treated as 0 (evict immediately) by the system.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "value": {
+ "description": "Value is the taint value the toleration matches to.\nIf the operator is Exists, the value should be empty, otherwise just a regular string.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "topologySpreadConstraints": {
+ "description": "TopologySpreadConstraints describes how a group of pods ought to spread across topology\ndomains. Scheduler will schedule pods in a way which abides by the constraints.\nAll topologySpreadConstraints are ANDed.",
+ "items": {
+ "description": "TopologySpreadConstraint specifies how to spread matching pods among the given topology.",
+ "properties": {
+ "labelSelector": {
+ "description": "LabelSelector is used to find matching pods.\nPods that match this label selector are counted to determine the number of pods\nin their corresponding topology domain.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select the pods over which\nspreading will be calculated. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are ANDed with labelSelector\nto select the group of existing pods over which spreading will be calculated\nfor the incoming pod. The same key is forbidden to exist in both MatchLabelKeys and LabelSelector.\nMatchLabelKeys cannot be set when LabelSelector isn't set.\nKeys that don't exist in the incoming pod labels will\nbe ignored. A null or empty list means only match against labelSelector.\n\nThis is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate to be enabled (enabled by default).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "maxSkew": {
+ "description": "MaxSkew describes the degree to which pods may be unevenly distributed.\nWhen `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference\nbetween the number of matching pods in the target topology and the global minimum.\nThe global minimum is the minimum number of matching pods in an eligible domain\nor zero if the number of eligible domains is less than MinDomains.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 2/2/1:\nIn this case, the global minimum is 1.\n| zone1 | zone2 | zone3 |\n| P P | P P | P |\n- if MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2;\nscheduling it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2)\nviolate MaxSkew(1).\n- if MaxSkew is 2, incoming pod can be scheduled onto any zone.\nWhen `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence\nto topologies that satisfy it.\nIt's a required field. Default value is 1 and 0 is not allowed.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "minDomains": {
+ "description": "MinDomains indicates a minimum number of eligible domains.\nWhen the number of eligible domains with matching topology keys is less than minDomains,\nPod Topology Spread treats \"global minimum\" as 0, and then the calculation of Skew is performed.\nAnd when the number of eligible domains with matching topology keys equals or greater than minDomains,\nthis value has no effect on scheduling.\nAs a result, when the number of eligible domains is less than minDomains,\nscheduler won't schedule more than maxSkew Pods to those domains.\nIf value is nil, the constraint behaves as if MinDomains is equal to 1.\nValid values are integers greater than 0.\nWhen value is not nil, WhenUnsatisfiable must be DoNotSchedule.\n\nFor example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and pods with the same\nlabelSelector spread as 2/2/2:\n| zone1 | zone2 | zone3 |\n| P P | P P | P P |\nThe number of domains is less than 5(MinDomains), so \"global minimum\" is treated as 0.\nIn this situation, new pod with the same labelSelector cannot be scheduled,\nbecause computed skew will be 3(3 - 0) if new Pod is scheduled to any of the three zones,\nit will violate MaxSkew.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "nodeAffinityPolicy": {
+ "description": "NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector\nwhen calculating pod topology spread skew. Options are:\n- Honor: only nodes matching nodeAffinity/nodeSelector are included in the calculations.\n- Ignore: nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.\n\nIf this value is nil, the behavior is equivalent to the Honor policy.",
+ "type": "string"
+ },
+ "nodeTaintsPolicy": {
+ "description": "NodeTaintsPolicy indicates how we will treat node taints when calculating\npod topology spread skew. Options are:\n- Honor: nodes without taints, along with tainted nodes for which the incoming pod\nhas a toleration, are included.\n- Ignore: node taints are ignored. All nodes are included.\n\nIf this value is nil, the behavior is equivalent to the Ignore policy.",
+ "type": "string"
+ },
+ "topologyKey": {
+ "description": "TopologyKey is the key of node labels. Nodes that have a label with this key\nand identical values are considered to be in the same topology.\nWe consider each as a \"bucket\", and try to put balanced number\nof pods into each bucket.\nWe define a domain as a particular instance of a topology.\nAlso, we define an eligible domain as a domain whose nodes meet the requirements of\nnodeAffinityPolicy and nodeTaintsPolicy.\ne.g. If TopologyKey is \"kubernetes.io/hostname\", each Node is a domain of that topology.\nAnd, if TopologyKey is \"topology.kubernetes.io/zone\", each zone is a domain of that topology.\nIt's a required field.",
+ "type": "string"
+ },
+ "whenUnsatisfiable": {
+ "description": "WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy\nthe spread constraint.\n- DoNotSchedule (default) tells the scheduler not to schedule it.\n- ScheduleAnyway tells the scheduler to schedule the pod in any location,\n but giving higher precedence to topologies that would help reduce the\n skew.\nA constraint is considered \"Unsatisfiable\" for an incoming pod\nif and only if every possible node assignment for that pod would violate\n\"MaxSkew\" on some topology.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 3/1/1:\n| zone1 | zone2 | zone3 |\n| P P P | P | P |\nIf WhenUnsatisfiable is set to DoNotSchedule, incoming pod can only be scheduled\nto zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies\nMaxSkew(1). In other words, the cluster can still be imbalanced, but scheduler\nwon't make it *more* imbalanced.\nIt's a required field.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "maxSkew",
+ "topologyKey",
+ "whenUnsatisfiable"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "volumes": {
+ "description": "Volumes that can be mounted by containers belonging to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes",
+ "items": {
+ "description": "Volume represents a named volume in a pod that may be accessed by any container in the pod.",
+ "properties": {
+ "awsElasticBlockStore": {
+ "description": "awsElasticBlockStore represents an AWS Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: AWSElasticBlockStore is deprecated. All operations for the in-tree\nawsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly value true will force the readOnly setting in VolumeMounts.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureDisk": {
+ "description": "azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.\nDeprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type\nare redirected to the disk.csi.azure.com CSI driver.",
+ "properties": {
+ "cachingMode": {
+ "description": "cachingMode is the Host Caching mode: None, Read Only, Read Write.",
+ "type": "string"
+ },
+ "diskName": {
+ "description": "diskName is the Name of the data disk in the blob storage",
+ "type": "string"
+ },
+ "diskURI": {
+ "description": "diskURI is the URI of data disk in the blob storage",
+ "type": "string"
+ },
+ "fsType": {
+ "default": "ext4",
+ "description": "fsType is Filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "kind expected values are Shared: multiple blob disks per storage account Dedicated: single blob disk per storage account Managed: azure managed data disk (only in managed availability set). defaults to shared",
+ "type": "string"
+ },
+ "readOnly": {
+ "default": false,
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "diskName",
+ "diskURI"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureFile": {
+ "description": "azureFile represents an Azure File Service mount on the host and bind mount to the pod.\nDeprecated: AzureFile is deprecated. All operations for the in-tree azureFile type\nare redirected to the file.csi.azure.com CSI driver.",
+ "properties": {
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of secret that contains Azure Storage Account Name and Key",
+ "type": "string"
+ },
+ "shareName": {
+ "description": "shareName is the azure share Name",
+ "type": "string"
+ }
+ },
+ "required": [
+ "secretName",
+ "shareName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cephfs": {
+ "description": "cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.\nDeprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.",
+ "properties": {
+ "monitors": {
+ "description": "monitors is Required: Monitors is a collection of Ceph monitors\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretFile": {
+ "description": "secretFile is Optional: SecretFile is the path to key ring for User, default is /etc/ceph/user.secret\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: SecretRef is reference to the authentication secret for User, default is empty.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "description": "user is optional: User is the rados user name, default is admin\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cinder": {
+ "description": "cinder represents a cinder volume attached and mounted on kubelets host machine.\nDeprecated: Cinder is deprecated. All operations for the in-tree cinder type\nare redirected to the cinder.csi.openstack.org CSI driver.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is optional: points to a secret object containing parameters used to connect\nto OpenStack.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeID": {
+ "description": "volumeID used to identify the volume in cinder.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap represents a configMap that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "csi": {
+ "description": "csi (Container Storage Interface) represents ephemeral storage that is handled by certain external CSI drivers.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the CSI driver that handles this volume.\nConsult with your admin for the correct name as registered in the cluster.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType to mount. Ex. \"ext4\", \"xfs\", \"ntfs\".\nIf not provided, the empty value is passed to the associated CSI driver\nwhich will determine the default filesystem to apply.",
+ "type": "string"
+ },
+ "nodePublishSecretRef": {
+ "description": "nodePublishSecretRef is a reference to the secret object containing\nsensitive information to pass to the CSI driver to complete the CSI\nNodePublishVolume and NodeUnpublishVolume calls.\nThis field is optional, and may be empty if no secret is required. If the\nsecret object contains more than one secret, all secret references are passed.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "readOnly": {
+ "description": "readOnly specifies a read-only configuration for the volume.\nDefaults to false (read/write).",
+ "type": "boolean"
+ },
+ "volumeAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "volumeAttributes stores driver-specific properties that are passed to the CSI\ndriver. Consult your driver's documentation for supported values.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI represents downward API about the pod that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "Optional: mode bits to use on created files by default. Must be a\nOptional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "Items is a list of downward API volume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emptyDir": {
+ "description": "emptyDir represents a temporary directory that shares a pod's lifetime.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "properties": {
+ "medium": {
+ "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "type": "string"
+ },
+ "sizeLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "sizeLimit is the total amount of local storage required for this EmptyDir volume.\nThe size limit is also applicable for memory medium.\nThe maximum usage on memory medium EmptyDir would be the minimum value between\nthe SizeLimit specified here and the sum of memory limits of all containers in a pod.\nThe default is nil which means that the limit is undefined.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ephemeral": {
+ "description": "ephemeral represents a volume that is handled by a cluster storage driver.\nThe volume's lifecycle is tied to the pod that defines it - it will be created before the pod starts,\nand deleted when the pod is removed.\n\nUse this if:\na) the volume is only needed while the pod runs,\nb) features of normal volumes like restoring from snapshot or capacity\n tracking are needed,\nc) the storage driver is specified through a storage class, and\nd) the storage driver supports dynamic volume provisioning through\n a PersistentVolumeClaim (see EphemeralVolumeSource for more\n information on the connection between this volume type\n and PersistentVolumeClaim).\n\nUse PersistentVolumeClaim or one of the vendor-specific\nAPIs for volumes that persist for longer than the lifecycle\nof an individual pod.\n\nUse CSI for light-weight local ephemeral volumes if the CSI driver is meant to\nbe used that way - see the documentation of the driver for\nmore information.\n\nA pod can use both types of ephemeral volumes and\npersistent volumes at the same time.",
+ "properties": {
+ "volumeClaimTemplate": {
+ "description": "Will be used to create a stand-alone PVC to provision the volume.\nThe pod in which this EphemeralVolumeSource is embedded will be the\nowner of the PVC, i.e. the PVC will be deleted together with the\npod. The name of the PVC will be `-` where\n`` is the name from the `PodSpec.Volumes` array\nentry. Pod validation will reject the pod if the concatenated name\nis not valid for a PVC (for example, too long).\n\nAn existing PVC with that name that is not owned by the pod\nwill *not* be used for the pod to avoid using an unrelated\nvolume by mistake. Starting the pod is then blocked until\nthe unrelated PVC is removed. If such a pre-created PVC is\nmeant to be used by the pod, the PVC has to updated with an\nowner reference to the pod once the pod exists. Normally\nthis should not be necessary, but it may be useful when\nmanually reconstructing a broken cluster.\n\nThis field is read-only and no changes will be made by Kubernetes\nto the PVC after it has been created.\n\nRequired, must not be nil.",
+ "properties": {
+ "metadata": {
+ "description": "May contain labels and annotations that will be copied into the PVC\nwhen creating it. No other fields are allowed and will be rejected during\nvalidation.",
+ "type": "object"
+ },
+ "spec": {
+ "description": "The specification for the PersistentVolumeClaim. The entire content is\ncopied unchanged into the PVC that gets created from this\ntemplate. The same fields as in a PersistentVolumeClaim\nare also valid here.",
+ "properties": {
+ "accessModes": {
+ "description": "accessModes contains the desired access modes the volume should have.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "dataSource": {
+ "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "dataSourceRef": {
+ "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of resource being referenced\nNote that when a namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is required in the referent namespace to allow that namespace's owner to accept the reference. See the ReferenceGrant documentation for details.\n(Alpha) This field requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resources": {
+ "description": "resources represents the minimum resources the volume should have.\nUsers are allowed to specify resource requirements\nthat are lower than previous value but must still be higher than capacity recorded in the\nstatus field of the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources",
+ "properties": {
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "selector": {
+ "description": "selector is a label query over volumes to consider for binding.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "storageClassName": {
+ "description": "storageClassName is the name of the StorageClass required by the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1",
+ "type": "string"
+ },
+ "volumeAttributesClassName": {
+ "description": "volumeAttributesClassName may be used to set the VolumeAttributesClass used by this claim.\nIf specified, the CSI driver will create or update the volume with the attributes defined\nin the corresponding VolumeAttributesClass. This has a different purpose than storageClassName,\nit can be changed after the claim is created. An empty string or nil value indicates that no\nVolumeAttributesClass will be applied to the claim. If the claim enters an Infeasible error state,\nthis field can be reset to its previous value (including nil) to cancel the modification.\nIf the resource referred to by volumeAttributesClass does not exist, this PersistentVolumeClaim will be\nset to a Pending state, as reflected by the modifyVolumeStatus field, until such as a resource\nexists.\nMore info: https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/",
+ "type": "string"
+ },
+ "volumeMode": {
+ "description": "volumeMode defines what type of volume is required by the claim.\nValue of Filesystem is implied when not included in claim spec.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the binding reference to the PersistentVolume backing this claim.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fc": {
+ "description": "fc represents a Fibre Channel resource that is attached to a kubelet's host machine and then exposed to the pod.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun is Optional: FC target lun number",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "targetWWNs": {
+ "description": "targetWWNs is Optional: FC target worldwide names (WWNs)",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "wwids": {
+ "description": "wwids Optional: FC volume world wide identifiers (wwids)\nEither wwids or combination of targetWWNs and lun must be set, but not both simultaneously.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flexVolume": {
+ "description": "flexVolume represents a generic volume resource that is\nprovisioned/attached using an exec based plugin.\nDeprecated: FlexVolume is deprecated. Consider using a CSIDriver instead.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the driver to use for this volume.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". The default filesystem depends on FlexVolume script.",
+ "type": "string"
+ },
+ "options": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "options is Optional: this field holds extra command options if any.",
+ "type": "object"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: secretRef is reference to the secret object containing\nsensitive information to pass to the plugin scripts. This may be\nempty if no secret object is specified. If the secret object\ncontains more than one secret, all secrets are passed to the plugin\nscripts.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flocker": {
+ "description": "flocker represents a Flocker volume attached to a kubelet's host machine. This depends on the Flocker control service being running.\nDeprecated: Flocker is deprecated and the in-tree flocker type is no longer supported.",
+ "properties": {
+ "datasetName": {
+ "description": "datasetName is Name of the dataset stored as metadata -> name on the dataset for Flocker\nshould be considered as deprecated",
+ "type": "string"
+ },
+ "datasetUUID": {
+ "description": "datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker dataset",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gcePersistentDisk": {
+ "description": "gcePersistentDisk represents a GCE Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: GCEPersistentDisk is deprecated. All operations for the in-tree\ngcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "format": "int32",
+ "type": "integer"
+ },
+ "pdName": {
+ "description": "pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "pdName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gitRepo": {
+ "description": "gitRepo represents a git repository at a particular revision.\nDeprecated: GitRepo is deprecated. To provision a container with a git repo, mount an\nEmptyDir into an InitContainer that clones the repo using git, then mount the EmptyDir\ninto the Pod's container.",
+ "properties": {
+ "directory": {
+ "description": "directory is the target directory name.\nMust not contain or start with '..'. If '.' is supplied, the volume directory will be the\ngit repository. Otherwise, if specified, the volume will contain the git repository in\nthe subdirectory with the given name.",
+ "type": "string"
+ },
+ "repository": {
+ "description": "repository is the URL",
+ "type": "string"
+ },
+ "revision": {
+ "description": "revision is the commit hash for the specified revision.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "repository"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "glusterfs": {
+ "description": "glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.\nDeprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer supported.",
+ "properties": {
+ "endpoints": {
+ "description": "endpoints is the endpoint name that details Glusterfs topology.",
+ "type": "string"
+ },
+ "path": {
+ "description": "path is the Glusterfs volume path.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Glusterfs volume to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "endpoints",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostPath": {
+ "description": "hostPath represents a pre-existing file or directory on the host\nmachine that is directly exposed to the container. This is generally\nused for system agents or other privileged things that are allowed\nto see the host machine. Most containers will NOT need this.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "properties": {
+ "path": {
+ "description": "path of the directory on the host.\nIf the path is a symlink, it will follow the link to the real path.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ },
+ "type": {
+ "description": "type for HostPath Volume\nDefaults to \"\"\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "image": {
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "properties": {
+ "pullPolicy": {
+ "description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
+ "type": "string"
+ },
+ "reference": {
+ "description": "Required: Image or artifact reference to be used.\nBehaves in the same way as pod.spec.containers[*].image.\nPull secrets will be assembled in the same way as for the container image by looking up node credentials, SA image pull secrets, and pod spec image pull secrets.\nMore info: https://kubernetes.io/docs/concepts/containers/images\nThis field is optional to allow higher level config management to default or override\ncontainer images in workload controllers like Deployments and StatefulSets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "iscsi": {
+ "description": "iscsi represents an ISCSI Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes/#iscsi",
+ "properties": {
+ "chapAuthDiscovery": {
+ "description": "chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication",
+ "type": "boolean"
+ },
+ "chapAuthSession": {
+ "description": "chapAuthSession defines whether support iSCSI Session CHAP authentication",
+ "type": "boolean"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#iscsi",
+ "type": "string"
+ },
+ "initiatorName": {
+ "description": "initiatorName is the custom iSCSI Initiator Name.\nIf initiatorName is specified with iscsiInterface simultaneously, new iSCSI interface\n: will be created for the connection.",
+ "type": "string"
+ },
+ "iqn": {
+ "description": "iqn is the target iSCSI Qualified Name.",
+ "type": "string"
+ },
+ "iscsiInterface": {
+ "default": "default",
+ "description": "iscsiInterface is the interface Name that uses an iSCSI transport.\nDefaults to 'default' (tcp).",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun represents iSCSI Target Lun number.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "portals": {
+ "description": "portals is the iSCSI Target Portal List. The portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is the CHAP Secret for iSCSI target and initiator authentication",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "targetPortal": {
+ "description": "targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "iqn",
+ "lun",
+ "targetPortal"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "name of the volume.\nMust be a DNS_LABEL and unique within the pod.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "nfs": {
+ "description": "nfs represents an NFS mount on the host that shares a pod's lifetime\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "properties": {
+ "path": {
+ "description": "path that is exported by the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the NFS export to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "boolean"
+ },
+ "server": {
+ "description": "server is the hostname or IP address of the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "persistentVolumeClaim": {
+ "description": "persistentVolumeClaimVolumeSource represents a reference to a\nPersistentVolumeClaim in the same namespace.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "properties": {
+ "claimName": {
+ "description": "claimName is the name of a PersistentVolumeClaim in the same namespace as the pod using this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Will force the ReadOnly setting in VolumeMounts.\nDefault false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "claimName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "photonPersistentDisk": {
+ "description": "photonPersistentDisk represents a PhotonController persistent disk attached and mounted on kubelets host machine.\nDeprecated: PhotonPersistentDisk is deprecated and the in-tree photonPersistentDisk type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "pdID": {
+ "description": "pdID is the ID that identifies Photon Controller persistent disk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "pdID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "portworxVolume": {
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID uniquely identifies a Portworx volume",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "projected": {
+ "description": "projected items for all in one resources secrets, configmaps, and downward API",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode are the mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "sources": {
+ "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
+ "items": {
+ "description": "Projection that may be projected along with other supported volume types.\nExactly one of these fields must be set.",
+ "properties": {
+ "clusterTrustBundle": {
+ "description": "ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field\nof ClusterTrustBundle objects in an auto-updating file.\n\nAlpha, gated by the ClusterTrustBundleProjection feature gate.\n\nClusterTrustBundle objects can either be selected by name, or by the\ncombination of signer name and a label selector.\n\nKubelet performs aggressive normalization of the PEM contents written\ninto the pod filesystem. Esoteric PEM features such as inter-block\ncomments and block headers are stripped. Certificates are deduplicated.\nThe ordering of certificates within the file is arbitrary, and Kubelet\nmay change the order over time.",
+ "properties": {
+ "labelSelector": {
+ "description": "Select all ClusterTrustBundles that match this label selector. Only has\neffect if signerName is set. Mutually-exclusive with name. If unset,\ninterpreted as \"match nothing\". If set but empty, interpreted as \"match\neverything\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Select a single ClusterTrustBundle by object name. Mutually-exclusive\nwith signerName and labelSelector.",
+ "type": "string"
+ },
+ "optional": {
+ "description": "If true, don't block pod startup if the referenced ClusterTrustBundle(s)\naren't available. If using name, then the named ClusterTrustBundle is\nallowed not to exist. If using signerName, then the combination of\nsignerName and labelSelector is allowed to match zero\nClusterTrustBundles.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "Relative path from the volume root to write the bundle.",
+ "type": "string"
+ },
+ "signerName": {
+ "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap information about the configMap data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI information about the downwardAPI data to project",
+ "properties": {
+ "items": {
+ "description": "Items is a list of DownwardAPIVolume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podCertificate": {
+ "description": "Projects an auto-rotating credential bundle (private key and certificate\nchain) that the pod can use either as a TLS client or server.\n\nKubelet generates a private key and uses it to send a\nPodCertificateRequest to the named signer. Once the signer approves the\nrequest and issues a certificate chain, Kubelet writes the key and\ncertificate chain to the pod filesystem. The pod does not start until\ncertificates have been issued for each podCertificate projected volume\nsource in its spec.\n\nKubelet will begin trying to rotate the certificate at the time indicated\nby the signer using the PodCertificateRequest.Status.BeginRefreshAt\ntimestamp.\n\nKubelet can write a single file, indicated by the credentialBundlePath\nfield, or separate files, indicated by the keyPath and\ncertificateChainPath fields.\n\nThe credential bundle is a single file in PEM format. The first PEM\nentry is the private key (in PKCS#8 format), and the remaining PEM\nentries are the certificate chain issued by the signer (typically,\nsigners will return their certificate chain in leaf-to-root order).\n\nPrefer using the credential bundle format, since your application code\ncan read it atomically. If you use keyPath and certificateChainPath,\nyour application must make two separate file reads. If these coincide\nwith a certificate rotation, it is possible that the private key and leaf\ncertificate you read may not correspond to each other. Your application\nwill need to check for this condition, and re-read until they are\nconsistent.\n\nThe named signer controls chooses the format of the certificate it\nissues; consult the signer implementation's documentation to learn how to\nuse the certificates it issues.",
+ "properties": {
+ "certificateChainPath": {
+ "description": "Write the certificate chain at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "credentialBundlePath": {
+ "description": "Write the credential bundle at this path in the projected volume.\n\nThe credential bundle is a single file that contains multiple PEM blocks.\nThe first PEM block is a PRIVATE KEY block, containing a PKCS#8 private\nkey.\n\nThe remaining blocks are CERTIFICATE blocks, containing the issued\ncertificate chain from the signer (leaf and any intermediates).\n\nUsing credentialBundlePath lets your Pod's application code make a single\natomic read that retrieves a consistent key and certificate chain. If you\nproject them to separate files, your application code will need to\nadditionally check that the leaf certificate was issued to the key.",
+ "type": "string"
+ },
+ "keyPath": {
+ "description": "Write the key at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "keyType": {
+ "description": "The type of keypair Kubelet will generate for the pod.\n\nValid values are \"RSA3072\", \"RSA4096\", \"ECDSAP256\", \"ECDSAP384\",\n\"ECDSAP521\", and \"ED25519\".",
+ "type": "string"
+ },
+ "maxExpirationSeconds": {
+ "description": "maxExpirationSeconds is the maximum lifetime permitted for the\ncertificate.\n\nKubelet copies this value verbatim into the PodCertificateRequests it\ngenerates for this projection.\n\nIf omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver\nwill reject values shorter than 3600 (1 hour). The maximum allowable\nvalue is 7862400 (91 days).\n\nThe signer implementation is then free to issue a certificate with any\nlifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600\nseconds (1 hour). This constraint is enforced by kube-apiserver.\n`kubernetes.io` signers will never issue certificates with a lifetime\nlonger than 24 hours.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "signerName": {
+ "description": "Kubelet's generated CSRs will be addressed to this signer.",
+ "type": "string"
+ },
+ "userAnnotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "userAnnotations allow pod authors to pass additional information to\nthe signer implementation. Kubernetes does not restrict or validate this\nmetadata in any way.\n\nThese values are copied verbatim into the `spec.unverifiedUserAnnotations` field of\nthe PodCertificateRequest objects that Kubelet creates.\n\nEntries are subject to the same validation as object metadata annotations,\nwith the addition that all keys must be domain-prefixed. No restrictions\nare placed on values, except an overall size limitation on the entire field.\n\nSigners should document the keys and values they support. Signers should\ndeny requests that contain keys they do not recognize.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "keyType",
+ "signerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret information about the secret data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "serviceAccountToken": {
+ "description": "serviceAccountToken is information about the serviceAccountToken data to project",
+ "properties": {
+ "audience": {
+ "description": "audience is the intended audience of the token. A recipient of a token\nmust identify itself with an identifier specified in the audience of the\ntoken, and otherwise should reject the token. The audience defaults to the\nidentifier of the apiserver.",
+ "type": "string"
+ },
+ "expirationSeconds": {
+ "description": "expirationSeconds is the requested duration of validity of the service\naccount token. As the token approaches expiration, the kubelet volume\nplugin will proactively rotate the service account token. The kubelet will\nstart trying to rotate the token if the token is older than 80 percent of\nits time to live or if the token is older than 24 hours.Defaults to 1 hour\nand must be at least 10 minutes.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "quobyte": {
+ "description": "quobyte represents a Quobyte mount on the host that shares a pod's lifetime.\nDeprecated: Quobyte is deprecated and the in-tree quobyte type is no longer supported.",
+ "properties": {
+ "group": {
+ "description": "group to map volume access to\nDefault is no group",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Quobyte volume to be mounted with read-only permissions.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "registry": {
+ "description": "registry represents a single or multiple Quobyte Registry services\nspecified as a string as host:port pair (multiple entries are separated with commas)\nwhich acts as the central registry for volumes",
+ "type": "string"
+ },
+ "tenant": {
+ "description": "tenant owning the given Quobyte volume in the Backend\nUsed with dynamically provisioned Quobyte volumes, value is set by the plugin",
+ "type": "string"
+ },
+ "user": {
+ "description": "user to map volume access to\nDefaults to serivceaccount user",
+ "type": "string"
+ },
+ "volume": {
+ "description": "volume is a string that references an already created Quobyte volume by name.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "registry",
+ "volume"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "rbd": {
+ "description": "rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.\nDeprecated: RBD is deprecated and the in-tree rbd type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#rbd",
+ "type": "string"
+ },
+ "image": {
+ "description": "image is the rados image name.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "keyring": {
+ "default": "/etc/ceph/keyring",
+ "description": "keyring is the path to key ring for RBDUser.\nDefault is /etc/ceph/keyring.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "monitors": {
+ "description": "monitors is a collection of Ceph monitors.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "pool": {
+ "default": "rbd",
+ "description": "pool is the rados pool name.\nDefault is rbd.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is name of the authentication secret for RBDUser. If provided\noverrides keyring.\nDefault is nil.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "default": "admin",
+ "description": "user is the rados user name.\nDefault is admin.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "image",
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scaleIO": {
+ "description": "scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes nodes.\nDeprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "default": "xfs",
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\".\nDefault is \"xfs\".",
+ "type": "string"
+ },
+ "gateway": {
+ "description": "gateway is the host address of the ScaleIO API Gateway.",
+ "type": "string"
+ },
+ "protectionDomain": {
+ "description": "protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef references to the secret for ScaleIO user and other\nsensitive information. If this is not provided, Login operation will fail.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "sslEnabled": {
+ "description": "sslEnabled Flag enable/disable SSL communication with Gateway, default false",
+ "type": "boolean"
+ },
+ "storageMode": {
+ "default": "ThinProvisioned",
+ "description": "storageMode indicates whether the storage for a volume should be ThickProvisioned or ThinProvisioned.\nDefault is ThinProvisioned.",
+ "type": "string"
+ },
+ "storagePool": {
+ "description": "storagePool is the ScaleIO Storage Pool associated with the protection domain.",
+ "type": "string"
+ },
+ "system": {
+ "description": "system is the name of the storage system as configured in ScaleIO.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the name of a volume already created in the ScaleIO system\nthat is associated with this volume source.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "gateway",
+ "secretRef",
+ "system"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret represents a secret that should populate this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is Optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values\nfor mode bits. Defaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its keys must be defined",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of the secret in the pod's namespace to use.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "storageos": {
+ "description": "storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.\nDeprecated: StorageOS is deprecated and the in-tree storageos type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef specifies the secret to use for obtaining the StorageOS API\ncredentials. If not specified, default values will be attempted.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeName": {
+ "description": "volumeName is the human-readable name of the StorageOS volume. Volume\nnames are only unique within a namespace.",
+ "type": "string"
+ },
+ "volumeNamespace": {
+ "description": "volumeNamespace specifies the scope of the volume within StorageOS. If no\nnamespace is specified then the Pod's namespace will be used. This allows the\nKubernetes name scoping to be mirrored within StorageOS for tighter integration.\nSet VolumeName to any name to override the default behaviour.\nSet to \"default\" if you are not using namespaces within StorageOS.\nNamespaces that do not pre-exist within StorageOS will be created.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "vsphereVolume": {
+ "description": "vsphereVolume represents a vSphere volume attached and mounted on kubelets host machine.\nDeprecated: VsphereVolume is deprecated. All operations for the in-tree vsphereVolume type\nare redirected to the csi.vsphere.vmware.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "storagePolicyID": {
+ "description": "storagePolicyID is the storage Policy Based Management (SPBM) profile ID associated with the StoragePolicyName.",
+ "type": "string"
+ },
+ "storagePolicyName": {
+ "description": "storagePolicyName is the storage Policy Based Management (SPBM) profile name.",
+ "type": "string"
+ },
+ "volumePath": {
+ "description": "volumePath is the path that identifies vSphere volume vmdk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumePath"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "replicas": {
+ "description": "Replicas is the number of desired pods. Defaults to 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "strategy": {
+ "description": "The deployment strategy to use to replace existing pods with new ones.",
+ "properties": {
+ "rollingUpdate": {
+ "description": "Rolling update config params. Present only if DeploymentStrategyType =\nRollingUpdate.",
+ "properties": {
+ "maxSurge": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of pods that can be scheduled above the desired number of\npods.\nValue can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%).\nThis can not be 0 if MaxUnavailable is 0.\nAbsolute number is calculated from percentage by rounding up.\nDefaults to 25%.\nExample: when this is set to 30%, the new ReplicaSet can be scaled up immediately when\nthe rolling update starts, such that the total number of old and new pods do not exceed\n130% of desired pods. Once old pods have been killed,\nnew ReplicaSet can be scaled up further, ensuring that total number of pods running\nat any time during the update is at most 130% of desired pods.",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxUnavailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of pods that can be unavailable during the update.\nValue can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%).\nAbsolute number is calculated from percentage by rounding down.\nThis can not be 0 if MaxSurge is 0.\nDefaults to 25%.\nExample: when this is set to 30%, the old ReplicaSet can be scaled down to 70% of desired pods\nimmediately when the rolling update starts. Once new pods are ready, old ReplicaSet\ncan be scaled down further, followed by scaling up the new ReplicaSet, ensuring\nthat the total number of pods available at all times during the update is at\nleast 70% of desired pods.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type of deployment. Can be \"Recreate\" or \"RollingUpdate\". Default is RollingUpdate.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "envoyHpa": {
+ "description": "EnvoyHpa defines the Horizontal Pod Autoscaler settings for Envoy Proxy Deployment.",
+ "properties": {
+ "behavior": {
+ "description": "behavior configures the scaling behavior of the target\nin both Up and Down directions (scaleUp and scaleDown fields respectively).\nIf not set, the default HPAScalingRules for scale up and scale down are used.\nSee k8s.io.autoscaling.v2.HorizontalPodAutoScalerBehavior.",
+ "properties": {
+ "scaleDown": {
+ "description": "scaleDown is scaling policy for scaling Down.\nIf not set, the default value is to allow to scale down to minReplicas pods, with a\n300 second stabilization window (i.e., the highest recommendation for\nthe last 300sec is used).",
+ "properties": {
+ "policies": {
+ "description": "policies is a list of potential scaling polices which can be used during scaling.\nIf not set, use the default values:\n- For scale up: allow doubling the number of pods, or an absolute change of 4 pods in a 15s window.\n- For scale down: allow all pods to be removed in a 15s window.",
+ "items": {
+ "description": "HPAScalingPolicy is a single policy which must hold true for a specified past interval.",
+ "properties": {
+ "periodSeconds": {
+ "description": "periodSeconds specifies the window of time for which the policy should hold true.\nPeriodSeconds must be greater than zero and less than or equal to 1800 (30 min).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": {
+ "description": "type is used to specify the scaling policy.",
+ "type": "string"
+ },
+ "value": {
+ "description": "value contains the amount of change which is permitted by the policy.\nIt must be greater than zero",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "periodSeconds",
+ "type",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "selectPolicy": {
+ "description": "selectPolicy is used to specify which policy should be used.\nIf not set, the default value Max is used.",
+ "type": "string"
+ },
+ "stabilizationWindowSeconds": {
+ "description": "stabilizationWindowSeconds is the number of seconds for which past recommendations should be\nconsidered while scaling up or scaling down.\nStabilizationWindowSeconds must be greater than or equal to zero and less than or equal to 3600 (one hour).\nIf not set, use the default values:\n- For scale up: 0 (i.e. no stabilization is done).\n- For scale down: 300 (i.e. the stabilization window is 300 seconds long).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tolerance": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "tolerance is the tolerance on the ratio between the current and desired\nmetric value under which no updates are made to the desired number of\nreplicas (e.g. 0.01 for 1%). Must be greater than or equal to zero. If not\nset, the default cluster-wide tolerance is applied (by default 10%).\n\nFor example, if autoscaling is configured with a memory consumption target of 100Mi,\nand scale-down and scale-up tolerances of 5% and 1% respectively, scaling will be\ntriggered when the actual consumption falls below 95Mi or exceeds 101Mi.\n\nThis is an beta field and requires the HPAConfigurableTolerance feature\ngate to be enabled.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scaleUp": {
+ "description": "scaleUp is scaling policy for scaling Up.\nIf not set, the default value is the higher of:\n * increase no more than 4 pods per 60 seconds\n * double the number of pods per 60 seconds\nNo stabilization is used.",
+ "properties": {
+ "policies": {
+ "description": "policies is a list of potential scaling polices which can be used during scaling.\nIf not set, use the default values:\n- For scale up: allow doubling the number of pods, or an absolute change of 4 pods in a 15s window.\n- For scale down: allow all pods to be removed in a 15s window.",
+ "items": {
+ "description": "HPAScalingPolicy is a single policy which must hold true for a specified past interval.",
+ "properties": {
+ "periodSeconds": {
+ "description": "periodSeconds specifies the window of time for which the policy should hold true.\nPeriodSeconds must be greater than zero and less than or equal to 1800 (30 min).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": {
+ "description": "type is used to specify the scaling policy.",
+ "type": "string"
+ },
+ "value": {
+ "description": "value contains the amount of change which is permitted by the policy.\nIt must be greater than zero",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "periodSeconds",
+ "type",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "selectPolicy": {
+ "description": "selectPolicy is used to specify which policy should be used.\nIf not set, the default value Max is used.",
+ "type": "string"
+ },
+ "stabilizationWindowSeconds": {
+ "description": "stabilizationWindowSeconds is the number of seconds for which past recommendations should be\nconsidered while scaling up or scaling down.\nStabilizationWindowSeconds must be greater than or equal to zero and less than or equal to 3600 (one hour).\nIf not set, use the default values:\n- For scale up: 0 (i.e. no stabilization is done).\n- For scale down: 300 (i.e. the stabilization window is 300 seconds long).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tolerance": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "tolerance is the tolerance on the ratio between the current and desired\nmetric value under which no updates are made to the desired number of\nreplicas (e.g. 0.01 for 1%). Must be greater than or equal to zero. If not\nset, the default cluster-wide tolerance is applied (by default 10%).\n\nFor example, if autoscaling is configured with a memory consumption target of 100Mi,\nand scale-down and scale-up tolerances of 5% and 1% respectively, scaling will be\ntriggered when the actual consumption falls below 95Mi or exceeds 101Mi.\n\nThis is an beta field and requires the HPAConfigurableTolerance feature\ngate to be enabled.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxReplicas": {
+ "description": "maxReplicas is the upper limit for the number of replicas to which the autoscaler can scale up.\nIt cannot be less that minReplicas.",
+ "format": "int32",
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maxReplicas must be greater than 0",
+ "rule": "self > 0"
+ }
+ ]
+ },
+ "metrics": {
+ "description": "metrics contains the specifications for which to use to calculate the\ndesired replica count (the maximum replica count across all metrics will\nbe used).\nIf left empty, it defaults to being based on CPU utilization with average on 80% usage.",
+ "items": {
+ "description": "MetricSpec specifies how to scale based on a single metric\n(only `type` and one other matching field should be set at once).",
+ "properties": {
+ "containerResource": {
+ "description": "containerResource refers to a resource metric (such as those specified in\nrequests and limits) known to Kubernetes describing a single container in\neach pod of the current scale target (e.g. CPU or memory). Such metrics are\nbuilt in to Kubernetes, and have special scaling options on top of those\navailable to normal per-pod metrics using the \"pods\" source.",
+ "properties": {
+ "container": {
+ "description": "container is the name of the container in the pods of the scaling target",
+ "type": "string"
+ },
+ "name": {
+ "description": "name is the name of the resource in question.",
+ "type": "string"
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "container",
+ "name",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "external": {
+ "description": "external refers to a global metric that is not associated\nwith any Kubernetes object. It allows autoscaling based on information\ncoming from components running outside of cluster\n(for example length of queue in cloud messaging service, or\nQPS from loadbalancer running outside of cluster).",
+ "properties": {
+ "metric": {
+ "description": "metric identifies the target metric by name and selector",
+ "properties": {
+ "name": {
+ "description": "name is the name of the given metric",
+ "type": "string"
+ },
+ "selector": {
+ "description": "selector is the string-encoded form of a standard kubernetes label selector for the given metric\nWhen set, it is passed as an additional parameter to the metrics server for more specific metrics scoping.\nWhen unset, just the metricName will be used to gather metrics.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "metric",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "object": {
+ "description": "object refers to a metric describing a single kubernetes object\n(for example, hits-per-second on an Ingress object).",
+ "properties": {
+ "describedObject": {
+ "description": "describedObject specifies the descriptions of a object,such as kind,name apiVersion",
+ "properties": {
+ "apiVersion": {
+ "description": "apiVersion is the API version of the referent",
+ "type": "string"
+ },
+ "kind": {
+ "description": "kind is the kind of the referent; More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "name": {
+ "description": "name is the name of the referent; More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metric": {
+ "description": "metric identifies the target metric by name and selector",
+ "properties": {
+ "name": {
+ "description": "name is the name of the given metric",
+ "type": "string"
+ },
+ "selector": {
+ "description": "selector is the string-encoded form of a standard kubernetes label selector for the given metric\nWhen set, it is passed as an additional parameter to the metrics server for more specific metrics scoping.\nWhen unset, just the metricName will be used to gather metrics.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "describedObject",
+ "metric",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pods": {
+ "description": "pods refers to a metric describing each pod in the current scale target\n(for example, transactions-processed-per-second). The values will be\naveraged together before being compared to the target value.",
+ "properties": {
+ "metric": {
+ "description": "metric identifies the target metric by name and selector",
+ "properties": {
+ "name": {
+ "description": "name is the name of the given metric",
+ "type": "string"
+ },
+ "selector": {
+ "description": "selector is the string-encoded form of a standard kubernetes label selector for the given metric\nWhen set, it is passed as an additional parameter to the metrics server for more specific metrics scoping.\nWhen unset, just the metricName will be used to gather metrics.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "metric",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resource": {
+ "description": "resource refers to a resource metric (such as those specified in\nrequests and limits) known to Kubernetes describing each pod in the\ncurrent scale target (e.g. CPU or memory). Such metrics are built in to\nKubernetes, and have special scaling options on top of those available\nto normal per-pod metrics using the \"pods\" source.",
+ "properties": {
+ "name": {
+ "description": "name is the name of the resource in question.",
+ "type": "string"
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "type is the type of metric source. It should be one of \"ContainerResource\", \"External\",\n\"Object\", \"Pods\" or \"Resource\", each mapping to a matching field in the object.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "minReplicas": {
+ "description": "minReplicas is the lower limit for the number of replicas to which the autoscaler\ncan scale down. It defaults to 1 replica.",
+ "format": "int32",
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "minReplicas must be greater than 0",
+ "rule": "self > 0"
+ }
+ ]
+ },
+ "name": {
+ "description": "Name of the horizontalPodAutoScaler.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to the HorizontalPodAutoscaler",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "maxReplicas"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "maxReplicas cannot be less than minReplicas",
+ "rule": "!has(self.minReplicas) || self.maxReplicas >= self.minReplicas"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "envoyPDB": {
+ "description": "EnvoyPDB allows to control the pod disruption budget of an Envoy Proxy.",
+ "properties": {
+ "maxUnavailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxUnavailable specifies the maximum amount of pods (can be expressed as integers or as a percentage) that can be unavailable at all times during voluntary disruptions,\nsuch as node drains or updates. This setting ensures that your envoy proxy maintains a certain level of availability\nand resilience during maintenance operations. Cannot be combined with minAvailable.",
+ "x-kubernetes-int-or-string": true
+ },
+ "minAvailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAvailable specifies the minimum amount of pods (can be expressed as integers or as a percentage) that must be available at all times during voluntary disruptions,\nsuch as node drains or updates. This setting ensures that your envoy proxy maintains a certain level of availability\nand resilience during maintenance operations. Cannot be combined with maxUnavailable.",
+ "x-kubernetes-int-or-string": true
+ },
+ "name": {
+ "description": "Name of the podDisruptionBudget.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to the PodDisruptionBudget",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of minAvailable or maxUnavailable can be specified",
+ "rule": "(has(self.minAvailable) && !has(self.maxUnavailable)) || (!has(self.minAvailable) && has(self.maxUnavailable))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "envoyService": {
+ "description": "EnvoyService defines the desired state of the Envoy service resource.\nIf unspecified, default settings for the managed Envoy service resource\nare applied.",
+ "properties": {
+ "allocateLoadBalancerNodePorts": {
+ "description": "AllocateLoadBalancerNodePorts defines if NodePorts will be automatically allocated for\nservices with type LoadBalancer. Default is \"true\". It may be set to \"false\" if the cluster\nload-balancer does not rely on NodePorts. If the caller requests specific NodePorts (by specifying a\nvalue), those requests will be respected, regardless of this field. This field may only be set for\nservices with type LoadBalancer and will be cleared if the type is changed to any other type.",
+ "type": "boolean"
+ },
+ "annotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Annotations that should be appended to the service.\nBy default, no annotations are appended.",
+ "type": "object"
+ },
+ "externalTrafficPolicy": {
+ "default": "Local",
+ "description": "ExternalTrafficPolicy determines the externalTrafficPolicy for the Envoy Service. Valid options\nare Local and Cluster. Default is \"Local\". \"Local\" means traffic will only go to pods on the node\nreceiving the traffic. \"Cluster\" means connections are loadbalanced to all pods in the cluster.",
+ "enum": [
+ "Local",
+ "Cluster"
+ ],
+ "type": "string"
+ },
+ "labels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Labels that should be appended to the service.\nBy default, no labels are appended.",
+ "type": "object"
+ },
+ "loadBalancerClass": {
+ "description": "LoadBalancerClass, when specified, allows for choosing the LoadBalancer provider\nimplementation if more than one are available or is otherwise expected to be specified",
+ "type": "string"
+ },
+ "loadBalancerIP": {
+ "description": "LoadBalancerIP defines the IP Address of the underlying load balancer service. This field\nmay be ignored if the load balancer provider does not support this feature.\nThis field has been deprecated in Kubernetes, but it is still used for setting the IP Address in some cloud\nproviders such as GCP.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "loadBalancerIP must be a valid IPv4 address",
+ "rule": "self.matches(r\"^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$\")"
+ }
+ ]
+ },
+ "loadBalancerSourceRanges": {
+ "description": "LoadBalancerSourceRanges defines a list of allowed IP addresses which will be configured as\nfirewall rules on the platform providers load balancer. This is not guaranteed to be working as\nit happens outside of kubernetes and has to be supported and handled by the platform provider.\nThis field may only be set for services with type LoadBalancer and will be cleared if the type\nis changed to any other type.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "name": {
+ "description": "Name of the service.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to the service",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "LoadBalancer",
+ "description": "Type determines how the Service is exposed. Defaults to LoadBalancer.\nValid options are ClusterIP, LoadBalancer and NodePort.\n\"LoadBalancer\" means a service will be exposed via an external load balancer (if the cloud provider supports it).\n\"ClusterIP\" means a service will only be accessible inside the cluster, via the cluster IP.\n\"NodePort\" means a service will be exposed on a static Port on all Nodes of the cluster.",
+ "enum": [
+ "ClusterIP",
+ "LoadBalancer",
+ "NodePort"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "allocateLoadBalancerNodePorts can only be set for LoadBalancer type",
+ "rule": "!has(self.allocateLoadBalancerNodePorts) || self.type == 'LoadBalancer'"
+ },
+ {
+ "message": "loadBalancerSourceRanges can only be set for LoadBalancer type",
+ "rule": "!has(self.loadBalancerSourceRanges) || self.type == 'LoadBalancer'"
+ },
+ {
+ "message": "loadBalancerIP can only be set for LoadBalancer type",
+ "rule": "!has(self.loadBalancerIP) || self.type == 'LoadBalancer'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "envoyServiceAccount": {
+ "description": "EnvoyServiceAccount defines the desired state of the Envoy service account resource.",
+ "properties": {
+ "name": {
+ "description": "Name of the Service Account.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "useListenerPortAsContainerPort": {
+ "description": "UseListenerPortAsContainerPort disables the port shifting feature in the Envoy Proxy.\nWhen set to false (default value), if the service port is a privileged port (1-1023), add a constant to the value converting it into an ephemeral port.\nThis allows the container to bind to the port without needing a CAP_NET_BIND_SERVICE capability.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of envoyDeployment or envoyDaemonSet can be specified",
+ "rule": "((has(self.envoyDeployment) && !has(self.envoyDaemonSet)) || (!has(self.envoyDeployment) && has(self.envoyDaemonSet))) || (!has(self.envoyDeployment) && !has(self.envoyDaemonSet))"
+ },
+ {
+ "message": "cannot use envoyHpa if envoyDaemonSet is used",
+ "rule": "((has(self.envoyHpa) && !has(self.envoyDaemonSet)) || (!has(self.envoyHpa) && has(self.envoyDaemonSet))) || (!has(self.envoyHpa) && !has(self.envoyDaemonSet))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type is the type of resource provider to use. A resource provider provides\ninfrastructure resources for running the data plane, e.g. Envoy proxy, and\noptional auxiliary control planes. Supported types are \"Kubernetes\"and \"Host\".",
+ "enum": [
+ "Kubernetes",
+ "Host"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "routingType": {
+ "description": "RoutingType can be set to \"Service\" to use the Service Cluster IP for routing to the backend,\nor it can be set to \"Endpoint\" to use Endpoint routing. The default is \"Endpoint\".",
+ "type": "string"
+ },
+ "shutdown": {
+ "description": "Shutdown defines configuration for graceful envoy shutdown process.",
+ "properties": {
+ "drainTimeout": {
+ "description": "DrainTimeout defines the graceful drain timeout. This should be less than the pod's terminationGracePeriodSeconds.\nIf unspecified, defaults to 60 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "minDrainDuration": {
+ "description": "MinDrainDuration defines the minimum drain duration allowing time for endpoint deprogramming to complete.\nIf unspecified, defaults to 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "telemetry": {
+ "description": "Telemetry defines telemetry parameters for managed proxies.",
+ "properties": {
+ "accessLog": {
+ "description": "AccessLogs defines accesslog parameters for managed proxies.\nIf unspecified, will send default format to stdout.",
+ "properties": {
+ "disable": {
+ "description": "Disable disables access logging for managed proxies if set to true.",
+ "type": "boolean"
+ },
+ "settings": {
+ "description": "Settings defines accesslog settings for managed proxies.\nIf unspecified, will send default format to stdout.",
+ "items": {
+ "properties": {
+ "format": {
+ "description": "Format defines the format of accesslog.\nThis will be ignored if sink type is ALS.",
+ "properties": {
+ "json": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "JSON is additional attributes that describe the specific event occurrence.\nStructured format for the envoy access logs. Envoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators)\ncan be used as values for fields within the Struct.\nIt's required when the format type is \"JSON\".",
+ "type": "object"
+ },
+ "text": {
+ "description": "Text defines the text accesslog format, following Envoy accesslog formatting,\nIt's required when the format type is \"Text\".\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the format.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type defines the type of accesslog format.\nWhen unset, both text and json can be specified.",
+ "enum": [
+ "Text",
+ "JSON"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If AccessLogFormat type is Text, text field needs to be set.",
+ "rule": "has(self.type) && self.type == 'Text' ? has(self.text) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is Text, json field must not be set.",
+ "rule": "has(self.type) && self.type == 'Text' ? !has(self.json) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is JSON, json field needs to be set.",
+ "rule": "has(self.type) && self.type == 'JSON' ? has(self.json) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is JSON, text field must not be set.",
+ "rule": "has(self.type) && self.type == 'JSON' ? !has(self.text) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is unset, at least one of text or json must be set.",
+ "rule": "!has(self.type) ? (has(self.text) || has(self.json)) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "matches": {
+ "description": "Matches defines the match conditions for accesslog in CEL expression.\nAn accesslog will be emitted only when one or more match conditions are evaluated to true.\nInvalid [CEL](https://www.envoyproxy.io/docs/envoy/latest/xds/type/v3/cel.proto.html#common-expression-language-cel-proto) expressions will be ignored.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "sinks": {
+ "description": "Sinks defines the sinks of accesslog.",
+ "items": {
+ "description": "ProxyAccessLogSink defines the sink of accesslog.",
+ "properties": {
+ "als": {
+ "description": "ALS defines the gRPC Access Log Service (ALS) sink.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTP defines additional configuration specific to HTTP access logs.",
+ "properties": {
+ "requestHeaders": {
+ "description": "RequestHeaders defines request headers to include in log entries sent to the access log service.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "responseHeaders": {
+ "description": "ResponseHeaders defines response headers to include in log entries sent to the access log service.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "responseTrailers": {
+ "description": "ResponseTrailers defines response trailers to include in log entries sent to the access log service.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "logName": {
+ "description": "LogName defines the friendly name of the access log to be returned in\nStreamAccessLogsMessage.Identifier. This allows the access log server\nto differentiate between different access logs coming from the same Envoy.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "description": "Type defines the type of accesslog. Supported types are \"HTTP\" and \"TCP\".",
+ "enum": [
+ "HTTP",
+ "TCP"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "The http field may only be set when type is HTTP.",
+ "rule": "self.type == 'HTTP' || !has(self.http)"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "must have at least one backend in backendRefs",
+ "rule": "has(self.backendRefs) && self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "file": {
+ "description": "File defines the file accesslog sink.",
+ "properties": {
+ "path": {
+ "description": "Path defines the file path used to expose envoy access log(e.g. /dev/stdout).",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "openTelemetry": {
+ "description": "OpenTelemetry defines the OpenTelemetry accesslog sink.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers is a list of additional headers to send with OTLP export requests.\nThese headers are added as gRPC initial metadata for the OTLP gRPC service.",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "host": {
+ "description": "Host define the extension service hostname.\n\nDeprecated: Use BackendRefs instead.",
+ "type": "string"
+ },
+ "port": {
+ "default": 4317,
+ "description": "Port defines the port the extension service is exposed on.\n\nDeprecated: Use BackendRefs instead.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes is a set of labels that describe the source of a log entry, including envoy node info.\nIt's recommended to follow [semantic conventions](https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/).",
+ "type": "object"
+ },
+ "resources": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Resources is a set of labels that describe the source of a log entry, including envoy node info.\nIt's recommended to follow [semantic conventions](https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/).\n\nDeprecated: Use ResourceAttributes instead.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "host or backendRefs needs to be set",
+ "rule": "has(self.host) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "either resources or resourceAttributes can be set, not both",
+ "rule": "!has(self.resources) || !has(self.resourceAttributes)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type defines the type of accesslog sink.",
+ "enum": [
+ "ALS",
+ "File",
+ "OpenTelemetry"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If AccessLogSink type is ALS, als field needs to be set.",
+ "rule": "self.type == 'ALS' ? has(self.als) : !has(self.als)"
+ },
+ {
+ "message": "If AccessLogSink type is File, file field needs to be set.",
+ "rule": "self.type == 'File' ? has(self.file) : !has(self.file)"
+ },
+ {
+ "message": "If AccessLogSink type is OpenTelemetry, openTelemetry field needs to be set.",
+ "rule": "self.type == 'OpenTelemetry' ? has(self.openTelemetry) : !has(self.openTelemetry)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ },
+ "type": {
+ "description": "Type defines the component emitting the accesslog, such as Listener and Route.\nIf type not defined, the setting would apply to:\n(1) All Routes.\n(2) Listeners if and only if Envoy does not find a matching route for a request.\nIf type is defined, the accesslog settings would apply to the relevant component (as-is).",
+ "enum": [
+ "Listener",
+ "Route",
+ "Upstream"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "sinks"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metrics": {
+ "description": "Metrics defines metrics configuration for managed proxies.",
+ "properties": {
+ "clusterStatName": {
+ "description": "ClusterStatName defines the value of cluster alt_stat_name, determining how cluster stats are named.\nFor more details, see envoy docs: https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto.html\nThe supported operators for this pattern are:\n`%ROUTE_NAME%`: name of Gateway API xRoute resource\n`%ROUTE_NAMESPACE%`: namespace of Gateway API xRoute resource\n`%ROUTE_KIND%`: kind of Gateway API xRoute resource\n`%ROUTE_RULE_NAME%`: name of the Gateway API xRoute section\n`%ROUTE_RULE_NUMBER%`: name of the Gateway API xRoute section\n`%BACKEND_REFS%`: names of all backends referenced in `/|/|...` format\nOnly xDS Clusters created for HTTPRoute and GRPCRoute are currently supported.\nDefault: `%ROUTE_KIND%/%ROUTE_NAMESPACE%/%ROUTE_NAME%/rule/%ROUTE_RULE_NUMBER%`\nExample: `httproute/my-ns/my-route/rule/0`",
+ "type": "string"
+ },
+ "enableGRPCStats": {
+ "description": "EnableGRPCStats enables the gRPC stats filter on listeners.\nThis is enabled by default for GRPCRoute and opt-in for HTTPRoute.\nIn general, gRPC traffic should be handled via GRPCRoute, but there are cases where\nusers want to route gRPC using HTTPRoute for its richer matching capabilities.\nTherefore, we enable this behavior only when it is explicitly opted in.",
+ "type": "boolean"
+ },
+ "enablePerEndpointStats": {
+ "description": "EnablePerEndpointStats enables per endpoint envoy stats metrics.\nPlease use with caution.",
+ "type": "boolean"
+ },
+ "enableRequestResponseSizesStats": {
+ "description": "EnableRequestResponseSizesStats enables publishing of histograms tracking header and body sizes of requests and responses.",
+ "type": "boolean"
+ },
+ "enableVirtualHostStats": {
+ "description": "EnableVirtualHostStats enables envoy stat metrics for virtual hosts.",
+ "type": "boolean"
+ },
+ "matches": {
+ "description": "Matches defines configuration for selecting specific metrics instead of generating all metrics stats\nthat are enabled by default. This helps reduce CPU and memory overhead in Envoy, but eliminating some stats\nmay after critical functionality. Here are the stats that we strongly recommend not disabling:\n`cluster_manager.warming_clusters`, `cluster..membership_total`,`cluster..membership_healthy`,\n`cluster..membership_degraded`\uff0creference https://github.com/envoyproxy/envoy/issues/9856,\nhttps://github.com/envoyproxy/envoy/issues/14610",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "prometheus": {
+ "description": "Prometheus defines the configuration for Admin endpoint `/stats/prometheus`.",
+ "properties": {
+ "compression": {
+ "description": "Configure the compression on Prometheus endpoint. Compression is useful in situations when bandwidth is scarce and large payloads can be effectively compressed at the expense of higher CPU load.",
+ "properties": {
+ "brotli": {
+ "description": "The configuration for Brotli compressor.",
+ "type": "object"
+ },
+ "gzip": {
+ "description": "The configuration for GZIP compressor.",
+ "type": "object"
+ },
+ "minContentLength": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinContentLength defines the minimum response size in bytes to apply compression.\nResponses smaller than this threshold will not be compressed.\nMust be at least 30 bytes as enforced by Envoy Proxy.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 30 bytes",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "CompressorType defines the compressor type to use for compression.",
+ "enum": [
+ "Gzip",
+ "Brotli",
+ "Zstd"
+ ],
+ "type": "string"
+ },
+ "zstd": {
+ "description": "The configuration for Zstd compressor.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "disable": {
+ "description": "Disable the Prometheus endpoint.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sinks": {
+ "description": "Sinks defines the metric sinks where metrics are sent to.",
+ "items": {
+ "description": "ProxyMetricSink defines the sink of metrics.\nDefault metrics sink is OpenTelemetry.",
+ "properties": {
+ "openTelemetry": {
+ "description": "OpenTelemetry defines the configuration for OpenTelemetry sink.\nIt's required if the sink type is OpenTelemetry.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers is a list of additional headers to send with OTLP export requests.\nThese headers are added as gRPC initial metadata for the OTLP gRPC service.",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "host": {
+ "description": "Host define the service hostname.\n\nDeprecated: Use BackendRefs instead.",
+ "type": "string"
+ },
+ "port": {
+ "default": 4317,
+ "description": "Port defines the port the service is exposed on.\n\nDeprecated: Use BackendRefs instead.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reportCountersAsDeltas": {
+ "description": "ReportCountersAsDeltas configures the OpenTelemetry sink to report\ncounters as delta temporality instead of cumulative.",
+ "type": "boolean"
+ },
+ "reportHistogramsAsDeltas": {
+ "description": "ReportHistogramsAsDeltas configures the OpenTelemetry sink to report\nhistograms as delta temporality instead of cumulative.\nRequired for backends like Elastic that drop cumulative histograms.",
+ "type": "boolean"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes is a set of labels that describe the source of metrics.\nIt's recommended to follow semantic conventions: https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "host or backendRefs needs to be set",
+ "rule": "has(self.host) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "OpenTelemetry",
+ "description": "Type defines the metric sink type.\nEG currently only supports OpenTelemetry.",
+ "enum": [
+ "OpenTelemetry"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If MetricSink type is OpenTelemetry, openTelemetry field needs to be set.",
+ "rule": "self.type == 'OpenTelemetry' ? has(self.openTelemetry) : !has(self.openTelemetry)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestID": {
+ "description": "RequestID configures Envoy request ID behavior.",
+ "properties": {
+ "tracing": {
+ "description": "Tracing configures Envoy's behavior for the UUID request ID extension,\nincluding whether the trace sampling decision is packed into the UUID and\nwhether `X-Request-ID` is used for trace sampling decisions.\n\nWhen omitted, the default behavior is `PackAndSample`, which alters the UUID\nto contain the trace sampling decision and uses `X-Request-ID` for stable\ntrace sampling.",
+ "enum": [
+ "PackAndSample",
+ "Sample",
+ "Pack",
+ "Disable"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tracing": {
+ "description": "Tracing defines tracing configuration for managed proxies.\nIf unspecified, will not send tracing data.",
+ "properties": {
+ "customTags": {
+ "additionalProperties": {
+ "properties": {
+ "environment": {
+ "description": "Environment adds value from environment variable to each span.\nIt's required when the type is \"Environment\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the environment variable is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the environment variable which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "literal": {
+ "description": "Literal adds hard-coded value to each span.\nIt's required when the type is \"Literal\".",
+ "properties": {
+ "value": {
+ "description": "Value defines the hard-coded value to add to each span.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestHeader": {
+ "description": "RequestHeader adds value from request header to each span.\nIt's required when the type is \"RequestHeader\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the request header is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the request header which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Literal",
+ "description": "Type defines the type of custom tag.",
+ "enum": [
+ "Literal",
+ "Environment",
+ "RequestHeader"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "description": "CustomTags defines the custom tags to add to each span.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nDeprecated: Use Tags instead.",
+ "type": "object"
+ },
+ "provider": {
+ "description": "Provider defines the tracing provider.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "host": {
+ "description": "Host define the provider service hostname.\n\nDeprecated: Use BackendRefs instead.",
+ "type": "string"
+ },
+ "openTelemetry": {
+ "description": "OpenTelemetry defines the OpenTelemetry tracing provider configuration",
+ "properties": {
+ "headers": {
+ "description": "Headers is a list of additional headers to send with OTLP export requests.\nThese headers are added as gRPC initial metadata for the OTLP gRPC service.",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes is a set of labels that describe the source of traces.\nIt's recommended to follow semantic conventions: https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/",
+ "type": "object"
+ },
+ "sampler": {
+ "description": "Sampler controls whether spans are exported.",
+ "properties": {
+ "samplingPercentage": {
+ "description": "SamplingPercentage controls the percentage of traces to sample.\nDefaults to 100% when not set.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "AlwaysOn",
+ "description": "Type is the sampler type.",
+ "enum": [
+ "AlwaysOn",
+ "AlwaysOff",
+ "TraceIdRatio",
+ "ParentBasedAlwaysOn",
+ "ParentBasedAlwaysOff",
+ "ParentBasedTraceIdRatio"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "samplingPercentage can only be set with TraceIdRatio or ParentBasedTraceIdRatio",
+ "rule": "has(self.samplingPercentage) ? (self.type == 'TraceIdRatio' || self.type == 'ParentBasedTraceIdRatio') : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "port": {
+ "default": 4317,
+ "description": "Port defines the port the provider service is exposed on.\n\nDeprecated: Use BackendRefs instead.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "serviceName": {
+ "description": "ServiceName defines the service name to use in tracing configuration.\nIf not set, Envoy Gateway will use a default service name set as\n\"name.namespace\" (e.g., \"my-gateway.default\").\nNote: This field is only supported for OpenTelemetry and Datadog tracing providers.\nFor Zipkin, the service name in traces is always derived from the Envoy --service-cluster flag\n(typically \"namespace/name\" format). Setting this field has no effect for Zipkin.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "serviceName cannot be empty if provided",
+ "rule": "self != \"\""
+ }
+ ]
+ },
+ "type": {
+ "default": "OpenTelemetry",
+ "description": "Type defines the tracing provider type.",
+ "enum": [
+ "OpenTelemetry",
+ "Zipkin",
+ "Datadog"
+ ],
+ "type": "string"
+ },
+ "zipkin": {
+ "description": "Zipkin defines the Zipkin tracing provider configuration",
+ "properties": {
+ "disableSharedSpanContext": {
+ "description": "DisableSharedSpanContext determines whether the default Envoy behaviour of\nclient and server spans sharing the same span context should be disabled.",
+ "type": "boolean"
+ },
+ "enable128BitTraceId": {
+ "description": "Enable128BitTraceID determines whether a 128bit trace id will be used\nwhen creating a new trace instance. If set to false, a 64bit trace\nid will be used.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "host or backendRefs needs to be set",
+ "rule": "has(self.host) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "openTelemetry can only be used with type OpenTelemetry",
+ "rule": "has(self.openTelemetry) ? self.type == 'OpenTelemetry' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "samplingFraction": {
+ "description": "SamplingFraction represents the fraction of requests that should be\nselected for tracing if no prior sampling decision has been made.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "samplingRate": {
+ "description": "SamplingRate controls the rate at which traffic will be\nselected for tracing if no prior sampling decision has been made.\nDefaults to 100, valid values [0-100]. 100 indicates 100% sampling.\n\nOnly one of SamplingRate or SamplingFraction may be specified.\nIf neither field is specified, all requests will be sampled.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "spanName": {
+ "description": "SpanName defines the name of the span which will be used for tracing.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\n\nIf not set, the span name is provider specific.\ne.g. Datadog use `ingress` as the default client span name,\nand `router egress` as the server span name.",
+ "properties": {
+ "client": {
+ "description": "Client defines operation name of the span which will be used for tracing.",
+ "type": "string"
+ },
+ "server": {
+ "description": "Server defines the operation name of the upstream span which will be used for tracing.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "client",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tags": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Tags defines the custom tags to add to each span.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nSame keys take precedence over CustomTags.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of SamplingRate or SamplingFraction can be specified",
+ "rule": "!(has(self.samplingRate) && has(self.samplingFraction))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "EnvoyProxyStatus defines the actual state of EnvoyProxy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors represent the status information for all the GatewayClass or Gateway\nreference this EnvoyProxy with ParametersReference.",
+ "items": {
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds a GatewayClass or Gateway use this EnvoyProxy with ParametersReference.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "ancestorRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/httproutefilter_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/httproutefilter_v1alpha1.json
new file mode 100644
index 0000000..6a3e24c
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/httproutefilter_v1alpha1.json
@@ -0,0 +1,411 @@
+{
+ "description": "HTTPRouteFilter is a custom Envoy Gateway HTTPRouteFilter which provides extended\ntraffic processing options such as path regex rewrite, direct response and more.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of HTTPRouteFilter.",
+ "properties": {
+ "credentialInjection": {
+ "description": "HTTPCredentialInjectionFilter defines the configuration to inject credentials into the request.\nThis is useful when the backend service requires credentials in the request, and the original\nrequest does not contain them. The filter can inject credentials into the request before forwarding\nit to the backend service.",
+ "properties": {
+ "credential": {
+ "description": "Credential is the credential to be injected.",
+ "properties": {
+ "valueRef": {
+ "description": "ValueRef is a reference to the secret containing the credentials to be injected.\nThis is an Opaque secret. The credential should be stored in the key\n\"credential\", and the value should be the credential to be injected.\nFor example, for basic authentication, the value should be \"Basic \".\nfor bearer token, the value should be \"Bearer \".",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "valueRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header is the name of the header where the credentials are injected.\nIf not specified, the credentials are injected into the Authorization header.",
+ "type": "string"
+ },
+ "overwrite": {
+ "description": "Whether to overwrite the value or not if the injected headers already exist.\nIf not specified, the default value is false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "credential"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "directResponse": {
+ "description": "HTTPDirectResponseFilter defines the configuration to return a fixed response.",
+ "properties": {
+ "body": {
+ "description": "Body of the direct response.\nSupports Envoy command operators for dynamic content (see https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators).",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the value as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ },
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ }
+ ],
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the body value.\nValid values are Inline and ValueRef, default is Inline.",
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef contains the contents of the body\nspecified as a local object reference.\nOnly a reference to ConfigMap is supported.\n\nThe value of key `response.body` in the ConfigMap will be used as the response body.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "inline must be set for type Inline",
+ "rule": "(!has(self.type) || self.type == 'Inline')? has(self.inline) : true"
+ },
+ {
+ "message": "valueRef must be set for type ValueRef",
+ "rule": "(has(self.type) && self.type == 'ValueRef')? has(self.valueRef) : true"
+ },
+ {
+ "message": "only ConfigMap is supported for ValueRef",
+ "rule": "has(self.valueRef) ? self.valueRef.kind == 'ConfigMap' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "contentType": {
+ "description": "Content Type of the direct response. This will be set in the Content-Type header.",
+ "type": "string"
+ },
+ "header": {
+ "description": "Header defines the headers of the direct response.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "header.remove is not supported for DirectResponse",
+ "rule": "!has(self.remove) || size(self.remove) == 0"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "statusCode": {
+ "description": "Status Code of the HTTP response\nIf unset, defaults to 200.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "matches": {
+ "description": "Matches defines additional matching criteria for the HTTPRoute rule.\nAs with HTTPRouteRule.Matches, the rule is matched if any one match applies.\nWhen both HTTPRouteRule.Matches and HTTPRouteFilter.Matches are set, the\neffective matching is the logical AND of the two sets.",
+ "items": {
+ "description": "HTTPRouteMatchFilter defines additional matching criteria for the HTTPRoute rule.\nAt least one matcher must be specified.",
+ "minProperties": 1,
+ "properties": {
+ "cookies": {
+ "description": "Cookies is a list of cookie matchers evaluated against the HTTP request.\nAll specified matchers must match.",
+ "items": {
+ "description": "HTTPCookieMatch defines how to match a single cookie.",
+ "properties": {
+ "name": {
+ "description": "Name is the cookie name to evaluate.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the cookie.",
+ "enum": [
+ "Exact",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the cookie value to be matched.",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "urlRewrite": {
+ "description": "HTTPURLRewriteFilter define rewrites of HTTP URL components such as path and host",
+ "properties": {
+ "appendXForwardedHost": {
+ "description": "AppendXForwardedHost controls whether the original Host header value is\nappended to the X-Forwarded-Host header when hostname rewriting is configured.\nDefaults to true for backward compatibility.",
+ "type": "boolean"
+ },
+ "hostname": {
+ "description": "Hostname is the value to be used to replace the Host header value during\nforwarding.",
+ "properties": {
+ "header": {
+ "description": "Header is the name of the header whose value would be used to rewrite the Host header",
+ "type": "string"
+ },
+ "type": {
+ "description": "HTTPPathModifierType defines the type of Hostname rewrite.",
+ "enum": [
+ "Header",
+ "Backend"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "header must be nil if the type is not Header",
+ "rule": "!(has(self.header) && self.type != 'Header')"
+ },
+ {
+ "message": "header must be specified for Header type",
+ "rule": "!(!has(self.header) && self.type == 'Header')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "path": {
+ "description": "Path defines a path rewrite.",
+ "properties": {
+ "replaceRegexMatch": {
+ "description": "ReplaceRegexMatch defines a path regex rewrite. The path portions matched by the regex pattern are replaced by the defined substitution.\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/config/route/v3/route_components.proto#envoy-v3-api-field-config-route-v3-routeaction-regex-rewrite\nSome examples:\n(1) replaceRegexMatch:\n pattern: ^/service/([^/]+)(/.*)$\n substitution: \\2/instance/\\1\n Would transform /service/foo/v1/api into /v1/api/instance/foo.\n(2) replaceRegexMatch:\n pattern: one\n substitution: two\n Would transform /xxx/one/yyy/one/zzz into /xxx/two/yyy/two/zzz.\n(3) replaceRegexMatch:\n pattern: ^(.*?)one(.*)$\n substitution: \\1two\\2\n Would transform /xxx/one/yyy/one/zzz into /xxx/two/yyy/one/zzz.\n(3) replaceRegexMatch:\n pattern: (?i)/xxx/\n substitution: /yyy/\n Would transform path /aaa/XxX/bbb into /aaa/yyy/bbb (case-insensitive).",
+ "properties": {
+ "pattern": {
+ "description": "Pattern matches a regular expression against the value of the HTTP Path.The regex string must\nadhere to the syntax documented in https://github.com/google/re2/wiki/Syntax.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "substitution": {
+ "description": "Substitution is an expression that replaces the matched portion.The expression may include numbered\ncapture groups that adhere to syntax documented in https://github.com/google/re2/wiki/Syntax.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "pattern",
+ "substitution"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "HTTPPathModifierType defines the type of path redirect or rewrite.",
+ "enum": [
+ "ReplaceRegexMatch"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If HTTPPathModifier type is ReplaceRegexMatch, replaceRegexMatch field needs to be set.",
+ "rule": "self.type == 'ReplaceRegexMatch' ? has(self.replaceRegexMatch) : !has(self.replaceRegexMatch)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.envoyproxy.io/securitypolicy_v1alpha1.json b/crdSchemas/gateway.envoyproxy.io/securitypolicy_v1alpha1.json
new file mode 100644
index 0000000..f55b400
--- /dev/null
+++ b/crdSchemas/gateway.envoyproxy.io/securitypolicy_v1alpha1.json
@@ -0,0 +1,7022 @@
+{
+ "description": "SecurityPolicy allows the user to configure various security settings for a\nGateway.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of SecurityPolicy.",
+ "properties": {
+ "apiKeyAuth": {
+ "description": "APIKeyAuth defines the configuration for the API Key Authentication.",
+ "properties": {
+ "credentialRefs": {
+ "description": "CredentialRefs is the Kubernetes secret which contains the API keys.\nThis is an Opaque secret.\nEach API key is stored in the key representing the client id.\nIf the secrets have a key for a duplicated client, the first one will be used.",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "extractFrom": {
+ "description": "ExtractFrom is where to fetch the key from the coming request.\nThe value from the first source that has a key will be used.",
+ "items": {
+ "description": "ExtractFrom is where to fetch the key from the coming request.\nOnly one of headers, params or cookies must be specified.",
+ "properties": {
+ "cookies": {
+ "description": "Cookies is the names of the cookie to fetch the key from.\nIf multiple cookies are specified, envoy will look for the api key in the order of the list.\nThis field is optional, but only one of headers, params or cookies must be specified.",
+ "items": {
+ "minLength": 1,
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "headers": {
+ "description": "Headers is the names of the header to fetch the key from.\nIf multiple headers are specified, envoy will look for the api key in the order of the list.\nThis field is optional, but only one of headers, params or cookies must be specified.",
+ "items": {
+ "minLength": 1,
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "params": {
+ "description": "Params is the names of the query parameter to fetch the key from.\nIf multiple params are specified, envoy will look for the api key in the order of the list.\nThis field is optional, but only one of headers, params or cookies must be specified.",
+ "items": {
+ "minLength": 1,
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one of headers, params, or cookies must be specified",
+ "rule": "(has(self.headers) ? 1 : 0) + (has(self.params) ? 1 : 0) + (has(self.cookies) ? 1 : 0) == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "forwardClientIDHeader": {
+ "description": "ForwardClientIDHeader is the name of the header to forward the client identity to the backend\nservice. The header will be added to the request with the client id as the value.",
+ "type": "string"
+ },
+ "sanitize": {
+ "description": "Sanitize indicates whether to remove the API key from the request before forwarding it to the backend service.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "credentialRefs",
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "authorization": {
+ "description": "Authorization defines the authorization configuration.",
+ "properties": {
+ "defaultAction": {
+ "description": "DefaultAction defines the default action to be taken if no rules match.\nIf not specified, the default action is Deny.",
+ "enum": [
+ "Allow",
+ "Deny"
+ ],
+ "type": "string"
+ },
+ "rules": {
+ "description": "Rules defines a list of authorization rules.\nThese rules are evaluated in order, the first matching rule will be applied,\nand the rest will be skipped.\n\nFor example, if there are two rules: the first rule allows the request\nand the second rule denies it, when a request matches both rules, it will be allowed.",
+ "items": {
+ "description": "AuthorizationRule defines a single authorization rule.",
+ "properties": {
+ "action": {
+ "description": "Action defines the action to be taken if the rule matches.",
+ "enum": [
+ "Allow",
+ "Deny"
+ ],
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is a user-friendly name for the rule.\nIf not specified, Envoy Gateway will generate a unique name for the rule.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "operation": {
+ "description": "Operation specifies the operation of a request, such as HTTP methods.\nIf not specified, all operations are matched on.",
+ "properties": {
+ "methods": {
+ "description": "Methods are the HTTP methods of the request.\nIf multiple methods are specified, all specified methods are allowed or denied, based on the action of the rule.",
+ "items": {
+ "description": "HTTPMethod describes how to select a HTTP route by matching the HTTP\nmethod as defined by\n[RFC 7231](https://datatracker.ietf.org/doc/html/rfc7231#section-4) and\n[RFC 5789](https://datatracker.ietf.org/doc/html/rfc5789#section-2).\nThe value is expected in upper case.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.",
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "methods"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "principal": {
+ "description": "Principal specifies the client identity of a request.\nIf there are multiple principal types, all principals must match for the rule to match.\nFor example, if there are two principals: one for client IP and one for JWT claim,\nthe rule will match only if both the client IP and the JWT claim match.",
+ "properties": {
+ "clientCIDRs": {
+ "description": "ClientCIDRs are the IP CIDR ranges of the client.\nValid examples are \"192.168.1.0/24\" or \"2001:db8::/64\"\n\nIf multiple CIDR ranges are specified, one of the CIDR ranges must match\nthe client IP for the rule to match.\n\nThe client IP is inferred from the X-Forwarded-For header, a custom header,\nor the proxy protocol.\nYou can use the `ClientIPDetection` or the `ProxyProtocol` field in\nthe `ClientTrafficPolicy` to configure how the client IP is detected.\n\nFor TCPRoute targets (raw TCP connections), HTTP headers such as\nX-Forwarded-For are not available. The client IP is obtained from the\nTCP connection's peer address. If intermediaries (load balancers, NAT)\nterminate or proxy TCP, the original client IP will only be available\nif the intermediary preserves the source address (for example by\nenabling the PROXY protocol or avoiding SNAT). Ensure your L4 proxy is\nconfigured to preserve the source IP to enable correct client-IP\nmatching for TCPRoute targets.",
+ "items": {
+ "description": "CIDR defines a CIDR Address range.\nA CIDR can be an IPv4 address range such as \"192.168.1.0/24\" or an IPv6 address range such as \"2001:0db8:11a3:09d7::/64\".",
+ "pattern": "((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]+))|((([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))\\/([0-9]+))",
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "clientIPGeoLocations": {
+ "description": "ClientIPGeoLocations authorizes the request based on geolocation metadata derived from the client IP.\nThis field is supported for HTTPRoute and GRPCRoute authorization.\nIt is not supported for TCPRoute targets.\n\nIf multiple entries are specified, one of the ClientIPGeoLocation entries must match for the rule to match.\n\nThe client IP is inferred from the X-Forwarded-For header or a custom header.\nYou can use the `ClientIPDetection` field in the `ClientTrafficPolicy` to configure the client IP detection.",
+ "items": {
+ "description": "ClientIPGeoLocation specifies geolocation-based match criteria for authorization.",
+ "properties": {
+ "anonymous": {
+ "description": "Anonymous matches anonymous network detection signals.",
+ "properties": {
+ "isAnonymous": {
+ "description": "IsAnonymous matches whether the client IP is considered anonymous.",
+ "type": "boolean"
+ },
+ "isHosting": {
+ "description": "IsHosting matches whether the client IP belongs to a hosting provider.",
+ "type": "boolean"
+ },
+ "isProxy": {
+ "description": "IsProxy matches whether the client IP belongs to a public proxy.",
+ "type": "boolean"
+ },
+ "isTor": {
+ "description": "IsTor matches whether the client IP belongs to a Tor exit node.",
+ "type": "boolean"
+ },
+ "isVPN": {
+ "description": "IsVPN matches whether the client IP is detected as VPN.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of isAnonymous, isVPN, isHosting, isTor, or isProxy must be specified",
+ "rule": "has(self.isAnonymous) || has(self.isVPN) || has(self.isHosting) || has(self.isTor) || has(self.isProxy)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "asn": {
+ "description": "ASN is the autonomous system number associated with the client IP.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "city": {
+ "description": "City is the city associated with the client IP.",
+ "maxLength": 128,
+ "minLength": 1,
+ "type": "string"
+ },
+ "country": {
+ "description": "Country is the country ISO code associated with the client IP.",
+ "maxLength": 2,
+ "minLength": 2,
+ "pattern": "^[A-Za-z]{2}$",
+ "type": "string"
+ },
+ "isp": {
+ "description": "ISP is the internet service provider associated with the client IP.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the region ISO code associated with the client IP.",
+ "maxLength": 16,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9-]+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of country, region, city, asn, isp, or anonymous must be specified",
+ "rule": "has(self.country) || has(self.region) || has(self.city) || has(self.asn) || has(self.isp) || has(self.anonymous)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "headers": {
+ "description": "Headers authorize the request based on user identity extracted from custom headers.\nIf multiple headers are specified, all headers must match for the rule to match.",
+ "items": {
+ "description": "AuthorizationHeaderMatch specifies how to match against the value of an HTTP header within a authorization rule.",
+ "properties": {
+ "name": {
+ "description": "Name of the HTTP header.\nThe header name is case-insensitive unless PreserveHeaderCase is set to true.\nFor example, \"Foo\" and \"foo\" are considered the same header.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "values": {
+ "description": "Values are the values that the header must match.\nIf multiple values are specified, the rule will match if any of the values match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 256,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "name",
+ "values"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 256,
+ "minItems": 1,
+ "type": "array"
+ },
+ "jwt": {
+ "description": "JWT authorize the request based on the JWT claims and scopes.\nNote: in order to use JWT claims for authorization, you must configure the\nJWT authentication in the same `SecurityPolicy`.",
+ "properties": {
+ "claims": {
+ "description": "Claims are the claims in a JWT token.\n\nIf multiple claims are specified, all claims must match for the rule to match.\nFor example, if there are two claims: one for the audience and one for the issuer,\nthe rule will match only if both the audience and the issuer match.",
+ "items": {
+ "description": "JWTClaim specifies a claim in a JWT token.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the claim.\nIf it is a nested claim, use a dot (.) separated string as the name to\nrepresent the full path to the claim.\nFor example, if the claim is in the \"department\" field in the \"organization\" field,\nthe name should be \"organization.department\".",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "valueType": {
+ "default": "String",
+ "description": "ValueType is the type of the claim value.\nOnly String and StringArray types are supported for now.",
+ "enum": [
+ "String",
+ "StringArray"
+ ],
+ "type": "string"
+ },
+ "values": {
+ "description": "Values are the values that the claim must match.\nIf the claim is a string type, the specified value must match exactly.\nIf the claim is a string array type, the specified value must match one of the values in the array.\nIf multiple values are specified, one of the values must match for the rule to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 128,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "name",
+ "values"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ },
+ "provider": {
+ "description": "Provider is the name of the JWT provider that used to verify the JWT token.\nIn order to use JWT claims for authorization, you must configure the JWT\nauthentication with the same provider in the same `SecurityPolicy`.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "scopes": {
+ "description": "Scopes are a special type of claim in a JWT token that represents the permissions of the client.\n\nThe value of the scopes field should be a space delimited string that is expected in the\nscope (or scp) claim, as defined in RFC 6749: https://datatracker.ietf.org/doc/html/rfc6749#page-23.\n\nIf multiple scopes are specified, all scopes must match for the rule to match.",
+ "items": {
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of claims or scopes must be specified",
+ "rule": "(has(self.claims) || has(self.scopes))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of clientCIDRs, jwt, headers, or clientIPGeoLocations must be specified",
+ "rule": "(has(self.clientCIDRs) || has(self.jwt) || has(self.headers) || has(self.clientIPGeoLocations))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "action",
+ "principal"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "basicAuth": {
+ "description": "BasicAuth defines the configuration for the HTTP Basic Authentication.",
+ "properties": {
+ "forwardUsernameHeader": {
+ "description": "This field specifies the header name to forward a successfully authenticated user to\nthe backend. The header will be added to the request with the username as the value.\n\nIf it is not specified, the username will not be forwarded.",
+ "type": "string"
+ },
+ "users": {
+ "description": "The Kubernetes secret which contains the username-password pairs in\nhtpasswd format, used to verify user credentials in the \"Authorization\"\nheader.\n\nThis is an Opaque secret. The username-password pairs should be stored in\nthe key \".htpasswd\". As the key name indicates, the value needs to be the\nhtpasswd format, for example: \"user1:{SHA}hashed_user1_password\".\nRight now, only SHA hash algorithm is supported.\nReference to https://httpd.apache.org/docs/2.4/programs/htpasswd.html\nfor more details.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "users"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cors": {
+ "description": "CORS defines the configuration for Cross-Origin Resource Sharing (CORS).",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether a request can include user credentials\nlike cookies, authentication headers, or TLS client certificates.\nIt specifies the value in the Access-Control-Allow-Credentials CORS response header.",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders defines the headers that are allowed to be sent with requests.\nIt specifies the allowed headers in the Access-Control-Allow-Headers CORS response header..\nThe value \"*\" allows any header to be sent.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "allowMethods": {
+ "description": "AllowMethods defines the methods that are allowed to make requests.\nIt specifies the allowed methods in the Access-Control-Allow-Methods CORS response header..\nThe value \"*\" allows any method to be used.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins defines the origins that are allowed to make requests.\nIt specifies the allowed origins in the Access-Control-Allow-Origin CORS response header.\nThe value \"*\" allows any origin to make requests.",
+ "items": {
+ "description": "Origin is defined by the scheme (protocol), hostname (domain), and port of\nthe URL used to access it. The hostname can be \"precise\" which is just the\ndomain name or \"wildcard\" which is a domain name prefixed with a single\nwildcard label such as \"*.example.com\".\nIn addition to that a single wildcard (with or without scheme) can be\nconfigured to match any origin.\n\nFor example, the following are valid origins:\n- https://foo.example.com\n- https://*.example.com\n- http://foo.example.com:8080\n- http://*.example.com:8080\n- https://*",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*|https?:\\/\\/(\\*|(\\*\\.)?(([\\w-]+\\.?)+)?[\\w-]+)(:\\d{1,5})?)$",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders defines which response headers should be made accessible to\nscripts running in the browser.\nIt specifies the headers in the Access-Control-Expose-Headers CORS response header..\nThe value \"*\" allows any header to be exposed.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "maxAge": {
+ "description": "MaxAge defines how long the results of a preflight request can be cached.\nIt specifies the value in the Access-Control-Max-Age CORS response header..",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "extAuth": {
+ "description": "ExtAuth defines the configuration for External Authorization.",
+ "properties": {
+ "bodyToExtAuth": {
+ "description": "BodyToExtAuth defines the Body to Ext Auth configuration.",
+ "properties": {
+ "maxRequestBytes": {
+ "description": "MaxRequestBytes is the maximum size of a message body that the filter will hold in memory.\nEnvoy will return HTTP 413 and will not initiate the authorization process when buffer\nreaches the number set in this field.\nNote that this setting will have precedence over failOpen mode.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "maxRequestBytes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "contextExtensions": {
+ "description": "ContextExtensions are analogous to http_request.headers, however these\ncontents will not be sent to the upstream server. This provides an\nextension mechanism for sending additional information to the auth server\nwithout modifying the proto definition. It maps to the internal opaque\ncontext in the filter chain.",
+ "items": {
+ "description": "ContextExtension is analogous to http_request.headers, however these\ncontents will not be sent to the upstream server. This provides an\nextension mechanism for sending additional information to the auth server\nwithout modifying the proto definition. It maps to the internal opaque\ncontext in the filter chain.",
+ "properties": {
+ "name": {
+ "description": "Name of the context extension.",
+ "type": "string"
+ },
+ "type": {
+ "default": "Value",
+ "description": "Type is the type of method to use to read the ContextExtension value.\nValid values are Value and ValueRef, default is Value.",
+ "enum": [
+ "Value",
+ "ValueRef"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the context extension.",
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef for the context extension's value.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "key",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Only a reference to an object of kind ConfigMap or Secret belonging to default v1 API group is supported.",
+ "rule": "self.kind in ['ConfigMap', 'Secret'] && self.group in ['', 'v1']"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Exactly one of value or valueRef must be set with correct type.",
+ "rule": "(self.type == 'Value' && has(self.value) && !has(self.valueRef)) || (self.type == 'ValueRef' && !has(self.value) && has(self.valueRef))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "failOpen": {
+ "default": false,
+ "description": "FailOpen is a switch used to control the behavior when a response from the External Authorization service cannot be obtained.\nIf FailOpen is set to true, the system allows the traffic to pass through.\nOtherwise, if it is set to false or not set (defaulting to false),\nthe system blocks the traffic and returns a HTTP 5xx error, reflecting a fail-closed approach.\nThis setting determines whether to prioritize accessibility over strict security in case of authorization service failure.\n\nIf set to true, the External Authorization will also be bypassed if its configuration is invalid.",
+ "type": "boolean"
+ },
+ "grpc": {
+ "description": "GRPC defines the gRPC External Authorization service.\nEither GRPCService or HTTPService must be specified,\nand only one of them can be provided.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "backendRef or backendRefs needs to be set",
+ "rule": "has(self.backendRef) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs only supports Service, ServiceImport, and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'ServiceImport' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only supports Core, multicluster.x-k8s.io, and gateway.envoyproxy.io groups.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'multicluster.x-k8s.io' || f.group == 'gateway.envoyproxy.io')) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headersToExtAuth": {
+ "description": "HeadersToExtAuth defines the client request headers that will be included\nin the request to the external authorization service.\nNote: If not specified, the default behavior for gRPC and HTTP external\nauthorization services is different due to backward compatibility reasons.\nAll headers will be included in the check request to a gRPC authorization server.\nOnly the following headers will be included in the check request to an HTTP\nauthorization server: Host, Method, Path, Content-Length, and Authorization.\nAnd these headers will always be included to the check request to an HTTP\nauthorization server by default, no matter whether they are specified\nin HeadersToExtAuth or not.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "http": {
+ "description": "HTTP defines the HTTP External Authorization service.\nEither GRPCService or HTTPService must be specified,\nand only one of them can be provided.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headersToBackend": {
+ "description": "HeadersToBackend are the authorization response headers that will be added\nto the original client request before sending it to the backend server.\nNote that coexisting headers will be overridden.\nIf not specified, no authorization response headers will be added to the\noriginal client request.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "path": {
+ "description": "Path is the path of the HTTP External Authorization service.\nIf path is specified, the authorization request will be sent to that path,\nor else the authorization request will use the path of the original request.\n\nPlease note that the original request path will be appended to the path specified here.\nFor example, if the original request path is \"/hello\", and the path specified here is \"/auth\",\nthen the path of the authorization request will be \"/auth/hello\". If the path is not specified,\nthe path of the authorization request will be \"/hello\".\nOnly one of Path or PathOverride can be set.",
+ "type": "string"
+ },
+ "pathOverride": {
+ "description": "PathOverride replaces the original request path in the authorization request.\nIf set, the path will be overridden to this value during authorization.\nFor example, if the original request path is \"/hello\", and PathOverride is set to \"/auth\",\nthen the path of the authorization request will be \"/auth\".\nOnly one of Path or PathOverride can be set.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "backendRef or backendRefs needs to be set",
+ "rule": "has(self.backendRef) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs only supports Service, ServiceImport, and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'ServiceImport' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only supports Core, multicluster.x-k8s.io, and gateway.envoyproxy.io groups.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'multicluster.x-k8s.io' || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "only one of path or pathOverride can be specified",
+ "rule": "!(has(self.path) && has(self.pathOverride))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "includeRouteMetadata": {
+ "description": "IncludeRouteMetadata sends Envoy Gateway's built-in route metadata to the\nexternal authorization service as context.\n\nThis includes Envoy Gateway's built-in metadata for the selected route in\nthe \"envoy-gateway\" metadata namespace.\n\nThe metadata is exposed under the \"resources\" field as a list of route\nresource objects. For example:\n\nenvoy-gateway:\n resources:\n - kind: HTTPRoute\n name: backend\n namespace: default\n annotations:\n foo: bar\n\nThe resource object may include fields such as kind, namespace, name,\nsectionName, and supported route annotations.",
+ "type": "boolean"
+ },
+ "recomputeRoute": {
+ "description": "RecomputeRoute clears the route cache and recalculates the routing decision.\nThis field must be enabled if the headers added or modified by the ExtAuth are used for\nroute matching decisions. If the recomputation selects a new route, features targeting\nthe new matched route will be applied.",
+ "type": "boolean"
+ },
+ "statusOnError": {
+ "description": "Sets the HTTP status that is returned when the authorization service returns an error\nor cannot be reached. Defaults to 403 Forbidden.\nOnly 4xx and 5xx status codes are supported.",
+ "enum": [
+ 400,
+ 401,
+ 402,
+ 403,
+ 404,
+ 405,
+ 406,
+ 407,
+ 408,
+ 409,
+ 410,
+ 411,
+ 412,
+ 413,
+ 414,
+ 415,
+ 416,
+ 417,
+ 421,
+ 422,
+ 423,
+ 424,
+ 426,
+ 428,
+ 429,
+ 431,
+ 500,
+ 501,
+ 502,
+ 503,
+ 504,
+ 505,
+ 506,
+ 507,
+ 508,
+ 510,
+ 511
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout defines the timeout for requests to the external authorization service.\nIf not specified, defaults to 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "one of grpc or http must be specified",
+ "rule": "(has(self.grpc) || has(self.http))"
+ },
+ {
+ "message": "only one of grpc or http can be specified",
+ "rule": "(has(self.grpc) && !has(self.http)) || (!has(self.grpc) && has(self.http))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "jwt": {
+ "description": "JWT defines the configuration for JSON Web Token (JWT) authentication.",
+ "properties": {
+ "optional": {
+ "description": "Optional determines whether a missing JWT is acceptable, defaulting to false if not specified.\nNote: Even if optional is set to true, JWT authentication will still fail if an invalid JWT is presented.",
+ "type": "boolean"
+ },
+ "providers": {
+ "description": "Providers defines the JSON Web Token (JWT) authentication provider type.\nWhen multiple JWT providers are specified, the JWT is considered valid if\nany of the providers successfully validate the JWT. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/jwt_authn_filter.html.",
+ "items": {
+ "description": "JWTProvider defines how a JSON Web Token (JWT) can be verified.",
+ "properties": {
+ "audiences": {
+ "description": "Audiences is a list of JWT audiences allowed access. For additional details, see\nhttps://tools.ietf.org/html/rfc7519#section-4.1.3. If not provided, JWT audiences\nare not checked.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "claimToHeaders": {
+ "description": "ClaimToHeaders is a list of JWT claims that must be extracted into HTTP request headers\nFor examples, following config:\nThe claim must be of type; string, int, double, bool. Array type claims are not supported",
+ "items": {
+ "description": "ClaimToHeader defines a configuration to convert JWT claims into HTTP headers",
+ "properties": {
+ "claim": {
+ "description": "Claim is the JWT Claim that should be saved into the header : it can be a nested claim of type\n(eg. \"claim.nested.key\", \"sub\"). The nested claim name must use dot \".\"\nto separate the JSON name path.",
+ "type": "string"
+ },
+ "header": {
+ "description": "Header defines the name of the HTTP request header that the JWT Claim will be saved into.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "claim",
+ "header"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "extractFrom": {
+ "description": "ExtractFrom defines different ways to extract the JWT token from HTTP request.\nIf empty, it defaults to extract JWT token from the Authorization HTTP request header using Bearer schema\nor access_token from query parameters.",
+ "properties": {
+ "cookies": {
+ "description": "Cookies represents a list of cookie names to extract the JWT token from.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "headers": {
+ "description": "Headers represents a list of HTTP request headers to extract the JWT token from.",
+ "items": {
+ "description": "JWTHeaderExtractor defines an HTTP header location to extract JWT token",
+ "properties": {
+ "name": {
+ "description": "Name is the HTTP header name to retrieve the token",
+ "type": "string"
+ },
+ "valuePrefix": {
+ "description": "ValuePrefix is the prefix that should be stripped before extracting the token.\nThe format would be used by Envoy like \"{ValuePrefix}\".\nFor example, \"Authorization: Bearer \", then the ValuePrefix=\"Bearer \" with a space at the end.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "params": {
+ "description": "Params represents a list of query parameters to extract the JWT token from.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "issuer": {
+ "description": "Issuer is the principal that issued the JWT and takes the form of a URL or email address.\nFor additional details, see https://tools.ietf.org/html/rfc7519#section-4.1.1 for\nURL format and https://rfc-editor.org/rfc/rfc5322.html for email format. If not provided,\nthe JWT issuer is not checked.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "localJWKS": {
+ "description": "LocalJWKS defines how to get the JSON Web Key Sets (JWKS) from a local source.",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the value as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the body value.\nValid values are Inline and ValueRef, default is Inline.",
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ],
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef is a reference to a local ConfigMap that contains the JSON Web Key Sets (JWKS).\n\nThe value of key `jwks` in the ConfigMap will be used.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Exactly one of inline or valueRef must be set with correct type.",
+ "rule": "(self.type == 'Inline' && has(self.inline) && !has(self.valueRef)) || (self.type == 'ValueRef' && !has(self.inline) && has(self.valueRef))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Name defines a unique name for the JWT provider. A name can have a variety of forms,\nincluding RFC1123 subdomains, RFC 1123 labels, or RFC 1035 labels.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "recomputeRoute": {
+ "description": "RecomputeRoute clears the route cache and recalculates the routing decision.\nThis field must be enabled if the headers generated from the claim are used for\nroute matching decisions. If the recomputation selects a new route, features targeting\nthe new matched route will be applied.",
+ "type": "boolean"
+ },
+ "remoteJWKS": {
+ "description": "RemoteJWKS defines how to fetch and cache JSON Web Key Sets (JWKS) from a remote\nHTTP/HTTPS endpoint.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "cacheDuration": {
+ "default": "300s",
+ "description": "Duration is a string value representing a duration in time. The format is as specified\nin GEP-2257, a strict subset of the syntax parsed by Golang time.ParseDuration.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "uri": {
+ "description": "URI is the HTTPS URI to fetch the JWKS. Envoy's system trust bundle is used to validate the server certificate.\nIf a custom trust bundle is needed, it can be specified in a BackendTLSConfig resource and target the BackendRefs.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "uri"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "Retry timeout is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.perRetry)? !has(self.backendSettings.retry.perRetry.timeout):true):true):true"
+ },
+ {
+ "message": "HTTPStatusCodes is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.retryOn)? !has(self.backendSettings.retry.retryOn.httpStatusCodes):true):true):true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "claimToHeaders must be specified if recomputeRoute is enabled.",
+ "rule": "(has(self.recomputeRoute) && self.recomputeRoute) ? size(self.claimToHeaders) > 0 : true"
+ },
+ {
+ "message": "either remoteJWKS or localJWKS must be specified.",
+ "rule": "has(self.remoteJWKS) || has(self.localJWKS)"
+ },
+ {
+ "message": "remoteJWKS and localJWKS cannot both be specified.",
+ "rule": "!(has(self.remoteJWKS) && has(self.localJWKS))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "providers"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "mergeType": {
+ "description": "MergeType determines how this configuration is merged with existing SecurityPolicy\nconfigurations targeting a parent resource. When set, this configuration will be merged\ninto a parent SecurityPolicy (i.e. the one targeting a Gateway or Listener).\nThis field cannot be set when targeting a parent resource (Gateway).\nIf unset, no merging occurs, and only the most specific configuration takes effect.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Replace is not a valid MergeType for SecurityPolicy",
+ "rule": "self != 'Replace'"
+ }
+ ]
+ },
+ "oidc": {
+ "description": "OIDC defines the configuration for the OpenID Connect (OIDC) authentication.",
+ "properties": {
+ "clientID": {
+ "description": "The client ID to be used in the OIDC\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\n\nOnly one of clientID or clientIDRef must be set.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "clientIDRef": {
+ "description": "The Kubernetes secret which contains the client ID to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nExactly one of clientID or clientIDRef must be set.\nThis is an Opaque secret. The client ID should be stored in the key \"client-id\".\n\nOnly one of clientID or clientIDRef must be set.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "clientSecret": {
+ "description": "The Kubernetes secret which contains the OIDC client secret to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\n\nThis is an Opaque secret. The client secret should be stored in the key\n\"client-secret\".",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cookieConfig": {
+ "description": "CookieConfigs allows setting the SameSite attribute for OIDC cookies.\nBy default, its unset.",
+ "properties": {
+ "sameSite": {
+ "enum": [
+ "Lax",
+ "Strict",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cookieDomain": {
+ "description": "The optional domain to set the access and ID token cookies on.\nIf not set, the cookies will default to the host of the request, not including the subdomains.\nIf set, the cookies will be set on the specified domain and all subdomains.\nThis means that requests to any subdomain will not require reauthentication after users log in to the parent domain.",
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9]))*$",
+ "type": "string"
+ },
+ "cookieNames": {
+ "description": "The optional cookie name overrides to be used for Bearer and IdToken cookies in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, uses a randomly generated suffix",
+ "properties": {
+ "accessToken": {
+ "description": "The name of the cookie used to store the AccessToken in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, defaults to \"AccessToken-(randomly generated uid)\"",
+ "type": "string"
+ },
+ "idToken": {
+ "description": "The name of the cookie used to store the IdToken in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, defaults to \"IdToken-(randomly generated uid)\"",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "csrfTokenTTL": {
+ "description": "CSRFTokenTTL defines how long the CSRF token generated during the OAuth2 authorization flow remains valid.\n\nThis duration determines the lifetime of the CSRF cookie, which is validated against the CSRF token\nin the \"state\" parameter when the provider redirects back to the callback endpoint.\n\nIf omitted, Envoy Gateway defaults the token expiration to 10 minutes.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "defaultRefreshTokenTTL": {
+ "description": "DefaultRefreshTokenTTL is the default lifetime of the refresh token.\nThis field is only used when the exp (expiration time) claim is omitted in\nthe refresh token or the refresh token is not JWT.\n\nIf not specified, defaults to 604800s (one week).\nNote: this field is only applicable when the \"refreshToken\" field is set to true.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "defaultTokenTTL": {
+ "description": "DefaultTokenTTL is the default lifetime of the id token and access token.\nPlease note that Envoy will always use the expiry time from the response\nof the authorization server if it is provided. This field is only used when\nthe expiry time is not provided by the authorization.\n\nIf not specified, defaults to 0. In this case, the \"expires_in\" field in\nthe authorization response must be set by the authorization server, or the\nOAuth flow will fail.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "denyRedirect": {
+ "description": "Any request that matches any of the provided matchers (with either tokens that are expired or missing tokens) will not be redirected to the OIDC Provider.\nThis behavior can be useful for AJAX or machine requests.",
+ "properties": {
+ "headers": {
+ "description": "Defines the headers to match against the request to deny redirect to the OIDC Provider.",
+ "items": {
+ "description": "OIDCDenyRedirectHeader defines how a header is matched",
+ "properties": {
+ "name": {
+ "description": "Specifies the name of the header in the request.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "headers"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "disableTokenEncryption": {
+ "description": "Disable token encryption. When set to true, both the access token and the ID token will be stored in plain text.\nThis option should only be used in secure environments where token encryption is not required.\nDefault is false (tokens are encrypted).",
+ "type": "boolean"
+ },
+ "forwardAccessToken": {
+ "description": "ForwardAccessToken indicates whether the Envoy should forward the access token\nvia the Authorization header Bearer scheme to the upstream.\nIf not specified, defaults to false.",
+ "type": "boolean"
+ },
+ "forwardIDToken": {
+ "description": "ForwardIDToken configures forwarding of the OIDC ID token to the upstream.\n\nIf the configured header is \"Authorization\", EG forwards the ID token using\nthe \"Bearer \" prefix. For any other header, EG forwards the raw token value.\nIf not specified, the ID token will not be forwarded.",
+ "properties": {
+ "header": {
+ "description": "Header is the upstream request header that will carry the ID token.",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "header"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "logoutPath": {
+ "description": "The path to log a user out, clearing their credential cookies.\n\nIf not specified, uses a default logout path \"/logout\"",
+ "type": "string"
+ },
+ "passThroughAuthHeader": {
+ "description": "Skips OIDC authentication when the request contains a header that will be extracted by the JWT filter. Unless\nexplicitly stated otherwise in the extractFrom field, this will be the \"Authorization: Bearer ...\" header.\n\nThe passThroughAuthHeader option is typically used for non-browser clients that may not be able to handle OIDC\nredirects and wish to directly supply a token instead.\n\nIf not specified, defaults to false.",
+ "type": "boolean"
+ },
+ "provider": {
+ "description": "The OIDC Provider configuration.",
+ "properties": {
+ "authorizationEndpoint": {
+ "description": "The OIDC Provider's [authorization endpoint](https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint).\nIf not provided, EG will try to discover it from the provider's [Well-Known Configuration Endpoint](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse).",
+ "type": "string"
+ },
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "endSessionEndpoint": {
+ "description": "The OIDC Provider's [end session endpoint](https://openid.net/specs/openid-connect-core-1_0.html#RPLogout).\n\nIf the end session endpoint is provided, EG will use it to log out the user from the OIDC Provider when the user accesses the logout path.\nEG will also try to discover the end session endpoint from the provider's [Well-Known Configuration Endpoint](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse) when authorizationEndpoint or tokenEndpoint is not provided.",
+ "type": "string"
+ },
+ "issuer": {
+ "description": "The OIDC Provider's [issuer identifier](https://openid.net/specs/openid-connect-discovery-1_0.html#IssuerDiscovery).\nIssuer MUST be a URI RFC 3986 [RFC3986] with a scheme component that MUST\nbe https, a host component, and optionally, port and path components and\nno query or fragment components.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "tokenEndpoint": {
+ "description": "The OIDC Provider's [token endpoint](https://openid.net/specs/openid-connect-core-1_0.html#TokenEndpoint).\nIf not provided, EG will try to discover it from the provider's [Well-Known Configuration Endpoint](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "issuer"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "Retry timeout is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.perRetry)? !has(self.backendSettings.retry.perRetry.timeout):true):true):true"
+ },
+ {
+ "message": "HTTPStatusCodes is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.retryOn)? !has(self.backendSettings.retry.retryOn.httpStatusCodes):true):true):true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "redirectURL": {
+ "description": "The redirect URL to be used in the OIDC\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, uses the default redirect URI \"%REQ(x-forwarded-proto)%://%REQ(:authority)%/oauth2/callback\"",
+ "type": "string"
+ },
+ "refreshToken": {
+ "default": true,
+ "description": "RefreshToken indicates whether the Envoy should automatically refresh the\nid token and access token when they expire.\nWhen set to true, the Envoy will use the refresh token to get a new id token\nand access token when they expire.\n\nIf not specified, defaults to true.",
+ "type": "boolean"
+ },
+ "resources": {
+ "description": "The OIDC resources to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "scopes": {
+ "description": "The OIDC scopes to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nThe \"openid\" scope is always added to the list of scopes if not already\nspecified.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "clientSecret",
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of clientID or clientIDRef must be set",
+ "rule": "(has(self.clientID) && !has(self.clientIDRef)) || (!has(self.clientID) && has(self.clientIDRef))"
+ },
+ {
+ "message": "forwardAccessToken cannot be true when forwardIDToken.header is Authorization",
+ "rule": "!(has(self.forwardAccessToken) && self.forwardAccessToken && has(self.forwardIDToken) && self.forwardIDToken.header.lowerAscii() == 'authorization')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true"
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute",
+ "rule": "has(self.targetRef) ? self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'TCPRoute'] : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true "
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'TCPRoute']) : true "
+ },
+ {
+ "message": "if authorization.rules.principal.jwt is used, jwt must be defined",
+ "rule": "(has(self.authorization) && has(self.authorization.rules) && self.authorization.rules.exists(r, has(r.principal.jwt))) ? has(self.jwt) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of SecurityPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/backendtlspolicy_v1.json b/crdSchemas/gateway.networking.k8s.io/backendtlspolicy_v1.json
similarity index 84%
rename from crdSchemas/backendtlspolicy_v1.json
rename to crdSchemas/gateway.networking.k8s.io/backendtlspolicy_v1.json
index b310b7f..8ba29db 100644
--- a/crdSchemas/backendtlspolicy_v1.json
+++ b/crdSchemas/gateway.networking.k8s.io/backendtlspolicy_v1.json
@@ -27,7 +27,7 @@
"type": "object"
},
"targetRefs": {
- "description": "TargetRefs identifies an API object to apply the policy to.\nOnly Services have Extended support. Implementations MAY support\nadditional objects, with Implementation Specific support.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {name}.\n For example, a policy named `bar` is given precedence over a\n policy named `baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nSupport: Extended for Kubernetes Service\n\nSupport: Implementation-specific for any other resource",
+ "description": "TargetRefs identifies an API object to apply the policy to.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {namespace}/{name}.\n For example, a policy named `foo/bar` is given precedence over a\n policy named `foo/baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nImplementations SHOULD NOT support more than one targetRef at this\ntime. Although the API technically allows for this, the current guidance\nfor conflict resolution and status handling is lacking. Until that can be\nclarified in a future release, the safest approach is to support a single\ntargetRef.\n\nSupport Levels:\n\n* Extended: Kubernetes Service referenced by HTTPRoute backendRefs.\n\n* Implementation-Specific: Services not connected via HTTPRoute, and any\n other kind of backend. Implementations MAY use BackendTLSPolicy for:\n - Services not referenced by any Route (e.g., infrastructure services)\n - Gateway feature backends (e.g., ExternalAuth, rate-limiting services)\n - Service mesh workload-to-service communication\n - Other resource types beyond Service\n\nImplementations SHOULD aim to ensure that BackendTLSPolicy behavior is consistent,\neven outside of the extended HTTPRoute -(backendRef) -> Service path.\nThey SHOULD clearly document how BackendTLSPolicy is interpreted in these\nscenarios, including:\n - Which resources beyond Service are supported\n - How the policy is discovered and applied\n - Any implementation-specific semantics or restrictions\n\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.",
"items": {
"description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
"properties": {
@@ -185,10 +185,10 @@
"x-kubernetes-list-type": "atomic"
},
"wellKnownCACertificates": {
- "description": "WellKnownCACertificates specifies whether system CA certificates may be used in\nthe TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nSupport: Implementation-specific",
- "enum": [
- "System"
- ],
+ "description": "WellKnownCACertificates specifies whether a well-known set of CA certificates\nmay be used in the TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nValid values include:\n* \"System\" - indicates that well-known system CA certificates should be used.\n\nImplementations MAY define their own sets of CA certificates. Such definitions\nMUST use an implementation-specific, prefixed name, such as\n`mycompany.com/my-custom-ca-certificates`.\n\nSupport: Implementation-specific",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(System|([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]))$",
"type": "string"
}
},
@@ -249,14 +249,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/backendtlspolicy_v1alpha3.json b/crdSchemas/gateway.networking.k8s.io/backendtlspolicy_v1alpha3.json
similarity index 84%
rename from crdSchemas/backendtlspolicy_v1alpha3.json
rename to crdSchemas/gateway.networking.k8s.io/backendtlspolicy_v1alpha3.json
index b310b7f..8ba29db 100644
--- a/crdSchemas/backendtlspolicy_v1alpha3.json
+++ b/crdSchemas/gateway.networking.k8s.io/backendtlspolicy_v1alpha3.json
@@ -27,7 +27,7 @@
"type": "object"
},
"targetRefs": {
- "description": "TargetRefs identifies an API object to apply the policy to.\nOnly Services have Extended support. Implementations MAY support\nadditional objects, with Implementation Specific support.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {name}.\n For example, a policy named `bar` is given precedence over a\n policy named `baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nSupport: Extended for Kubernetes Service\n\nSupport: Implementation-specific for any other resource",
+ "description": "TargetRefs identifies an API object to apply the policy to.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {namespace}/{name}.\n For example, a policy named `foo/bar` is given precedence over a\n policy named `foo/baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nImplementations SHOULD NOT support more than one targetRef at this\ntime. Although the API technically allows for this, the current guidance\nfor conflict resolution and status handling is lacking. Until that can be\nclarified in a future release, the safest approach is to support a single\ntargetRef.\n\nSupport Levels:\n\n* Extended: Kubernetes Service referenced by HTTPRoute backendRefs.\n\n* Implementation-Specific: Services not connected via HTTPRoute, and any\n other kind of backend. Implementations MAY use BackendTLSPolicy for:\n - Services not referenced by any Route (e.g., infrastructure services)\n - Gateway feature backends (e.g., ExternalAuth, rate-limiting services)\n - Service mesh workload-to-service communication\n - Other resource types beyond Service\n\nImplementations SHOULD aim to ensure that BackendTLSPolicy behavior is consistent,\neven outside of the extended HTTPRoute -(backendRef) -> Service path.\nThey SHOULD clearly document how BackendTLSPolicy is interpreted in these\nscenarios, including:\n - Which resources beyond Service are supported\n - How the policy is discovered and applied\n - Any implementation-specific semantics or restrictions\n\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.",
"items": {
"description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
"properties": {
@@ -185,10 +185,10 @@
"x-kubernetes-list-type": "atomic"
},
"wellKnownCACertificates": {
- "description": "WellKnownCACertificates specifies whether system CA certificates may be used in\nthe TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nSupport: Implementation-specific",
- "enum": [
- "System"
- ],
+ "description": "WellKnownCACertificates specifies whether a well-known set of CA certificates\nmay be used in the TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nValid values include:\n* \"System\" - indicates that well-known system CA certificates should be used.\n\nImplementations MAY define their own sets of CA certificates. Such definitions\nMUST use an implementation-specific, prefixed name, such as\n`mycompany.com/my-custom-ca-certificates`.\n\nSupport: Implementation-specific",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(System|([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]))$",
"type": "string"
}
},
@@ -249,14 +249,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/gateway_v1.json b/crdSchemas/gateway.networking.k8s.io/gateway_v1.json
similarity index 63%
rename from crdSchemas/gateway_v1.json
rename to crdSchemas/gateway.networking.k8s.io/gateway_v1.json
index 7ed11b5..0722a8f 100644
--- a/crdSchemas/gateway_v1.json
+++ b/crdSchemas/gateway.networking.k8s.io/gateway_v1.json
@@ -89,6 +89,89 @@
}
]
},
+ "allowedListeners": {
+ "description": "AllowedListeners defines which ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "namespaces": {
+ "default": {
+ "from": "None"
+ },
+ "description": "Namespaces defines which namespaces ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "from": {
+ "default": "None",
+ "description": "From indicates where ListenerSets can attach to this Gateway. Possible\nvalues are:\n\n* Same: Only ListenerSets in the same namespace may be attached to this Gateway.\n* Selector: ListenerSets in namespaces selected by the selector may be attached to this Gateway.\n* All: ListenerSets in all namespaces may be attached to this Gateway.\n* None: Only listeners defined in the Gateway's spec are allowed\n\nThe default value None",
+ "enum": [
+ "All",
+ "Selector",
+ "Same",
+ "None"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector must be specified when From is set to \"Selector\". In that case,\nonly ListenerSets in Namespaces matching this Selector will be selected by this\nGateway. This field is ignored for other values of \"From\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "defaultScope": {
+ "description": "DefaultScope, when set, configures the Gateway as a default Gateway,\nmeaning it will dynamically and implicitly have Routes (e.g. HTTPRoute)\nattached to it, according to the scope configured here.\n\nIf unset (the default) or set to None, the Gateway will not act as a\ndefault Gateway; if set, the Gateway will claim any Route with a\nmatching scope set in its UseDefaultGateway field, subject to the usual\nrules about which routes the Gateway can attach to.\n\nThink carefully before using this functionality! While the normal rules\nabout which Route can apply are still enforced, it is simply easier for\nthe wrong Route to be accidentally attached to this Gateway in this\nconfiguration. If the Gateway operator is not also the operator in\ncontrol of the scope (e.g. namespace) with tight controls and checks on\nwhat kind of workloads and Routes get added in that scope, we strongly\nrecommend not using this just because it seems convenient, and instead\nstick to direct Route attachment.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ },
"gatewayClassName": {
"description": "GatewayClassName used for this Gateway. This is the name of a\nGatewayClass resource.",
"maxLength": 253,
@@ -291,7 +374,7 @@
"additionalProperties": false
},
"hostname": {
- "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
+ "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host, the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
"maxLength": 253,
"minLength": 1,
"pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
@@ -420,6 +503,10 @@
"message": "tls mode must be Terminate for protocol HTTPS",
"rule": "self.all(l, (l.protocol == 'HTTPS' && has(l.tls)) ? (l.tls.mode == '' || l.tls.mode == 'Terminate') : true)"
},
+ {
+ "message": "tls mode must be set for protocol TLS",
+ "rule": "self.all(l, (l.protocol == 'TLS' ? has(l.tls) && has(l.tls.mode) && l.tls.mode != '' : true))"
+ },
{
"message": "hostname must not be specified for protocols ['TCP', 'UDP']",
"rule": "self.all(l, l.protocol in ['TCP', 'UDP'] ? (!has(l.hostname) || l.hostname == '') : true)"
@@ -433,6 +520,242 @@
"rule": "self.all(l1, self.exists_one(l2, l1.port == l2.port && l1.protocol == l2.protocol && (has(l1.hostname) && has(l2.hostname) ? l1.hostname == l2.hostname : !has(l1.hostname) && !has(l2.hostname))))"
}
]
+ },
+ "tls": {
+ "description": "TLS specifies frontend and backend tls configuration for entire gateway.\n\nSupport: Extended",
+ "properties": {
+ "backend": {
+ "description": "Backend describes TLS configuration for gateway when connecting\nto backends.\n\nNote that this contains only details for the Gateway as a TLS client,\nand does _not_ imply behavior about how to choose which backend should\nget a TLS connection. That is determined by the presence of a BackendTLSPolicy.\n\nSupport: Core",
+ "properties": {
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef references an object that contains a client certificate\nand its associated private key. It can reference standard Kubernetes resources,\ni.e., Secret, or implementation-specific custom resources.\n\nA ClientCertificateRef is considered invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the referenced resource\n does not exist) or is misconfigured (e.g., a Secret does not contain the keys\n named `tls.crt` and `tls.key`). In this case, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `InvalidClientCertificateRef`\n and the Message of the Condition MUST indicate why the reference is invalid.\n\n* It refers to a resource in another namespace UNLESS there is a ReferenceGrant\n in the target namespace that allows the certificate to be attached.\n If a ReferenceGrant does not allow this reference, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the certificate\ncontent (e.g., checking expiry or enforcing specific formats). In such cases,\nan implementation-specific Reason and Message MUST be set.\n\nSupport: Core - Reference to a Kubernetes TLS Secret (with the type `kubernetes.io/tls`).\nSupport: Implementation-specific - Other resource kinds or Secrets with a\ndifferent type (e.g., `Opaque`).",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "frontend": {
+ "description": "Frontend describes TLS config when client connects to Gateway.\nSupport: Core",
+ "properties": {
+ "default": {
+ "description": "Default specifies the default client certificate validation configuration\nfor all Listeners handling HTTPS traffic, unless a per-port configuration\nis defined.\n\nsupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "perPort": {
+ "description": "PerPort specifies tls configuration assigned per port.\nPer port configuration is optional. Once set this configuration overrides\nthe default configuration for all Listeners handling HTTPS traffic\nthat match this port.\nEach override port requires a unique TLS configuration.\n\nsupport: Core",
+ "items": {
+ "properties": {
+ "port": {
+ "description": "The Port indicates the Port Number to which the TLS configuration will be\napplied. This configuration will be applied to all Listeners handling HTTPS\ntraffic that match this port.\n\nSupport: Core",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS store the configuration that will be applied to all Listeners handling\nHTTPS traffic and matching given port.\n\nSupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "port",
+ "tls"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "port"
+ ],
+ "x-kubernetes-list-type": "map",
+ "x-kubernetes-validations": [
+ {
+ "message": "Port for TLS configuration must be unique within the Gateway",
+ "rule": "self.all(t1, self.exists_one(t2, t1.port == t2.port))"
+ }
+ ]
+ }
+ },
+ "required": [
+ "default"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
}
},
"required": [
@@ -531,6 +854,11 @@
"type": "array",
"x-kubernetes-list-type": "atomic"
},
+ "attachedListenerSets": {
+ "description": "AttachedListenerSets represents the total number of ListenerSets that have been\nsuccessfully attached to this Gateway.\n\nA ListenerSet is successfully attached to a Gateway when all the following conditions are met:\n- The ListenerSet is selected by the Gateway's AllowedListeners field\n- The ListenerSet has a valid ParentRef selecting the Gateway\n- The ListenerSet's status has the condition \"Accepted: true\"\n\nUses for this field include troubleshooting AttachedListenerSets attachment and\nmeasuring blast radius/impact of changes to a Gateway.",
+ "format": "int32",
+ "type": "integer"
+ },
"conditions": {
"default": [
{
@@ -614,7 +942,7 @@
"description": "ListenerStatus is the status associated with a Listener.",
"properties": {
"attachedRoutes": {
- "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners with condition Accepted: false and MUST count successfully\nattached Routes that may themselves have Accepted: false conditions.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
+ "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners, even if the Accepted condition of an individual Listener is set\nto \"False\". The AttachedRoutes number represents the number of Routes with\nthe Accepted condition set to \"True\" that have been attached to this Listener.\nRoutes with any other value for the Accepted condition MUST NOT be included\nin this count.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
"format": "int32",
"type": "integer"
},
@@ -687,7 +1015,7 @@
"type": "string"
},
"supportedKinds": {
- "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds an implementation supports for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
+ "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds supported by an implementation for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
"items": {
"description": "RouteGroupKind indicates the group and kind of a Route resource.",
"properties": {
@@ -720,8 +1048,7 @@
"required": [
"attachedRoutes",
"conditions",
- "name",
- "supportedKinds"
+ "name"
],
"type": "object",
"additionalProperties": false
diff --git a/crdSchemas/gateway_v1beta1.json b/crdSchemas/gateway.networking.k8s.io/gateway_v1beta1.json
similarity index 63%
rename from crdSchemas/gateway_v1beta1.json
rename to crdSchemas/gateway.networking.k8s.io/gateway_v1beta1.json
index 7ed11b5..0722a8f 100644
--- a/crdSchemas/gateway_v1beta1.json
+++ b/crdSchemas/gateway.networking.k8s.io/gateway_v1beta1.json
@@ -89,6 +89,89 @@
}
]
},
+ "allowedListeners": {
+ "description": "AllowedListeners defines which ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "namespaces": {
+ "default": {
+ "from": "None"
+ },
+ "description": "Namespaces defines which namespaces ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "from": {
+ "default": "None",
+ "description": "From indicates where ListenerSets can attach to this Gateway. Possible\nvalues are:\n\n* Same: Only ListenerSets in the same namespace may be attached to this Gateway.\n* Selector: ListenerSets in namespaces selected by the selector may be attached to this Gateway.\n* All: ListenerSets in all namespaces may be attached to this Gateway.\n* None: Only listeners defined in the Gateway's spec are allowed\n\nThe default value None",
+ "enum": [
+ "All",
+ "Selector",
+ "Same",
+ "None"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector must be specified when From is set to \"Selector\". In that case,\nonly ListenerSets in Namespaces matching this Selector will be selected by this\nGateway. This field is ignored for other values of \"From\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "defaultScope": {
+ "description": "DefaultScope, when set, configures the Gateway as a default Gateway,\nmeaning it will dynamically and implicitly have Routes (e.g. HTTPRoute)\nattached to it, according to the scope configured here.\n\nIf unset (the default) or set to None, the Gateway will not act as a\ndefault Gateway; if set, the Gateway will claim any Route with a\nmatching scope set in its UseDefaultGateway field, subject to the usual\nrules about which routes the Gateway can attach to.\n\nThink carefully before using this functionality! While the normal rules\nabout which Route can apply are still enforced, it is simply easier for\nthe wrong Route to be accidentally attached to this Gateway in this\nconfiguration. If the Gateway operator is not also the operator in\ncontrol of the scope (e.g. namespace) with tight controls and checks on\nwhat kind of workloads and Routes get added in that scope, we strongly\nrecommend not using this just because it seems convenient, and instead\nstick to direct Route attachment.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ },
"gatewayClassName": {
"description": "GatewayClassName used for this Gateway. This is the name of a\nGatewayClass resource.",
"maxLength": 253,
@@ -291,7 +374,7 @@
"additionalProperties": false
},
"hostname": {
- "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
+ "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host, the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
"maxLength": 253,
"minLength": 1,
"pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
@@ -420,6 +503,10 @@
"message": "tls mode must be Terminate for protocol HTTPS",
"rule": "self.all(l, (l.protocol == 'HTTPS' && has(l.tls)) ? (l.tls.mode == '' || l.tls.mode == 'Terminate') : true)"
},
+ {
+ "message": "tls mode must be set for protocol TLS",
+ "rule": "self.all(l, (l.protocol == 'TLS' ? has(l.tls) && has(l.tls.mode) && l.tls.mode != '' : true))"
+ },
{
"message": "hostname must not be specified for protocols ['TCP', 'UDP']",
"rule": "self.all(l, l.protocol in ['TCP', 'UDP'] ? (!has(l.hostname) || l.hostname == '') : true)"
@@ -433,6 +520,242 @@
"rule": "self.all(l1, self.exists_one(l2, l1.port == l2.port && l1.protocol == l2.protocol && (has(l1.hostname) && has(l2.hostname) ? l1.hostname == l2.hostname : !has(l1.hostname) && !has(l2.hostname))))"
}
]
+ },
+ "tls": {
+ "description": "TLS specifies frontend and backend tls configuration for entire gateway.\n\nSupport: Extended",
+ "properties": {
+ "backend": {
+ "description": "Backend describes TLS configuration for gateway when connecting\nto backends.\n\nNote that this contains only details for the Gateway as a TLS client,\nand does _not_ imply behavior about how to choose which backend should\nget a TLS connection. That is determined by the presence of a BackendTLSPolicy.\n\nSupport: Core",
+ "properties": {
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef references an object that contains a client certificate\nand its associated private key. It can reference standard Kubernetes resources,\ni.e., Secret, or implementation-specific custom resources.\n\nA ClientCertificateRef is considered invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the referenced resource\n does not exist) or is misconfigured (e.g., a Secret does not contain the keys\n named `tls.crt` and `tls.key`). In this case, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `InvalidClientCertificateRef`\n and the Message of the Condition MUST indicate why the reference is invalid.\n\n* It refers to a resource in another namespace UNLESS there is a ReferenceGrant\n in the target namespace that allows the certificate to be attached.\n If a ReferenceGrant does not allow this reference, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the certificate\ncontent (e.g., checking expiry or enforcing specific formats). In such cases,\nan implementation-specific Reason and Message MUST be set.\n\nSupport: Core - Reference to a Kubernetes TLS Secret (with the type `kubernetes.io/tls`).\nSupport: Implementation-specific - Other resource kinds or Secrets with a\ndifferent type (e.g., `Opaque`).",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "frontend": {
+ "description": "Frontend describes TLS config when client connects to Gateway.\nSupport: Core",
+ "properties": {
+ "default": {
+ "description": "Default specifies the default client certificate validation configuration\nfor all Listeners handling HTTPS traffic, unless a per-port configuration\nis defined.\n\nsupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "perPort": {
+ "description": "PerPort specifies tls configuration assigned per port.\nPer port configuration is optional. Once set this configuration overrides\nthe default configuration for all Listeners handling HTTPS traffic\nthat match this port.\nEach override port requires a unique TLS configuration.\n\nsupport: Core",
+ "items": {
+ "properties": {
+ "port": {
+ "description": "The Port indicates the Port Number to which the TLS configuration will be\napplied. This configuration will be applied to all Listeners handling HTTPS\ntraffic that match this port.\n\nSupport: Core",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS store the configuration that will be applied to all Listeners handling\nHTTPS traffic and matching given port.\n\nSupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "port",
+ "tls"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "port"
+ ],
+ "x-kubernetes-list-type": "map",
+ "x-kubernetes-validations": [
+ {
+ "message": "Port for TLS configuration must be unique within the Gateway",
+ "rule": "self.all(t1, self.exists_one(t2, t1.port == t2.port))"
+ }
+ ]
+ }
+ },
+ "required": [
+ "default"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
}
},
"required": [
@@ -531,6 +854,11 @@
"type": "array",
"x-kubernetes-list-type": "atomic"
},
+ "attachedListenerSets": {
+ "description": "AttachedListenerSets represents the total number of ListenerSets that have been\nsuccessfully attached to this Gateway.\n\nA ListenerSet is successfully attached to a Gateway when all the following conditions are met:\n- The ListenerSet is selected by the Gateway's AllowedListeners field\n- The ListenerSet has a valid ParentRef selecting the Gateway\n- The ListenerSet's status has the condition \"Accepted: true\"\n\nUses for this field include troubleshooting AttachedListenerSets attachment and\nmeasuring blast radius/impact of changes to a Gateway.",
+ "format": "int32",
+ "type": "integer"
+ },
"conditions": {
"default": [
{
@@ -614,7 +942,7 @@
"description": "ListenerStatus is the status associated with a Listener.",
"properties": {
"attachedRoutes": {
- "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners with condition Accepted: false and MUST count successfully\nattached Routes that may themselves have Accepted: false conditions.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
+ "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners, even if the Accepted condition of an individual Listener is set\nto \"False\". The AttachedRoutes number represents the number of Routes with\nthe Accepted condition set to \"True\" that have been attached to this Listener.\nRoutes with any other value for the Accepted condition MUST NOT be included\nin this count.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
"format": "int32",
"type": "integer"
},
@@ -687,7 +1015,7 @@
"type": "string"
},
"supportedKinds": {
- "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds an implementation supports for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
+ "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds supported by an implementation for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
"items": {
"description": "RouteGroupKind indicates the group and kind of a Route resource.",
"properties": {
@@ -720,8 +1048,7 @@
"required": [
"attachedRoutes",
"conditions",
- "name",
- "supportedKinds"
+ "name"
],
"type": "object",
"additionalProperties": false
diff --git a/crdSchemas/gatewayclass_v1.json b/crdSchemas/gateway.networking.k8s.io/gatewayclass_v1.json
similarity index 100%
rename from crdSchemas/gatewayclass_v1.json
rename to crdSchemas/gateway.networking.k8s.io/gatewayclass_v1.json
diff --git a/crdSchemas/gatewayclass_v1beta1.json b/crdSchemas/gateway.networking.k8s.io/gatewayclass_v1beta1.json
similarity index 100%
rename from crdSchemas/gatewayclass_v1beta1.json
rename to crdSchemas/gateway.networking.k8s.io/gatewayclass_v1beta1.json
diff --git a/crdSchemas/grpcroute_v1.json b/crdSchemas/gateway.networking.k8s.io/grpcroute_v1.json
similarity index 88%
rename from crdSchemas/grpcroute_v1.json
rename to crdSchemas/gateway.networking.k8s.io/grpcroute_v1.json
index 8f24a6b..57ea300 100644
--- a/crdSchemas/grpcroute_v1.json
+++ b/crdSchemas/gateway.networking.k8s.io/grpcroute_v1.json
@@ -29,7 +29,7 @@
"x-kubernetes-list-type": "atomic"
},
"parentRefs": {
- "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.",
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
"items": {
"description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
"properties": {
@@ -55,14 +55,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
@@ -87,12 +87,12 @@
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
- "message": "sectionName must be specified when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))"
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
},
{
- "message": "sectionName must be unique when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))"
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
}
]
},
@@ -104,7 +104,7 @@
"backendRefs": {
"description": "BackendRefs defines the backend(s) where matching requests should be\nsent.\n\nFailure behavior here depends on how many BackendRefs are specified and\nhow many are invalid.\n\nIf *all* entries in BackendRefs are invalid, and there are also no filters\nspecified in this route rule, *all* traffic which matches this rule MUST\nreceive an `UNAVAILABLE` status.\n\nSee the GRPCBackendRef definition for the rules about what makes a single\nGRPCBackendRef invalid.\n\nWhen a GRPCBackendRef is invalid, `UNAVAILABLE` statuses MUST be returned for\nrequests that would have otherwise been routed to an invalid backend. If\nmultiple backends are specified, and some are invalid, the proportion of\nrequests that would otherwise have been routed to an invalid backend\nMUST receive an `UNAVAILABLE` status.\n\nFor example, if two backends are specified with equal weights, and one is\ninvalid, 50 percent of traffic MUST receive an `UNAVAILABLE` status.\nImplementations may choose how that 50 percent is determined.\n\nSupport: Core for Kubernetes Service\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Core",
"items": {
- "description": "GRPCBackendRef defines how a GRPCRoute forwards a gRPC request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.",
+ "description": "GRPCBackendRef defines how a GRPCRoute forwards a gRPC request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.",
"properties": {
"filters": {
"description": "Filters defined at this level MUST be executed if and only if the\nrequest is being forwarded to the backend defined here.\n\nSupport: Implementation-specific (For broader support of filters, use the\nFilters field in GRPCRouteRule.)",
@@ -158,9 +158,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -200,9 +201,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -341,9 +343,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -383,9 +386,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -584,9 +588,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -626,9 +631,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -767,9 +773,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -809,9 +816,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -901,7 +909,7 @@
"matches": {
"description": "Matches define conditions used for matching the rule against incoming\ngRPC requests. Each match is independent, i.e. this rule will be matched\nif **any** one of the matches is satisfied.\n\nFor example, take the following matches configuration:\n\n```\nmatches:\n- method:\n service: foo.bar\n headers:\n values:\n version: 2\n- method:\n service: foo.bar.v2\n```\n\nFor a request to match against this rule, it MUST satisfy\nEITHER of the two conditions:\n\n- service of foo.bar AND contains the header `version: 2`\n- service of foo.bar.v2\n\nSee the documentation for GRPCRouteMatch on how to specify multiple\nmatch conditions to be ANDed together.\n\nIf no matches are specified, the implementation MUST match every gRPC request.\n\nProxy or Load Balancer routing configuration generated from GRPCRoutes\nMUST prioritize rules based on the following criteria, continuing on\nties. Merging MUST not be done between GRPCRoutes and HTTPRoutes.\nPrecedence MUST be given to the rule with the largest number of:\n\n* Characters in a matching non-wildcard hostname.\n* Characters in a matching hostname.\n* Characters in a matching service.\n* Characters in a matching method.\n* Header matches.\n\nIf ties still exist across multiple Routes, matching precedence MUST be\ndetermined in order of the following criteria, continuing on ties:\n\n* The oldest Route based on creation timestamp.\n* The Route appearing first in alphabetical order by\n \"{namespace}/{name}\".\n\nIf ties still exist within the Route that has been given precedence,\nmatching precedence MUST be granted to the first matching rule meeting\nthe above criteria.",
"items": {
- "description": "GRPCRouteMatch defines the predicate used to match requests to a given\naction. Multiple match types are ANDed together, i.e. the match will\nevaluate to true only if all conditions are satisfied.\n\nFor example, the match below will match a gRPC request only if its service\nis `foo` AND it contains the `version: v1` header:\n\n```\nmatches:\n - method:\n type: Exact\n service: \"foo\"\n headers:\n - name: \"version\"\n value \"v1\"\n\n```",
+ "description": "GRPCRouteMatch defines the predicate used to match requests to a given\naction. Multiple match types are ANDed together, i.e. the match will\nevaluate to true only if all conditions are satisfied.\n\nFor example, the match below will match a gRPC request only if its service\nis `foo` AND it contains the `version: v1` header:\n\n```\nmatches:\n - method:\n type: Exact\n service: \"foo\"\n - headers:\n name: \"version\"\n value \"v1\"\n\n```",
"properties": {
"headers": {
"description": "Headers specifies gRPC request header matchers. Multiple match values are\nANDed together, meaning, a request MUST match all the specified headers\nto select the route.",
@@ -999,6 +1007,63 @@
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
"type": "string"
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the route rule.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
}
},
"type": "object",
@@ -1011,8 +1076,20 @@
{
"message": "While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",
"rule": "(self.size() > 0 ? (has(self[0].matches) ? self[0].matches.size() : 0) : 0) + (self.size() > 1 ? (has(self[1].matches) ? self[1].matches.size() : 0) : 0) + (self.size() > 2 ? (has(self[2].matches) ? self[2].matches.size() : 0) : 0) + (self.size() > 3 ? (has(self[3].matches) ? self[3].matches.size() : 0) : 0) + (self.size() > 4 ? (has(self[4].matches) ? self[4].matches.size() : 0) : 0) + (self.size() > 5 ? (has(self[5].matches) ? self[5].matches.size() : 0) : 0) + (self.size() > 6 ? (has(self[6].matches) ? self[6].matches.size() : 0) : 0) + (self.size() > 7 ? (has(self[7].matches) ? self[7].matches.size() : 0) : 0) + (self.size() > 8 ? (has(self[8].matches) ? self[8].matches.size() : 0) : 0) + (self.size() > 9 ? (has(self[9].matches) ? self[9].matches.size() : 0) : 0) + (self.size() > 10 ? (has(self[10].matches) ? self[10].matches.size() : 0) : 0) + (self.size() > 11 ? (has(self[11].matches) ? self[11].matches.size() : 0) : 0) + (self.size() > 12 ? (has(self[12].matches) ? self[12].matches.size() : 0) : 0) + (self.size() > 13 ? (has(self[13].matches) ? self[13].matches.size() : 0) : 0) + (self.size() > 14 ? (has(self[14].matches) ? self[14].matches.size() : 0) : 0) + (self.size() > 15 ? (has(self[15].matches) ? self[15].matches.size() : 0) : 0) <= 128"
+ },
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
}
]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
}
},
"type": "object",
@@ -1027,7 +1104,7 @@
"description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
"properties": {
"conditions": {
- "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace the controller does not have access to.",
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
@@ -1120,14 +1197,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/httproute_v1.json b/crdSchemas/gateway.networking.k8s.io/httproute_v1.json
similarity index 65%
rename from crdSchemas/httproute_v1.json
rename to crdSchemas/gateway.networking.k8s.io/httproute_v1.json
index 774f9fa..cb8bca6 100644
--- a/crdSchemas/httproute_v1.json
+++ b/crdSchemas/gateway.networking.k8s.io/httproute_v1.json
@@ -29,7 +29,7 @@
"x-kubernetes-list-type": "atomic"
},
"parentRefs": {
- "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.",
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
"items": {
"description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
"properties": {
@@ -55,14 +55,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
@@ -87,12 +87,12 @@
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
- "message": "sectionName must be specified when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))"
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
},
{
- "message": "sectionName must be unique when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))"
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
}
]
},
@@ -116,13 +116,109 @@
"backendRefs": {
"description": "BackendRefs defines the backend(s) where matching requests should be\nsent.\n\nFailure behavior here depends on how many BackendRefs are specified and\nhow many are invalid.\n\nIf *all* entries in BackendRefs are invalid, and there are also no filters\nspecified in this route rule, *all* traffic which matches this rule MUST\nreceive a 500 status code.\n\nSee the HTTPBackendRef definition for the rules about what makes a single\nHTTPBackendRef invalid.\n\nWhen a HTTPBackendRef is invalid, 500 status codes MUST be returned for\nrequests that would have otherwise been routed to an invalid backend. If\nmultiple backends are specified, and some are invalid, the proportion of\nrequests that would otherwise have been routed to an invalid backend\nMUST receive a 500 status code.\n\nFor example, if two backends are specified with equal weights, and one is\ninvalid, 50 percent of traffic must receive a 500. Implementations may\nchoose how that 50 percent is determined.\n\nWhen a HTTPBackendRef refers to a Service that has no ready endpoints,\nimplementations SHOULD return a 503 for requests to that backend instead.\nIf an implementation chooses to do this, all of the above rules for 500 responses\nMUST also apply for responses that return a 503.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Core",
"items": {
- "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.",
+ "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.",
"properties": {
"filters": {
"description": "Filters defined at this level should be executed if and only if the\nrequest is being forwarded to the backend defined here.\n\nSupport: Implementation-specific (For broader support of filters, use the\nFilters field in HTTPRouteRule.)",
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -154,6 +250,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -170,9 +412,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -212,9 +455,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -413,7 +657,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -437,9 +684,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -479,9 +727,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -511,7 +760,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -581,6 +832,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -628,6 +887,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -640,6 +907,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -723,6 +994,102 @@
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -754,6 +1121,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -770,9 +1283,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -812,9 +1326,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1013,7 +1528,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -1037,9 +1555,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1079,9 +1598,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1111,7 +1631,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -1181,6 +1703,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -1228,6 +1758,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -1240,6 +1778,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -1293,9 +1835,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1458,6 +2001,90 @@
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
"type": "string"
},
+ "retry": {
+ "description": "Retry defines the configuration for when to retry an HTTP request.\n\nSupport: Extended",
+ "properties": {
+ "attempts": {
+ "description": "Attempts specifies the maximum number of times an individual request\nfrom the gateway to a backend should be retried.\n\nIf the maximum number of retries has been attempted without a successful\nresponse from the backend, the Gateway MUST return an error.\n\nWhen this field is unspecified, the number of times to attempt to retry\na backend request is implementation-specific.\n\nSupport: Extended",
+ "type": "integer"
+ },
+ "backoff": {
+ "description": "Backoff specifies the minimum duration a Gateway should wait between\nretry attempts and is represented in Gateway API Duration formatting.\n\nFor example, setting the `rules[].retry.backoff` field to the value\n`100ms` will cause a backend request to first be retried approximately\n100 milliseconds after timing out or receiving a response code configured\nto be retriable.\n\nAn implementation MAY use an exponential or alternative backoff strategy\nfor subsequent retry attempts, MAY cap the maximum backoff duration to\nsome amount greater than the specified minimum, and MAY add arbitrary\njitter to stagger requests, as long as unsuccessful backend requests are\nnot retried before the configured minimum duration.\n\nIf a Request timeout (`rules[].timeouts.request`) is configured on the\nroute, the entire duration of the initial request and any retry attempts\nMUST not exceed the Request timeout duration. If any retry attempts are\nstill in progress when the Request timeout duration has been reached,\nthese SHOULD be canceled if possible and the Gateway MUST immediately\nreturn a timeout error.\n\nIf a BackendRequest timeout (`rules[].timeouts.backendRequest`) is\nconfigured on the route, any retry attempts which reach the configured\nBackendRequest timeout duration without a response SHOULD be canceled if\npossible and the Gateway should wait for at least the specified backoff\nduration before attempting to retry the backend request again.\n\nIf a BackendRequest timeout is _not_ configured on the route, retry\nattempts MAY time out after an implementation default duration, or MAY\nremain pending until a configured Request timeout or implementation\ndefault duration for total request time is reached.\n\nWhen this field is unspecified, the time to wait between retry attempts\nis implementation-specific.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "codes": {
+ "description": "Codes defines the HTTP response status codes for which a backend request\nshould be retried.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPRouteRetryStatusCode defines an HTTP response status code for\nwhich a backend request should be retried.\n\nImplementations MUST support the following status codes as retriable:\n\n* 500\n* 502\n* 503\n* 504\n\nImplementations MAY support specifying additional discrete values in the\n500-599 range.\n\nImplementations MAY support specifying discrete values in the 400-499 range,\nwhich are often inadvisable to retry.",
+ "maximum": 599,
+ "minimum": 400,
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the route rule.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
+ },
"timeouts": {
"description": "Timeouts defines the timeouts that can be configured for an HTTP request.\n\nSupport: Extended",
"properties": {
@@ -1508,14 +2135,27 @@
"additionalProperties": false
},
"maxItems": 16,
+ "minItems": 1,
"type": "array",
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
"message": "While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",
"rule": "(self.size() > 0 ? self[0].matches.size() : 0) + (self.size() > 1 ? self[1].matches.size() : 0) + (self.size() > 2 ? self[2].matches.size() : 0) + (self.size() > 3 ? self[3].matches.size() : 0) + (self.size() > 4 ? self[4].matches.size() : 0) + (self.size() > 5 ? self[5].matches.size() : 0) + (self.size() > 6 ? self[6].matches.size() : 0) + (self.size() > 7 ? self[7].matches.size() : 0) + (self.size() > 8 ? self[8].matches.size() : 0) + (self.size() > 9 ? self[9].matches.size() : 0) + (self.size() > 10 ? self[10].matches.size() : 0) + (self.size() > 11 ? self[11].matches.size() : 0) + (self.size() > 12 ? self[12].matches.size() : 0) + (self.size() > 13 ? self[13].matches.size() : 0) + (self.size() > 14 ? self[14].matches.size() : 0) + (self.size() > 15 ? self[15].matches.size() : 0) <= 128"
+ },
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
}
]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
}
},
"type": "object",
@@ -1530,7 +2170,7 @@
"description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
"properties": {
"conditions": {
- "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace the controller does not have access to.",
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
@@ -1623,14 +2263,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/httproute_v1beta1.json b/crdSchemas/gateway.networking.k8s.io/httproute_v1beta1.json
similarity index 65%
rename from crdSchemas/httproute_v1beta1.json
rename to crdSchemas/gateway.networking.k8s.io/httproute_v1beta1.json
index 774f9fa..cb8bca6 100644
--- a/crdSchemas/httproute_v1beta1.json
+++ b/crdSchemas/gateway.networking.k8s.io/httproute_v1beta1.json
@@ -29,7 +29,7 @@
"x-kubernetes-list-type": "atomic"
},
"parentRefs": {
- "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.",
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
"items": {
"description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
"properties": {
@@ -55,14 +55,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
@@ -87,12 +87,12 @@
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
- "message": "sectionName must be specified when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))"
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
},
{
- "message": "sectionName must be unique when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))"
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
}
]
},
@@ -116,13 +116,109 @@
"backendRefs": {
"description": "BackendRefs defines the backend(s) where matching requests should be\nsent.\n\nFailure behavior here depends on how many BackendRefs are specified and\nhow many are invalid.\n\nIf *all* entries in BackendRefs are invalid, and there are also no filters\nspecified in this route rule, *all* traffic which matches this rule MUST\nreceive a 500 status code.\n\nSee the HTTPBackendRef definition for the rules about what makes a single\nHTTPBackendRef invalid.\n\nWhen a HTTPBackendRef is invalid, 500 status codes MUST be returned for\nrequests that would have otherwise been routed to an invalid backend. If\nmultiple backends are specified, and some are invalid, the proportion of\nrequests that would otherwise have been routed to an invalid backend\nMUST receive a 500 status code.\n\nFor example, if two backends are specified with equal weights, and one is\ninvalid, 50 percent of traffic must receive a 500. Implementations may\nchoose how that 50 percent is determined.\n\nWhen a HTTPBackendRef refers to a Service that has no ready endpoints,\nimplementations SHOULD return a 503 for requests to that backend instead.\nIf an implementation chooses to do this, all of the above rules for 500 responses\nMUST also apply for responses that return a 503.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Core",
"items": {
- "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.",
+ "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.",
"properties": {
"filters": {
"description": "Filters defined at this level should be executed if and only if the\nrequest is being forwarded to the backend defined here.\n\nSupport: Implementation-specific (For broader support of filters, use the\nFilters field in HTTPRouteRule.)",
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -154,6 +250,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -170,9 +412,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -212,9 +455,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -413,7 +657,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -437,9 +684,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -479,9 +727,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -511,7 +760,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -581,6 +832,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -628,6 +887,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -640,6 +907,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -723,6 +994,102 @@
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -754,6 +1121,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -770,9 +1283,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -812,9 +1326,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1013,7 +1528,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -1037,9 +1555,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1079,9 +1598,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1111,7 +1631,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -1181,6 +1703,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -1228,6 +1758,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -1240,6 +1778,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -1293,9 +1835,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1458,6 +2001,90 @@
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
"type": "string"
},
+ "retry": {
+ "description": "Retry defines the configuration for when to retry an HTTP request.\n\nSupport: Extended",
+ "properties": {
+ "attempts": {
+ "description": "Attempts specifies the maximum number of times an individual request\nfrom the gateway to a backend should be retried.\n\nIf the maximum number of retries has been attempted without a successful\nresponse from the backend, the Gateway MUST return an error.\n\nWhen this field is unspecified, the number of times to attempt to retry\na backend request is implementation-specific.\n\nSupport: Extended",
+ "type": "integer"
+ },
+ "backoff": {
+ "description": "Backoff specifies the minimum duration a Gateway should wait between\nretry attempts and is represented in Gateway API Duration formatting.\n\nFor example, setting the `rules[].retry.backoff` field to the value\n`100ms` will cause a backend request to first be retried approximately\n100 milliseconds after timing out or receiving a response code configured\nto be retriable.\n\nAn implementation MAY use an exponential or alternative backoff strategy\nfor subsequent retry attempts, MAY cap the maximum backoff duration to\nsome amount greater than the specified minimum, and MAY add arbitrary\njitter to stagger requests, as long as unsuccessful backend requests are\nnot retried before the configured minimum duration.\n\nIf a Request timeout (`rules[].timeouts.request`) is configured on the\nroute, the entire duration of the initial request and any retry attempts\nMUST not exceed the Request timeout duration. If any retry attempts are\nstill in progress when the Request timeout duration has been reached,\nthese SHOULD be canceled if possible and the Gateway MUST immediately\nreturn a timeout error.\n\nIf a BackendRequest timeout (`rules[].timeouts.backendRequest`) is\nconfigured on the route, any retry attempts which reach the configured\nBackendRequest timeout duration without a response SHOULD be canceled if\npossible and the Gateway should wait for at least the specified backoff\nduration before attempting to retry the backend request again.\n\nIf a BackendRequest timeout is _not_ configured on the route, retry\nattempts MAY time out after an implementation default duration, or MAY\nremain pending until a configured Request timeout or implementation\ndefault duration for total request time is reached.\n\nWhen this field is unspecified, the time to wait between retry attempts\nis implementation-specific.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "codes": {
+ "description": "Codes defines the HTTP response status codes for which a backend request\nshould be retried.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPRouteRetryStatusCode defines an HTTP response status code for\nwhich a backend request should be retried.\n\nImplementations MUST support the following status codes as retriable:\n\n* 500\n* 502\n* 503\n* 504\n\nImplementations MAY support specifying additional discrete values in the\n500-599 range.\n\nImplementations MAY support specifying discrete values in the 400-499 range,\nwhich are often inadvisable to retry.",
+ "maximum": 599,
+ "minimum": 400,
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the route rule.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
+ },
"timeouts": {
"description": "Timeouts defines the timeouts that can be configured for an HTTP request.\n\nSupport: Extended",
"properties": {
@@ -1508,14 +2135,27 @@
"additionalProperties": false
},
"maxItems": 16,
+ "minItems": 1,
"type": "array",
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
"message": "While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",
"rule": "(self.size() > 0 ? self[0].matches.size() : 0) + (self.size() > 1 ? self[1].matches.size() : 0) + (self.size() > 2 ? self[2].matches.size() : 0) + (self.size() > 3 ? self[3].matches.size() : 0) + (self.size() > 4 ? self[4].matches.size() : 0) + (self.size() > 5 ? self[5].matches.size() : 0) + (self.size() > 6 ? self[6].matches.size() : 0) + (self.size() > 7 ? self[7].matches.size() : 0) + (self.size() > 8 ? self[8].matches.size() : 0) + (self.size() > 9 ? self[9].matches.size() : 0) + (self.size() > 10 ? self[10].matches.size() : 0) + (self.size() > 11 ? self[11].matches.size() : 0) + (self.size() > 12 ? self[12].matches.size() : 0) + (self.size() > 13 ? self[13].matches.size() : 0) + (self.size() > 14 ? self[14].matches.size() : 0) + (self.size() > 15 ? self[15].matches.size() : 0) <= 128"
+ },
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
}
]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
}
},
"type": "object",
@@ -1530,7 +2170,7 @@
"description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
"properties": {
"conditions": {
- "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace the controller does not have access to.",
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
@@ -1623,14 +2263,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/gateway.networking.k8s.io/listenerset_v1.json b/crdSchemas/gateway.networking.k8s.io/listenerset_v1.json
new file mode 100644
index 0000000..487ba2b
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/listenerset_v1.json
@@ -0,0 +1,556 @@
+{
+ "description": "ListenerSet defines a set of additional listeners to attach to an existing Gateway.\nThis resource provides a mechanism to merge multiple listeners into a single Gateway.\n\nThe parent Gateway must explicitly allow ListenerSet attachment through its\nAllowedListeners configuration. By default, Gateways do not allow ListenerSet\nattachment.\n\nRoutes can attach to a ListenerSet by specifying it as a parentRef, and can\noptionally target specific listeners using the sectionName field.\n\nPolicy Attachment:\n- Policies that attach to a ListenerSet apply to all listeners defined in that resource\n- Policies do not impact listeners in the parent Gateway\n- Different ListenerSets attached to the same Gateway can have different policies\n- If an implementation cannot apply a policy to specific listeners, it should reject the policy\n\nReferenceGrant Semantics:\n- ReferenceGrants applied to a Gateway are not inherited by child ListenerSets\n- ReferenceGrants applied to a ListenerSet do not grant permission to the parent Gateway's listeners\n- A ListenerSet can reference secrets/backends in its own namespace without a ReferenceGrant\n\nGateway Integration:\n - The parent Gateway's status will include \"AttachedListenerSets\"\n which is the count of ListenerSets that have successfully attached to a Gateway\n A ListenerSet is successfully attached to a Gateway when all the following conditions are met:\n - The ListenerSet is selected by the Gateway's AllowedListeners field\n - The ListenerSet has a valid ParentRef selecting the Gateway\n - The ListenerSet's status has the condition \"Accepted: true\"",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of ListenerSet.",
+ "properties": {
+ "listeners": {
+ "description": "Listeners associated with this ListenerSet. Listeners define\nlogical endpoints that are bound on this referenced parent Gateway's addresses.\n\nListeners in a `Gateway` and their attached `ListenerSets` are concatenated\nas a list when programming the underlying infrastructure. Each listener\nname does not need to be unique across the Gateway and ListenerSets.\nSee ListenerEntry.Name for more details.\n\nImplementations MUST treat the parent Gateway as having the merged\nlist of all listeners from itself and attached ListenerSets using\nthe following precedence:\n\n1. \"parent\" Gateway\n2. ListenerSet ordered by creation time (oldest first)\n3. ListenerSet ordered alphabetically by \"{namespace}/{name}\".\n\nAn implementation MAY reject listeners by setting the ListenerEntryStatus\n`Accepted` condition to False with the Reason `TooManyListeners`\n\nIf a listener has a conflict, this will be reported in the\nStatus.ListenerEntryStatus setting the `Conflicted` condition to True.\n\nImplementations SHOULD be cautious about what information from the\nparent or siblings are reported to avoid accidentally leaking\nsensitive information that the child would not otherwise have access\nto. This can include contents of secrets etc.",
+ "items": {
+ "properties": {
+ "allowedRoutes": {
+ "default": {
+ "namespaces": {
+ "from": "Same"
+ }
+ },
+ "description": "AllowedRoutes defines the types of routes that MAY be attached to a\nListener and the trusted namespaces where those Route resources MAY be\npresent.\n\nAlthough a client request may match multiple route rules, only one rule\nmay ultimately receive the request. Matching precedence MUST be\ndetermined in order of the following criteria:\n\n* The most specific match as defined by the Route type.\n* The oldest Route based on creation timestamp. For example, a Route with\n a creation timestamp of \"2020-09-08 01:02:03\" is given precedence over\n a Route with a creation timestamp of \"2020-09-08 01:02:04\".\n* If everything else is equivalent, the Route appearing first in\n alphabetical order (namespace/name) should be given precedence. For\n example, foo/bar is given precedence over foo/baz.\n\nAll valid rules within a Route attached to this Listener should be\nimplemented. Invalid Route rules can be ignored (sometimes that will mean\nthe full Route). If a Route rule transitions from valid to invalid,\nsupport for that Route rule should be dropped to ensure consistency. For\nexample, even if a filter specified by a Route rule is invalid, the rest\nof the rules within that Route should still be supported.",
+ "properties": {
+ "kinds": {
+ "description": "Kinds specifies the groups and kinds of Routes that are allowed to bind\nto this Gateway Listener. When unspecified or empty, the kinds of Routes\nselected are determined using the Listener protocol.\n\nA RouteGroupKind MUST correspond to kinds of Routes that are compatible\nwith the application protocol specified in the Listener's Protocol field.\nIf an implementation does not support or recognize this resource type, it\nMUST set the \"ResolvedRefs\" condition to False for this Listener with the\n\"InvalidRouteKinds\" reason.\n\nSupport: Core",
+ "items": {
+ "description": "RouteGroupKind indicates the group and kind of a Route resource.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the Route.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the Route.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaces": {
+ "default": {
+ "from": "Same"
+ },
+ "description": "Namespaces indicates namespaces from which Routes may be attached to this\nListener. This is restricted to the namespace of this Gateway by default.\n\nSupport: Core",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates where Routes will be selected for this Gateway. Possible\nvalues are:\n\n* All: Routes in all namespaces may be used by this Gateway.\n* Selector: Routes in namespaces selected by the selector may be used by\n this Gateway.\n* Same: Only Routes in the same namespace may be used by this Gateway.\n\nSupport: Core",
+ "enum": [
+ "All",
+ "Selector",
+ "Same"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector must be specified when From is set to \"Selector\". In that case,\nonly Routes in Namespaces matching this Selector will be selected by this\nGateway. This field is ignored for other values of \"From\".\n\nSupport: Core",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostname": {
+ "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match at both the TLS and HTTP\n protocol layers as described above. If an implementation does not\n ensure that both the SNI and Host header match the Listener hostname,\n it MUST clearly document that.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the Listener. This name MUST be unique within a\nListenerSet.\n\nName is not required to be unique across a Gateway and ListenerSets.\nRoutes can attach to a Listener by having a ListenerSet as a parentRef\nand setting the SectionName",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port. Multiple listeners may use the\nsame port, subject to the Listener compatibility rules.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "protocol": {
+ "description": "Protocol specifies the network protocol this listener expects to receive.",
+ "maxLength": 255,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z0-9]([-a-zA-Z0-9]*[a-zA-Z0-9])?$|[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9]+$",
+ "type": "string"
+ },
+ "tls": {
+ "description": "TLS is the TLS configuration for the Listener. This field is required if\nthe Protocol field is \"HTTPS\" or \"TLS\". It is invalid to set this field\nif the Protocol field is \"HTTP\", \"TCP\", or \"UDP\".\n\nThe association of SNIs to Certificate defined in ListenerTLSConfig is\ndefined based on the Hostname field for this listener.\n\nThe GatewayClass MUST use the longest matching SNI out of all\navailable certificates for any TLS handshake.",
+ "properties": {
+ "certificateRefs": {
+ "description": "CertificateRefs contains a series of references to Kubernetes objects that\ncontains TLS certificates and private keys. These certificates are used to\nestablish a TLS handshake for requests that match the hostname of the\nassociated listener.\n\nA single CertificateRef to a Kubernetes Secret has \"Core\" support.\nImplementations MAY choose to support attaching multiple certificates to\na Listener, but this behavior is implementation-specific.\n\nReferences to a resource in different namespace are invalid UNLESS there\nis a ReferenceGrant in the target namespace that allows the certificate\nto be attached. If a ReferenceGrant does not allow this reference, the\n\"ResolvedRefs\" condition MUST be set to False for this listener with the\n\"RefNotPermitted\" reason.\n\nThis field is required to have at least one element when the mode is set\nto \"Terminate\" (default) and is optional otherwise.\n\nCertificateRefs can reference to standard Kubernetes resources, i.e.\nSecret, or implementation-specific custom resources.\n\nSupport: Core - A single reference to a Kubernetes Secret of type kubernetes.io/tls\n\nSupport: Implementation-specific (More than one reference or other resource types)",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "Terminate",
+ "description": "Mode defines the TLS behavior for the TLS session initiated by the client.\nThere are two possible modes:\n\n- Terminate: The TLS session between the downstream client and the\n Gateway is terminated at the Gateway. This mode requires certificates\n to be specified in some way, such as populating the certificateRefs\n field.\n- Passthrough: The TLS session is NOT terminated by the Gateway. This\n implies that the Gateway can't decipher the TLS stream except for\n the ClientHello message of the TLS protocol. The certificateRefs field\n is ignored in this mode.\n\nSupport: Core",
+ "enum": [
+ "Terminate",
+ "Passthrough"
+ ],
+ "type": "string"
+ },
+ "options": {
+ "additionalProperties": {
+ "description": "AnnotationValue is the value of an annotation in Gateway API. This is used\nfor validation of maps such as TLS options. This roughly matches Kubernetes\nannotation validation, although the length validation in that case is based\non the entire size of the annotations struct.",
+ "maxLength": 4096,
+ "minLength": 0,
+ "type": "string"
+ },
+ "description": "Options are a list of key/value pairs to enable extended TLS\nconfiguration for each implementation. For example, configuring the\nminimum TLS version or supported cipher suites.\n\nA set of common keys MAY be defined by the API in the future. To avoid\nany ambiguity, implementation-specific definitions MUST use\ndomain-prefixed names, such as `example.com/my-custom-option`.\nUn-prefixed names are reserved for key names defined by Gateway API.\n\nSupport: Implementation-specific",
+ "maxProperties": 16,
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "certificateRefs or options must be specified when mode is Terminate",
+ "rule": "self.mode == 'Terminate' ? size(self.certificateRefs) > 0 || size(self.options) > 0 : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "port",
+ "protocol"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map",
+ "x-kubernetes-validations": [
+ {
+ "message": "tls must not be specified for protocols ['HTTP', 'TCP', 'UDP']",
+ "rule": "self.all(l, l.protocol in ['HTTP', 'TCP', 'UDP'] ? !has(l.tls) : true)"
+ },
+ {
+ "message": "tls mode must be Terminate for protocol HTTPS",
+ "rule": "self.all(l, (l.protocol == 'HTTPS' && has(l.tls)) ? (l.tls.mode == '' || l.tls.mode == 'Terminate') : true)"
+ },
+ {
+ "message": "tls mode must be set for protocol TLS",
+ "rule": "self.all(l, (l.protocol == 'TLS' ? has(l.tls) && has(l.tls.mode) && l.tls.mode != '' : true))"
+ },
+ {
+ "message": "hostname must not be specified for protocols ['TCP', 'UDP']",
+ "rule": "self.all(l, l.protocol in ['TCP', 'UDP'] ? (!has(l.hostname) || l.hostname == '') : true)"
+ },
+ {
+ "message": "Listener name must be unique within the Gateway",
+ "rule": "self.all(l1, self.exists_one(l2, l1.name == l2.name))"
+ },
+ {
+ "message": "Combination of port, protocol and hostname must be unique for each listener",
+ "rule": "self.all(l1, !has(l1.port) || self.exists_one(l2, has(l2.port) && l1.port == l2.port && l1.protocol == l2.protocol && (has(l1.hostname) && has(l2.hostname) ? l1.hostname == l2.hostname : !has(l1.hostname) && !has(l2.hostname))))"
+ }
+ ]
+ },
+ "parentRef": {
+ "description": "ParentRef references the Gateway that the listeners are attached to.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent. For example \"Gateway\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. If not present,\nthe namespace of the referent is assumed to be the same as\nthe namespace of the referring object.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "listeners",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "default": {
+ "conditions": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ },
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Programmed"
+ }
+ ]
+ },
+ "description": "Status defines the current state of ListenerSet.",
+ "properties": {
+ "conditions": {
+ "default": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ },
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Programmed"
+ }
+ ],
+ "description": "Conditions describe the current conditions of the ListenerSet.\n\nImplementations MUST express ListenerSet conditions using the\n`ListenerSetConditionType` and `ListenerSetConditionReason`\nconstants so that operators and tools can converge on a common\nvocabulary to describe ListenerSet state.\n\nKnown condition types are:\n\n* \"Accepted\"\n* \"Programmed\"",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "listeners": {
+ "description": "Listeners provide status for each unique listener port defined in the Spec.",
+ "items": {
+ "description": "ListenerStatus is the status associated with a Listener.",
+ "properties": {
+ "attachedRoutes": {
+ "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners, even if the Accepted condition of an individual Listener is set\nto \"False\". The AttachedRoutes number represents the number of Routes with\nthe Accepted condition set to \"True\" that have been attached to this Listener.\nRoutes with any other value for the Accepted condition MUST NOT be included\nin this count.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "conditions": {
+ "description": "Conditions describe the current condition of this listener.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "name": {
+ "description": "Name is the name of the Listener that this status corresponds to.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "supportedKinds": {
+ "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds supported by an implementation for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
+ "items": {
+ "description": "RouteGroupKind indicates the group and kind of a Route resource.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the Route.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the Route.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "attachedRoutes",
+ "conditions",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/referencegrant_v1beta1.json b/crdSchemas/gateway.networking.k8s.io/referencegrant_v1.json
similarity index 100%
rename from crdSchemas/referencegrant_v1beta1.json
rename to crdSchemas/gateway.networking.k8s.io/referencegrant_v1.json
diff --git a/crdSchemas/gateway.networking.k8s.io/referencegrant_v1beta1.json b/crdSchemas/gateway.networking.k8s.io/referencegrant_v1beta1.json
new file mode 100644
index 0000000..2097e00
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/referencegrant_v1beta1.json
@@ -0,0 +1,104 @@
+{
+ "description": "ReferenceGrant identifies kinds of resources in other namespaces that are\ntrusted to reference the specified kinds of resources in the same namespace\nas the policy.\n\nEach ReferenceGrant can be used to represent a unique trust relationship.\nAdditional Reference Grants can be used to add to the set of trusted\nsources of inbound references for the namespace they are defined within.\n\nAll cross-namespace references in Gateway API (with the exception of cross-namespace\nGateway-route attachment) require a ReferenceGrant.\n\nReferenceGrant is a form of runtime verification allowing users to assert\nwhich cross-namespace object references are permitted. Implementations that\nsupport ReferenceGrant MUST NOT permit cross-namespace references which have\nno grant, and MUST respond to the removal of a grant by revoking the access\nthat the grant allowed.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of ReferenceGrant.",
+ "properties": {
+ "from": {
+ "description": "From describes the trusted namespaces and kinds that can reference the\nresources described in \"To\". Each entry in this list MUST be considered\nto be an additional place that references can be valid from, or to put\nthis another way, entries MUST be combined using OR.\n\nSupport: Core",
+ "items": {
+ "description": "ReferenceGrantFrom describes trusted namespaces and kinds.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent.\nWhen empty, the Kubernetes core API group is inferred.\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the referent. Although implementations may support\nadditional resources, the following types are part of the \"Core\"\nsupport level for this field.\n\nWhen used to permit a SecretObjectReference:\n\n* Gateway\n\nWhen used to permit a BackendObjectReference:\n\n* GRPCRoute\n* HTTPRoute\n* TCPRoute\n* TLSRoute\n* UDPRoute",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "to": {
+ "description": "To describes the resources that may be referenced by the resources\ndescribed in \"From\". Each entry in this list MUST be considered to be an\nadditional place that references can be valid to, or to put this another\nway, entries MUST be combined using OR.\n\nSupport: Core",
+ "items": {
+ "description": "ReferenceGrantTo describes what Kinds are allowed as targets of the\nreferences.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent.\nWhen empty, the Kubernetes core API group is inferred.\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the referent. Although implementations may support\nadditional resources, the following types are part of the \"Core\"\nsupport level for this field:\n\n* Secret when used to permit a SecretObjectReference\n* Service when used to permit a BackendObjectReference",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent. When unspecified, this policy\nrefers to all resources of the specified Group and Kind in the local\nnamespace.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "from",
+ "to"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.k8s.io/tcproute_v1alpha2.json b/crdSchemas/gateway.networking.k8s.io/tcproute_v1alpha2.json
new file mode 100644
index 0000000..17ae551
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/tcproute_v1alpha2.json
@@ -0,0 +1,351 @@
+{
+ "description": "TCPRoute provides a way to route TCP requests. When combined with a Gateway\nlistener, it can be used to forward connections on the port specified by the\nlistener to a set of backends specified by the TCPRoute.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TCPRoute.",
+ "properties": {
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of TCP matchers and actions.",
+ "items": {
+ "description": "TCPRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or a\nService with no endpoints), the underlying implementation MUST actively\nreject connection attempts to this backend. Connection rejections must\nrespect weight; if an invalid backend is requested to have 80% of\nconnections, then 80% of connections must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.\n\nSupport: Extended",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
+ }
+ ]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TCPRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.k8s.io/tlsroute_v1.json b/crdSchemas/gateway.networking.k8s.io/tlsroute_v1.json
new file mode 100644
index 0000000..5c9a7c1
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/tlsroute_v1.json
@@ -0,0 +1,374 @@
+{
+ "description": "The TLSRoute resource is similar to TCPRoute, but can be configured\nto match against TLS-specific metadata. This allows more flexibility\nin matching streams for a given TLS listener.\n\nIf you need to forward traffic to a single target for a TLS listener, you\ncould choose to use a TCPRoute with a TLS listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TLSRoute.",
+ "properties": {
+ "hostnames": {
+ "description": "Hostnames defines a set of SNI hostnames that should match against the\nSNI attribute of TLS ClientHello message in TLS handshake. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n1. IPs are not allowed in SNI hostnames per RFC 6066.\n2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.",
+ "items": {
+ "description": "Hostname is the fully qualified domain name of a network host. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n 1. IPs are not allowed.\n 2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nHostname can be \"precise\" which is a domain name without the terminating\ndot of a network host (e.g. \"foo.example.com\") or \"wildcard\", which is a\ndomain name prefixed with a single wildcard label (e.g. `*.example.com`).\n\nNote that as per RFC1035 and RFC1123, a *label* must consist of lower case\nalphanumeric characters or '-', and must start and end with an alphanumeric\ncharacter. No other punctuation is allowed.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Hostnames cannot contain an IP",
+ "rule": "self.all(h, !isIP(h))"
+ },
+ {
+ "message": "Hostnames must be valid based on RFC-1123",
+ "rule": "self.all(h, !h.contains('*') ? h.matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$') : true)"
+ },
+ {
+ "message": "Wildcards on hostnames must be the first label, and the rest of hostname must be valid based on RFC-1123",
+ "rule": "self.all(h, h.contains('*') ? (h.startsWith('*.') && h.substring(2).matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$')) : true)"
+ }
+ ]
+ },
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of actions.",
+ "items": {
+ "description": "TLSRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or\na Service with no endpoints), the rule performs no forwarding; if no\nfilters are specified that would result in a response being sent, the\nunderlying implementation must actively reject request attempts to this\nbackend, by rejecting the connection. Request rejections must respect\nweight; if an invalid backend is requested to have 80% of requests, then\n80% of requests must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 1,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "hostnames",
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TLSRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.k8s.io/tlsroute_v1alpha2.json b/crdSchemas/gateway.networking.k8s.io/tlsroute_v1alpha2.json
new file mode 100644
index 0000000..8e29f4c
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/tlsroute_v1alpha2.json
@@ -0,0 +1,364 @@
+{
+ "description": "The TLSRoute resource is similar to TCPRoute, but can be configured\nto match against TLS-specific metadata. This allows more flexibility\nin matching streams for a given TLS listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TLSRoute.",
+ "properties": {
+ "hostnames": {
+ "description": "Hostnames defines a set of SNI names that should match against the\nSNI attribute of TLS ClientHello message in TLS handshake. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n1. IPs are not allowed in SNI names per RFC 6066.\n2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nIf a hostname is specified by both the Listener and TLSRoute, there\nmust be at least one intersecting hostname for the TLSRoute to be\nattached to the Listener. For example:\n\n* A Listener with `test.example.com` as the hostname matches TLSRoutes\n that have either not specified any hostnames, or have specified at\n least one of `test.example.com` or `*.example.com`.\n* A Listener with `*.example.com` as the hostname matches TLSRoutes\n that have either not specified any hostnames or have specified at least\n one hostname that matches the Listener hostname. For example,\n `test.example.com` and `*.example.com` would both match. On the other\n hand, `example.com` and `test.example.net` would not match.\n\nIf both the Listener and TLSRoute have specified hostnames, any\nTLSRoute hostnames that do not match the Listener hostname MUST be\nignored. For example, if a Listener specified `*.example.com`, and the\nTLSRoute specified `test.example.com` and `test.example.net`,\n`test.example.net` must not be considered for a match.\n\nIf both the Listener and TLSRoute have specified hostnames, and none\nmatch with the criteria above, then the TLSRoute is not accepted. The\nimplementation must raise an 'Accepted' Condition with a status of\n`False` in the corresponding RouteParentStatus.\n\nSupport: Core",
+ "items": {
+ "description": "Hostname is the fully qualified domain name of a network host. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n 1. IPs are not allowed.\n 2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nHostname can be \"precise\" which is a domain name without the terminating\ndot of a network host (e.g. \"foo.example.com\") or \"wildcard\", which is a\ndomain name prefixed with a single wildcard label (e.g. `*.example.com`).\n\nNote that as per RFC1035 and RFC1123, a *label* must consist of lower case\nalphanumeric characters or '-', and must start and end with an alphanumeric\ncharacter. No other punctuation is allowed.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of TLS matchers and actions.",
+ "items": {
+ "description": "TLSRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or\na Service with no endpoints), the rule performs no forwarding; if no\nfilters are specified that would result in a response being sent, the\nunderlying implementation must actively reject request attempts to this\nbackend, by rejecting the connection. Request rejections must respect\nweight; if an invalid backend is requested to have 80% of requests, then\n80% of requests must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
+ }
+ ]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TLSRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.k8s.io/tlsroute_v1alpha3.json b/crdSchemas/gateway.networking.k8s.io/tlsroute_v1alpha3.json
new file mode 100644
index 0000000..5c9a7c1
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/tlsroute_v1alpha3.json
@@ -0,0 +1,374 @@
+{
+ "description": "The TLSRoute resource is similar to TCPRoute, but can be configured\nto match against TLS-specific metadata. This allows more flexibility\nin matching streams for a given TLS listener.\n\nIf you need to forward traffic to a single target for a TLS listener, you\ncould choose to use a TCPRoute with a TLS listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TLSRoute.",
+ "properties": {
+ "hostnames": {
+ "description": "Hostnames defines a set of SNI hostnames that should match against the\nSNI attribute of TLS ClientHello message in TLS handshake. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n1. IPs are not allowed in SNI hostnames per RFC 6066.\n2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.",
+ "items": {
+ "description": "Hostname is the fully qualified domain name of a network host. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n 1. IPs are not allowed.\n 2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nHostname can be \"precise\" which is a domain name without the terminating\ndot of a network host (e.g. \"foo.example.com\") or \"wildcard\", which is a\ndomain name prefixed with a single wildcard label (e.g. `*.example.com`).\n\nNote that as per RFC1035 and RFC1123, a *label* must consist of lower case\nalphanumeric characters or '-', and must start and end with an alphanumeric\ncharacter. No other punctuation is allowed.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Hostnames cannot contain an IP",
+ "rule": "self.all(h, !isIP(h))"
+ },
+ {
+ "message": "Hostnames must be valid based on RFC-1123",
+ "rule": "self.all(h, !h.contains('*') ? h.matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$') : true)"
+ },
+ {
+ "message": "Wildcards on hostnames must be the first label, and the rest of hostname must be valid based on RFC-1123",
+ "rule": "self.all(h, h.contains('*') ? (h.startsWith('*.') && h.substring(2).matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$')) : true)"
+ }
+ ]
+ },
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of actions.",
+ "items": {
+ "description": "TLSRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or\na Service with no endpoints), the rule performs no forwarding; if no\nfilters are specified that would result in a response being sent, the\nunderlying implementation must actively reject request attempts to this\nbackend, by rejecting the connection. Request rejections must respect\nweight; if an invalid backend is requested to have 80% of requests, then\n80% of requests must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 1,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "hostnames",
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TLSRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.k8s.io/udproute_v1alpha2.json b/crdSchemas/gateway.networking.k8s.io/udproute_v1alpha2.json
new file mode 100644
index 0000000..7f43170
--- /dev/null
+++ b/crdSchemas/gateway.networking.k8s.io/udproute_v1alpha2.json
@@ -0,0 +1,351 @@
+{
+ "description": "UDPRoute provides a way to route UDP traffic. When combined with a Gateway\nlistener, it can be used to forward traffic on the port specified by the\nlistener to a set of backends specified by the UDPRoute.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of UDPRoute.",
+ "properties": {
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of UDP matchers and actions.",
+ "items": {
+ "description": "UDPRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or a\nService with no endpoints), the underlying implementation MUST actively\nreject connection attempts to this backend. Packet drops must\nrespect weight; if an invalid backend is requested to have 80% of\nthe packets, then 80% of packets must be dropped instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.\n\nSupport: Extended",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
+ }
+ ]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of UDPRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.x-k8s.io/xbackendtrafficpolicy_v1alpha1.json b/crdSchemas/gateway.networking.x-k8s.io/xbackendtrafficpolicy_v1alpha1.json
new file mode 100644
index 0000000..f9cf262
--- /dev/null
+++ b/crdSchemas/gateway.networking.x-k8s.io/xbackendtrafficpolicy_v1alpha1.json
@@ -0,0 +1,344 @@
+{
+ "description": "XBackendTrafficPolicy defines the configuration for how traffic to a\ntarget backend should be handled.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of BackendTrafficPolicy.",
+ "properties": {
+ "retryConstraint": {
+ "description": "RetryConstraint defines the configuration for when to allow or prevent\nfurther retries to a target backend, by dynamically calculating a 'retry\nbudget'. This budget is calculated based on the percentage of incoming\ntraffic composed of retries over a given time interval. Once the budget\nis exceeded, additional retries will be rejected.\n\nFor example, if the retry budget interval is 10 seconds, there have been\n1000 active requests in the past 10 seconds, and the allowed percentage\nof requests that can be retried is 20% (the default), then 200 of those\nrequests may be composed of retries. Active requests will only be\nconsidered for the duration of the interval when calculating the retry\nbudget. Retrying the same original request multiple times within the\nretry budget interval will lead to each retry being counted towards\ncalculating the budget.\n\nConfiguring a RetryConstraint in BackendTrafficPolicy is compatible with\nHTTPRoute Retry settings for each HTTPRouteRule that targets the same\nbackend. While the HTTPRouteRule Retry stanza can specify whether a\nrequest will be retried, and the number of retry attempts each client\nmay perform, RetryConstraint helps prevent cascading failures such as\nretry storms during periods of consistent failures.\n\nAfter the retry budget has been exceeded, additional retries to the\nbackend MUST return a 503 response to the client.\n\nAdditional configurations for defining a constraint on retries MAY be\ndefined in the future.\n\nSupport: Extended",
+ "properties": {
+ "budget": {
+ "default": {
+ "interval": "10s",
+ "percent": 20
+ },
+ "description": "Budget holds the details of the retry budget configuration.",
+ "properties": {
+ "interval": {
+ "default": "10s",
+ "description": "Interval defines the duration in which requests will be considered\nfor calculating the budget for retries.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "interval cannot be greater than one hour or less than one second",
+ "rule": "!(duration(self) < duration('1s') || duration(self) > duration('1h'))"
+ }
+ ]
+ },
+ "percent": {
+ "default": 20,
+ "description": "Percent defines the maximum percentage of active requests that may\nbe made up of retries.\n\nSupport: Extended",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minRetryRate": {
+ "default": {
+ "count": 10,
+ "interval": "1s"
+ },
+ "description": "MinRetryRate defines the minimum rate of retries that will be allowable\nover a specified duration of time.\n\nThe effective overall minimum rate of retries targeting the backend\nservice may be much higher, as there can be any number of clients which\nare applying this setting locally.\n\nThis ensures that requests can still be retried during periods of low\ntraffic, where the budget for retries may be calculated as a very low\nvalue.\n\nSupport: Extended",
+ "properties": {
+ "count": {
+ "description": "Count specifies the number of requests per time interval.\n\nSupport: Extended",
+ "maximum": 1000000,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "interval": {
+ "description": "Interval specifies the divisor of the rate of requests, the amount of\ntime during which the given count of requests occur.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "interval cannot be greater than one hour",
+ "rule": "!(duration(self) == duration('0s') || duration(self) > duration('1h'))"
+ }
+ ]
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the backend.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs identifies API object(s) to apply this policy to.\nCurrently, Backends (A grouping of like endpoints such as Service,\nServiceImport, or any implementation-specific backendRef) are the only\nvalid API target references.\n\nCurrently, a TargetRef cannot be scoped to a specific port on a\nService.",
+ "items": {
+ "description": "LocalPolicyTargetReference identifies an API object to apply a direct or\ninherited policy to. This should be used as part of Policy resources\nthat can target Gateway API resources. For more information on how this\npolicy attachment model works, and a sample Policy resource, refer to\nthe policy attachment documentation for Gateway API.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "targetRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of BackendTrafficPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.networking.x-k8s.io/xmesh_v1alpha1.json b/crdSchemas/gateway.networking.x-k8s.io/xmesh_v1alpha1.json
new file mode 100644
index 0000000..168daab
--- /dev/null
+++ b/crdSchemas/gateway.networking.x-k8s.io/xmesh_v1alpha1.json
@@ -0,0 +1,203 @@
+{
+ "description": "XMesh defines mesh-wide characteristics of a GAMMA-compliant service mesh.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of XMesh.",
+ "properties": {
+ "controllerName": {
+ "description": "ControllerName is the name of a controller that is managing Gateway API\nresources for mesh traffic management. The value of this field MUST be a\ndomain prefixed path.\n\nExample: \"example.com/awesome-mesh\".\n\nThis field is not mutable and cannot be empty.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Value is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "description": {
+ "description": "Description optionally provides a human-readable description of a Mesh.",
+ "maxLength": 64,
+ "type": "string"
+ },
+ "parametersRef": {
+ "description": "ParametersRef is an optional reference to a resource that contains\nimplementation-specific configuration for this Mesh. If no\nimplementation-specific parameters are needed, this field MUST be\nomitted.\n\nParametersRef can reference a standard Kubernetes resource, i.e.\nConfigMap, or an implementation-specific custom resource. The resource\ncan be cluster-scoped or namespace-scoped.\n\nIf the referent cannot be found, refers to an unsupported kind, or when\nthe data within that resource is malformed, the Mesh MUST be rejected\nwith the \"Accepted\" status condition set to \"False\" and an\n\"InvalidParameters\" reason.\n\nSupport: Implementation-specific",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent.\nThis field is required when referring to a Namespace-scoped resource and\nMUST be unset when referring to a Cluster-scoped resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "default": {
+ "conditions": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ }
+ ]
+ },
+ "description": "Status defines the current state of XMesh.",
+ "properties": {
+ "conditions": {
+ "default": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ },
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Programmed"
+ }
+ ],
+ "description": "Conditions is the current status from the controller for\nthis Mesh.\n\nControllers should prefer to publish conditions using values\nof MeshConditionType for the type of each Condition.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "supportedFeatures": {
+ "description": "SupportedFeatures is the set of features the Mesh support.\nIt MUST be sorted in ascending alphabetical order by the Name key.",
+ "items": {
+ "properties": {
+ "name": {
+ "description": "FeatureName is used to describe distinct features that are covered by\nconformance tests.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/gateway.pomerium.io/policyfilter_v1alpha1.json b/crdSchemas/gateway.pomerium.io/policyfilter_v1alpha1.json
new file mode 100644
index 0000000..7a75ad8
--- /dev/null
+++ b/crdSchemas/gateway.pomerium.io/policyfilter_v1alpha1.json
@@ -0,0 +1,95 @@
+{
+ "description": "PolicyFilter represents a Pomerium policy that can be attached to a particular route defined\nvia the Kubernetes Gateway API.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the content of the policy.",
+ "properties": {
+ "ppl": {
+ "description": "Policy rules in Pomerium Policy Language (PPL) syntax. May be expressed\nin either YAML or JSON format.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status contains the status of the policy (e.g. is the policy valid).",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describe the current state of the PolicyFilter.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.\n---\nThis struct is intended for direct use as an array at the field path .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents the observations of a foo's current state.\n\t // Known .status.conditions.type are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other fields\n\t}",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.\n---\nMany .condition.type values are consistent across resources like Available, but because arbitrary conditions can be\nuseful (see .node.status.conditions), the ability to deconflict is important.\nThe regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/helmrelease_v2.json b/crdSchemas/helm.toolkit.fluxcd.io/helmrelease_v2.json
similarity index 100%
rename from crdSchemas/helmrelease_v2.json
rename to crdSchemas/helm.toolkit.fluxcd.io/helmrelease_v2.json
diff --git a/crdSchemas/httpscaledobject_v1alpha1.json b/crdSchemas/http.keda.sh/httpscaledobject_v1alpha1.json
similarity index 100%
rename from crdSchemas/httpscaledobject_v1alpha1.json
rename to crdSchemas/http.keda.sh/httpscaledobject_v1alpha1.json
diff --git a/crdSchemas/interceptorroute_v1beta1.json b/crdSchemas/http.keda.sh/interceptorroute_v1beta1.json
similarity index 100%
rename from crdSchemas/interceptorroute_v1beta1.json
rename to crdSchemas/http.keda.sh/interceptorroute_v1beta1.json
diff --git a/crdSchemas/accesscontrolpolicy_v1alpha1.json b/crdSchemas/hub.traefik.io/accesscontrolpolicy_v1alpha1.json
similarity index 97%
rename from crdSchemas/accesscontrolpolicy_v1alpha1.json
rename to crdSchemas/hub.traefik.io/accesscontrolpolicy_v1alpha1.json
index 56a7592..e5287e1 100644
--- a/crdSchemas/accesscontrolpolicy_v1alpha1.json
+++ b/crdSchemas/hub.traefik.io/accesscontrolpolicy_v1alpha1.json
@@ -162,7 +162,7 @@
},
"maxRetries": {
"default": 3,
- "description": "MaxRetries defines the number of retries for introspection requests.",
+ "description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
"type": "integer"
},
"timeoutSeconds": {
@@ -171,14 +171,14 @@
"type": "integer"
},
"tls": {
- "description": "TLS configures TLS communication with the Authorization Server.",
+ "description": "TLS configures TLS for the HTTP client.",
"properties": {
"ca": {
- "description": "CA sets the CA bundle used to sign the Authorization Server certificate.",
+ "description": "CA sets the CA bundle used to verify the server certificate.",
"type": "string"
},
"insecureSkipVerify": {
- "description": "InsecureSkipVerify skips the Authorization Server certificate validation.\nFor testing purposes only, do not use in production.",
+ "description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
"type": "boolean"
}
},
diff --git a/crdSchemas/aiservice_v1alpha1.json b/crdSchemas/hub.traefik.io/aiservice_v1alpha1.json
similarity index 100%
rename from crdSchemas/aiservice_v1alpha1.json
rename to crdSchemas/hub.traefik.io/aiservice_v1alpha1.json
diff --git a/crdSchemas/api_v1alpha1.json b/crdSchemas/hub.traefik.io/api_v1alpha1.json
similarity index 98%
rename from crdSchemas/api_v1alpha1.json
rename to crdSchemas/hub.traefik.io/api_v1alpha1.json
index 85a3e02..8ccb3f6 100644
--- a/crdSchemas/api_v1alpha1.json
+++ b/crdSchemas/hub.traefik.io/api_v1alpha1.json
@@ -208,6 +208,11 @@
}
]
},
+ "refreshInterval": {
+ "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
+ "format": "duration",
+ "type": "string"
+ },
"url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"type": "string",
diff --git a/crdSchemas/apiauth_v1alpha1.json b/crdSchemas/hub.traefik.io/apiauth_v1alpha1.json
similarity index 90%
rename from crdSchemas/apiauth_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apiauth_v1alpha1.json
index 4d8c5c5..0c12738 100644
--- a/crdSchemas/apiauth_v1alpha1.json
+++ b/crdSchemas/hub.traefik.io/apiauth_v1alpha1.json
@@ -59,6 +59,38 @@
"description": "AppIDClaim is the name of the claim holding the identifier of the application.\nThis field is sometimes named `client_id`.",
"type": "string"
},
+ "clientConfig": {
+ "description": "ClientConfig configures the HTTP client used to fetch the JWKS from the JWKS URL or the trusted issuers.",
+ "properties": {
+ "maxRetries": {
+ "default": 3,
+ "description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "default": 5,
+ "description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS configures TLS for the HTTP client.",
+ "properties": {
+ "ca": {
+ "description": "CA sets the CA bundle used to verify the server certificate.",
+ "type": "string"
+ },
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"forwardHeaders": {
"additionalProperties": {
"type": "string"
diff --git a/crdSchemas/apibundle_v1alpha1.json b/crdSchemas/hub.traefik.io/apibundle_v1alpha1.json
similarity index 100%
rename from crdSchemas/apibundle_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apibundle_v1alpha1.json
diff --git a/crdSchemas/apicatalogitem_v1alpha1.json b/crdSchemas/hub.traefik.io/apicatalogitem_v1alpha1.json
similarity index 100%
rename from crdSchemas/apicatalogitem_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apicatalogitem_v1alpha1.json
diff --git a/crdSchemas/apiplan_v1alpha1.json b/crdSchemas/hub.traefik.io/apiplan_v1alpha1.json
similarity index 100%
rename from crdSchemas/apiplan_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apiplan_v1alpha1.json
diff --git a/crdSchemas/apiportal_v1alpha1.json b/crdSchemas/hub.traefik.io/apiportal_v1alpha1.json
similarity index 100%
rename from crdSchemas/apiportal_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apiportal_v1alpha1.json
diff --git a/crdSchemas/apiportalauth_v1alpha1.json b/crdSchemas/hub.traefik.io/apiportalauth_v1alpha1.json
similarity index 89%
rename from crdSchemas/apiportalauth_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apiportalauth_v1alpha1.json
index 9f4b8bf..9dd3a8c 100644
--- a/crdSchemas/apiportalauth_v1alpha1.json
+++ b/crdSchemas/hub.traefik.io/apiportalauth_v1alpha1.json
@@ -162,6 +162,38 @@
"type": "object",
"additionalProperties": false
},
+ "clientConfig": {
+ "description": "ClientConfig configures the HTTP client used to communicate with the OIDC provider.",
+ "properties": {
+ "maxRetries": {
+ "default": 3,
+ "description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "default": 5,
+ "description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS configures TLS for the HTTP client.",
+ "properties": {
+ "ca": {
+ "description": "CA sets the CA bundle used to verify the server certificate.",
+ "type": "string"
+ },
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"issuerUrl": {
"description": "IssuerURL is the OIDC provider issuer URL.",
"type": "string",
diff --git a/crdSchemas/apiratelimit_v1alpha1.json b/crdSchemas/hub.traefik.io/apiratelimit_v1alpha1.json
similarity index 100%
rename from crdSchemas/apiratelimit_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apiratelimit_v1alpha1.json
diff --git a/crdSchemas/apiversion_v1alpha1.json b/crdSchemas/hub.traefik.io/apiversion_v1alpha1.json
similarity index 98%
rename from crdSchemas/apiversion_v1alpha1.json
rename to crdSchemas/hub.traefik.io/apiversion_v1alpha1.json
index e20bb0f..24ad814 100644
--- a/crdSchemas/apiversion_v1alpha1.json
+++ b/crdSchemas/hub.traefik.io/apiversion_v1alpha1.json
@@ -208,6 +208,11 @@
}
]
},
+ "refreshInterval": {
+ "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
+ "format": "duration",
+ "type": "string"
+ },
"url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"type": "string",
diff --git a/crdSchemas/contentitem_v1alpha1.json b/crdSchemas/hub.traefik.io/contentitem_v1alpha1.json
similarity index 100%
rename from crdSchemas/contentitem_v1alpha1.json
rename to crdSchemas/hub.traefik.io/contentitem_v1alpha1.json
diff --git a/crdSchemas/managedapplication_v1alpha1.json b/crdSchemas/hub.traefik.io/managedapplication_v1alpha1.json
similarity index 100%
rename from crdSchemas/managedapplication_v1alpha1.json
rename to crdSchemas/hub.traefik.io/managedapplication_v1alpha1.json
diff --git a/crdSchemas/managedsubscription_v1alpha1.json b/crdSchemas/hub.traefik.io/managedsubscription_v1alpha1.json
similarity index 100%
rename from crdSchemas/managedsubscription_v1alpha1.json
rename to crdSchemas/hub.traefik.io/managedsubscription_v1alpha1.json
diff --git a/crdSchemas/uplink_v1alpha1.json b/crdSchemas/hub.traefik.io/uplink_v1alpha1.json
similarity index 100%
rename from crdSchemas/uplink_v1alpha1.json
rename to crdSchemas/hub.traefik.io/uplink_v1alpha1.json
diff --git a/crdSchemas/imagepolicy_v1.json b/crdSchemas/image.toolkit.fluxcd.io/imagepolicy_v1.json
similarity index 100%
rename from crdSchemas/imagepolicy_v1.json
rename to crdSchemas/image.toolkit.fluxcd.io/imagepolicy_v1.json
diff --git a/crdSchemas/imagepolicy_v1beta2.json b/crdSchemas/image.toolkit.fluxcd.io/imagepolicy_v1beta2.json
similarity index 100%
rename from crdSchemas/imagepolicy_v1beta2.json
rename to crdSchemas/image.toolkit.fluxcd.io/imagepolicy_v1beta2.json
diff --git a/crdSchemas/imagerepository_v1.json b/crdSchemas/image.toolkit.fluxcd.io/imagerepository_v1.json
similarity index 100%
rename from crdSchemas/imagerepository_v1.json
rename to crdSchemas/image.toolkit.fluxcd.io/imagerepository_v1.json
diff --git a/crdSchemas/imagerepository_v1beta2.json b/crdSchemas/image.toolkit.fluxcd.io/imagerepository_v1beta2.json
similarity index 100%
rename from crdSchemas/imagerepository_v1beta2.json
rename to crdSchemas/image.toolkit.fluxcd.io/imagerepository_v1beta2.json
diff --git a/crdSchemas/imageupdateautomation_v1.json b/crdSchemas/image.toolkit.fluxcd.io/imageupdateautomation_v1.json
similarity index 100%
rename from crdSchemas/imageupdateautomation_v1.json
rename to crdSchemas/image.toolkit.fluxcd.io/imageupdateautomation_v1.json
diff --git a/crdSchemas/imageupdateautomation_v1beta2.json b/crdSchemas/image.toolkit.fluxcd.io/imageupdateautomation_v1beta2.json
similarity index 100%
rename from crdSchemas/imageupdateautomation_v1beta2.json
rename to crdSchemas/image.toolkit.fluxcd.io/imageupdateautomation_v1beta2.json
diff --git a/crdSchemas/ingress.pomerium.io/pomerium_v1.json b/crdSchemas/ingress.pomerium.io/pomerium_v1.json
new file mode 100644
index 0000000..7e524ae
--- /dev/null
+++ b/crdSchemas/ingress.pomerium.io/pomerium_v1.json
@@ -0,0 +1,744 @@
+{
+ "description": "Pomerium define runtime-configurable Pomerium settings\nthat do not fall into the category of deployment parameters",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "PomeriumSpec defines Pomerium-specific configuration parameters.",
+ "properties": {
+ "accessLogFields": {
+ "description": "AccessLogFields sets the access fields to log.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "allowUpgrades": {
+ "description": "AllowUpgrades sets the allowed upgrade types.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "authenticate": {
+ "description": "Authenticate sets authenticate service parameters.\nIf not specified, a Pomerium-hosted authenticate service would be used.",
+ "properties": {
+ "url": {
+ "description": "AuthenticateURL is a dedicated domain URL\nthe non-authenticated persons would be referred to.\n\n\n - You do not need to create a dedicated
Ingress for this\n\t\tvirtual route, as it is handled by Pomerium internally. \n\t- You do need create a secret with corresponding TLS certificate for this route\n\t\tand reference it via
certificates.\n\t\tIf you use cert-manager with HTTP01 challenge,\n\t\tyou may use pomerium ingressClass to solve it. \n
",
+ "format": "uri",
+ "pattern": "^https://",
+ "type": "string"
+ }
+ },
+ "required": [
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "authorizeLogFields": {
+ "description": "AuthorizeLogFields sets the authorize fields to log.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "bearerTokenFormat": {
+ "description": "BearerTokenFormat sets the Bearer Token Format.",
+ "enum": [
+ "default",
+ "idp_access_token",
+ "idp_identity_token"
+ ],
+ "type": "string"
+ },
+ "caSecrets": {
+ "description": "CASecret should refer to k8s secrets with key ca.crt containing a CA certificate.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "certificateAutoProvision": {
+ "description": "CertificateAutoProvision sets the certificate auto provision settings.\nThis is a fallback for routes that are not defined via Ingress or\nGateway resources. When configured, cert-manager certificate resources\nwill be created for any routes which have no matching TLS certificate.",
+ "properties": {
+ "clusterIssuer": {
+ "description": "The cert-manager ClusterIssuer that will be used for new certificates.\nCertificates will be created in the same namespace as the controller\npod.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "issuer": {
+ "description": "The cert-manager Issuer that will be used for new certificates.\nCertificates will be created in the same namespace as the Issuer.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "certificates": {
+ "description": "Certificates is a list of secrets of type TLS to use",
+ "format": "namespace/name",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "circuitBreakerThresholds": {
+ "description": "CircuitBreakerThresholds sets the circuit breaker thresholds settings.",
+ "properties": {
+ "maxConnectionPools": {
+ "description": "MaxConnectionPools sets the maximum number of connection pools per\ncluster that Envoy will concurrently support at once. If not specified,\nthe default is unlimited. Set this for clusters which create a large\nnumber of connection pools.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxConnections": {
+ "description": "MaxConnections sets the maximum number of connections that Envoy will\nmake to the upstream cluster. If not specified, the default is 1024.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "description": "MaxPendingRequests sets the maximum number of pending requests that\nEnvoy will allow to the upstream cluster. If not specified, the\ndefault is 1024. This limit is applied as a connection limit for\nnon-HTTP traffic.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxRequests": {
+ "description": "MaxRequests sets the maximum number of parallel requests that Envoy\nwill make to the upstream cluster. If not specified, the default is\n1024. This limit does not apply to non-HTTP traffic.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxRetries": {
+ "description": "MaxRetries sets the maximum number of parallel retries that Envoy\nwill allow to the upstream cluster. If not specified, the default is 3.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "codecType": {
+ "description": "CodecType sets the Codec Type.",
+ "enum": [
+ "auto",
+ "http1",
+ "http2",
+ "http3"
+ ],
+ "type": "string"
+ },
+ "cookie": {
+ "description": "Cookie defines Pomerium session cookie options.",
+ "properties": {
+ "domain": {
+ "description": "Domain defaults to the same host that set the cookie.\nIf you specify the domain explicitly, then subdomains would also be included.",
+ "type": "string"
+ },
+ "expire": {
+ "description": "Expire sets cookie and Pomerium session expiration time.\nOnce session expires, users would have to re-login.\nIf you change this parameter, existing sessions are not affected.\nSee Session Management\n(Enterprise) for a more fine-grained session controls.
\nDefaults to 14 hours.
",
+ "format": "duration",
+ "type": "string"
+ },
+ "httpOnly": {
+ "description": "HTTPOnly if set to false, the cookie would be accessible from within the JavaScript.\nDefaults to true.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name sets the Pomerium session cookie name.\nDefaults to _pomerium",
+ "type": "string"
+ },
+ "sameSite": {
+ "description": "SameSite sets the SameSite option for cookies.\nDefaults to .",
+ "enum": [
+ "strict",
+ "lax",
+ "none"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dataBroker": {
+ "description": "DataBroker sets the databroker settings.",
+ "properties": {
+ "clusterLeaderId": {
+ "description": "ClusterLeaderID defines the cluster leader in a clustered databroker.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS sets the dns settings.",
+ "properties": {
+ "failureRefreshRate": {
+ "description": "FailureRefreshRate is the rate at which DNS lookups are refreshed when requests are failing.",
+ "format": "duration",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily is the DNS IP address resolution policy.",
+ "enum": [
+ "auto",
+ "v4_only",
+ "v6_only",
+ "v4_preferred",
+ "all"
+ ],
+ "type": "string"
+ },
+ "queryTimeout": {
+ "description": "QueryTimeout is the amount of time each name server is given to respond to a query on the first try of any given server.",
+ "format": "duration",
+ "type": "string"
+ },
+ "queryTries": {
+ "description": "QueryTries is the maximum number of query attempts the resolver will make before giving up. Each attempt may use a different name server.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "refreshRate": {
+ "description": "RefreshRate is the rate at which DNS lookups are refreshed.",
+ "format": "duration",
+ "type": "string"
+ },
+ "udpMaxQueries": {
+ "description": "UDPMaxQueries caps the number of UDP based DNS queries on a single port.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "useTcp": {
+ "description": "UseTCP uses TCP for all DNS queries instead of the default protocol UDP.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "downstreamMtls": {
+ "description": "DownstreamMTLS sets the Downstream MTLS Settings.",
+ "properties": {
+ "ca": {
+ "description": "CA is a bundle of PEM-encoded X.509 certificates that will be treated as trust anchors when verifying client certificates.",
+ "format": "byte",
+ "type": "string"
+ },
+ "crl": {
+ "description": "CRL is a bundle of PEM-encoded certificate revocation lists to be consulted during certificate validation.",
+ "format": "byte",
+ "type": "string"
+ },
+ "enforcement": {
+ "description": "Enforcement controls Pomerium's behavior when a client does not present a trusted client certificate.",
+ "enum": [
+ "policy_with_default_deny",
+ "policy",
+ "reject_connection"
+ ],
+ "type": "string"
+ },
+ "matchSubjectAltNames": {
+ "description": "Match Subject Alt Names can be used to add an additional constraint when validating client certificates.",
+ "properties": {
+ "dns": {
+ "type": "string"
+ },
+ "email": {
+ "type": "string"
+ },
+ "ipAddress": {
+ "type": "string"
+ },
+ "uri": {
+ "type": "string"
+ },
+ "userPrincipalName": {
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxVerifyDepth": {
+ "description": "MaxVerifyDepth sets a limit on the depth of a certificate chain presented by the client.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "envoyDynamicExtensions": {
+ "description": "EnvoyDynamicExtensions file paths to the extensions to be loaded by Envoy at runtime.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "headersWithUnderscoresAction": {
+ "description": "HeadersWithUnderscoresAction controls the behavior for a request with a\nheader name containing an underscore character. The default behavior is\nreject_request.",
+ "enum": [
+ "allow",
+ "reject_request",
+ "drop_header"
+ ],
+ "type": "string"
+ },
+ "identityProvider": {
+ "description": "IdentityProvider configure single-sign-on authentication and user identity details\nby integrating with your Identity Provider",
+ "properties": {
+ "provider": {
+ "description": "Provider is the short-hand name of a built-in OpenID Connect (oidc) identity provider to be used for authentication.\nTo use a generic provider, set to oidc.",
+ "enum": [
+ "apple",
+ "auth0",
+ "azure",
+ "cognito",
+ "github",
+ "gitlab",
+ "google",
+ "hosted",
+ "oidc",
+ "okta",
+ "onelogin",
+ "ping"
+ ],
+ "type": "string"
+ },
+ "refreshDirectory": {
+ "description": "RefreshDirectory is no longer supported,\nplease see Upgrade Guide.",
+ "properties": {
+ "interval": {
+ "description": "interval is the time that pomerium will sync your IDP directory.",
+ "format": "duration",
+ "type": "string"
+ },
+ "timeout": {
+ "description": "timeout is the maximum time allowed each run.",
+ "format": "duration",
+ "type": "string"
+ }
+ },
+ "required": [
+ "interval",
+ "timeout"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestParams": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "RequestParams to be added as part of a sign-in request using OAuth2 code flow.",
+ "format": "namespace/name",
+ "type": "object"
+ },
+ "requestParamsSecret": {
+ "description": "RequestParamsSecret is a reference to a secret for additional parameters you'd prefer not to provide in plaintext.",
+ "format": "namespace/name",
+ "type": "string"
+ },
+ "scopes": {
+ "description": "Scopes Identity provider scopes correspond to access privilege scopes\nas defined in Section 3.3 of OAuth 2.0 RFC6749.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "secret": {
+ "description": "Secret containing IdP provider specific parameters.\nand must contain at least client_id and client_secret values.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "serviceAccountFromSecret": {
+ "description": "ServiceAccountFromSecret is no longer supported,\nsee Upgrade Guide.",
+ "type": "string"
+ },
+ "url": {
+ "description": "URL is the base path to an identity provider's OpenID connect discovery document.\nSee Identity Providers guides for details.",
+ "format": "uri",
+ "pattern": "^https://",
+ "type": "string"
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "fieldPath": ".secret",
+ "message": "secret is required unless provider is 'hosted'",
+ "reason": "FieldValueRequired",
+ "rule": "self.provider != 'hosted' ? has(self.secret) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "idpAccessTokenAllowedAudiences": {
+ "description": "IDPAccessTokenAllowedAudiences specifies the\nidp access token allowed audiences\nlist.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "jwtClaimHeaders": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "JWTClaimHeaders convert claims from the assertion token\ninto HTTP headers and adds them into JWT assertion header.\nPlease make sure to read\n\nGetting User Identity guide.",
+ "type": "object"
+ },
+ "mcpAllowedAsMetadataDomains": {
+ "description": "MCPAllowedASMetadataDomains specifies the allowed domains for upstream AS/PRM metadata URLs.\nSupports wildcard patterns like \"*.example.com\".\nThis restricts which domains Pomerium will contact during upstream OAuth discovery\n(resource_metadata from WWW-Authenticate, authorization_servers from PRM).\nSee MCP Settings.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "mcpAllowedClientIdDomains": {
+ "description": "MCPAllowedClientIDDomains specifies the allowed domains for MCP client ID metadata URLs.\nThis is required when MCP is enabled.\nSee MCP Settings.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "mergeSlashes": {
+ "description": "MergeSlashes controls whether adjacent slashes in the request URI path\nwill be merged into one. Defaults to true.",
+ "type": "boolean"
+ },
+ "normalizePath": {
+ "description": "NormalizePath controls whether request URI paths will be normalized\naccording to RFC 3986. Defaults to true.",
+ "type": "boolean"
+ },
+ "otel": {
+ "description": "OTEL sets the OpenTelemetry Tracing.",
+ "properties": {
+ "bspMaxExportBatchSize": {
+ "description": "BSPMaxExportBatchSize sets the maximum number of spans to export in a single batch",
+ "format": "int32",
+ "type": "integer"
+ },
+ "bspScheduleDelay": {
+ "description": "BSPScheduleDelay sets interval between two consecutive exports",
+ "format": "duration",
+ "type": "string"
+ },
+ "endpoint": {
+ "description": "An OTLP/gRPC or OTLP/HTTP base endpoint URL with optional port.
Example: `http://localhost:4318`",
+ "type": "string"
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Extra headers",
+ "type": "object"
+ },
+ "logLevel": {
+ "description": "LogLevel sets the log level for the OpenTelemetry SDK.",
+ "enum": [
+ "trace",
+ "debug",
+ "info",
+ "warn",
+ "error"
+ ],
+ "type": "string"
+ },
+ "protocol": {
+ "description": "Valid values are `\"grpc\"` or `\"http/protobuf\"`.",
+ "enum": [
+ "grpc",
+ "http/protobuf"
+ ],
+ "type": "string"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes sets the additional attributes to be added to the trace.",
+ "type": "object"
+ },
+ "sampling": {
+ "description": "Sampling sets sampling probability between [0, 1].",
+ "format": "number",
+ "type": "string"
+ },
+ "timeout": {
+ "description": "Export request timeout duration",
+ "format": "duration",
+ "type": "string"
+ }
+ },
+ "required": [
+ "endpoint",
+ "protocol"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "passIdentityHeaders": {
+ "description": "PassIdentityHeaders sets the pass identity headers option.",
+ "type": "boolean"
+ },
+ "pathWithEscapedSlashesAction": {
+ "description": "PathWithEscapedSlashesAction controls the behavior for a request with an\nescaped slash or backslash character in the URI path. This operation will\noccur before path normalization and the merge slashes operation. The\ndefault behavior is reject_request.",
+ "enum": [
+ "keep_unchanged",
+ "reject_request",
+ "unescape_and_redirect",
+ "unescape_and_forward"
+ ],
+ "type": "string"
+ },
+ "programmaticRedirectDomains": {
+ "description": "ProgrammaticRedirectDomains specifies a list of domains that can be used for\nprogrammatic redirects.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "runtimeFlags": {
+ "additionalProperties": {
+ "type": "boolean"
+ },
+ "description": "RuntimeFlags sets the runtime flags to enable/disable certain features.",
+ "type": "object"
+ },
+ "secrets": {
+ "description": "Secrets references a Secret with Pomerium bootstrap parameters.\n\n\n
\n\n\nIn a default Pomerium installation manifest, they would be generated via a\none-time job\nand stored in a pomerium/bootstrap Secret.\nYou may re-run the job to rotate the secrets, or update the Secret values manually.\n
\n\nWhen defining the Secret in a manifest, put raw values in stringData so\nKubernetes base64-encodes them. Use data only when values are already\nbase64-encoded.\n
\n\nExample: stringData.shared_secret and stringData.cookie_secret are\nraw strings, while data.signing_key is base64-encoded.\n
",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "setResponseHeaders": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "SetResponseHeaders specifies a mapping of HTTP Header to be added globally to all managed routes and pomerium's authenticate service.\nSee Set Response Headers",
+ "type": "object"
+ },
+ "ssh": {
+ "description": "SSH sets the ssh settings.",
+ "properties": {
+ "hostKeySecrets": {
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "userCaKeySecret": {
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "storage": {
+ "description": "Storage defines persistent storage for sessions and other data.\nSee Storage for details.\nIf no storage is specified, Pomerium would use a transient in-memory storage (not recommended for production).",
+ "properties": {
+ "file": {
+ "description": "File specifies file storage options.",
+ "properties": {
+ "path": {
+ "description": "Path defines the local file system path to store data.",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "postgres": {
+ "description": "Postgres specifies PostgreSQL database connection parameters",
+ "properties": {
+ "caSecret": {
+ "description": "CASecret should refer to a k8s secret with key ca.crt containing CA certificate\nthat, if specified, would be used to populate sslrootcert parameter of the connection string.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "secret": {
+ "description": "Secret specifies a name of a Secret that must contain\nconnection key. See\nDSN Format and Parameters.\nDo not set sslrootcert, sslcert and sslkey via connection string,\nuse tlsSecret and caSecret CRD options instead.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "tlsSecret": {
+ "description": "TLSSecret should refer to a k8s secret of type kubernetes.io/tls\nand allows to specify an optional client certificate and key,\nby constructing sslcert and sslkey connection string\n\nparameter values.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "secret"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeouts": {
+ "description": "Timeout specifies the global timeouts for all routes.",
+ "properties": {
+ "idle": {
+ "description": "Idle specifies the time at which a downstream or upstream connection will be terminated if there are no active streams.",
+ "format": "duration",
+ "type": "string"
+ },
+ "read": {
+ "description": "Read specifies the amount of time for the entire request stream to be received from the client.",
+ "format": "duration",
+ "type": "string"
+ },
+ "write": {
+ "description": "Write specifies max stream duration is the maximum time that a stream\u2019s lifetime will span.\nAn HTTP request/response exchange fully consumes a single stream.\nTherefore, this value must be greater than read_timeout as it covers both request and response time.",
+ "format": "duration",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "useProxyProtocol": {
+ "description": "UseProxyProtocol enables Proxy Protocol support.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "secrets"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "fieldPath": ".authenticate",
+ "message": "authenticate is required if identityProvider is set",
+ "reason": "FieldValueRequired",
+ "rule": "!has(self.identityProvider) || has(self.authenticate)"
+ },
+ {
+ "fieldPath": ".identityProvider",
+ "message": "identityProvider is required if authenticate is set",
+ "reason": "FieldValueRequired",
+ "rule": "!has(self.authenticate) || has(self.identityProvider)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "PomeriumStatus represents configuration and Ingress status.",
+ "properties": {
+ "certificateAutoProvisionStatus": {
+ "description": "Status of certificate auto provisioning.",
+ "properties": {
+ "dataBrokerLastUpdated": {
+ "format": "date-time",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ingress": {
+ "additionalProperties": {
+ "description": "ResourceStatus represents the outcome of the latest attempt to reconcile\nrelevant Kubernetes resource with Pomerium.",
+ "properties": {
+ "error": {
+ "description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
+ "type": "string"
+ },
+ "observedAt": {
+ "description": "ObservedAt is when last reconciliation attempt was made.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "reconciled": {
+ "description": "Reconciled is whether this object generation was successfully synced with pomerium.",
+ "type": "boolean"
+ },
+ "warnings": {
+ "description": "Warnings while parsing the resource.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "reconciled"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "description": "Routes provide per-Ingress status.",
+ "type": "object"
+ },
+ "settingsStatus": {
+ "description": "SettingsStatus represent most recent main configuration reconciliation status.",
+ "properties": {
+ "error": {
+ "description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
+ "type": "string"
+ },
+ "observedAt": {
+ "description": "ObservedAt is when last reconciliation attempt was made.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "reconciled": {
+ "description": "Reconciled is whether this object generation was successfully synced with pomerium.",
+ "type": "boolean"
+ },
+ "warnings": {
+ "description": "Warnings while parsing the resource.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "reconciled"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/clustertriggerauthentication_v1alpha1.json b/crdSchemas/keda.sh/clustertriggerauthentication_v1alpha1.json
similarity index 100%
rename from crdSchemas/clustertriggerauthentication_v1alpha1.json
rename to crdSchemas/keda.sh/clustertriggerauthentication_v1alpha1.json
diff --git a/crdSchemas/scaledjob_v1alpha1.json b/crdSchemas/keda.sh/scaledjob_v1alpha1.json
similarity index 100%
rename from crdSchemas/scaledjob_v1alpha1.json
rename to crdSchemas/keda.sh/scaledjob_v1alpha1.json
diff --git a/crdSchemas/scaledobject_v1alpha1.json b/crdSchemas/keda.sh/scaledobject_v1alpha1.json
similarity index 100%
rename from crdSchemas/scaledobject_v1alpha1.json
rename to crdSchemas/keda.sh/scaledobject_v1alpha1.json
diff --git a/crdSchemas/triggerauthentication_v1alpha1.json b/crdSchemas/keda.sh/triggerauthentication_v1alpha1.json
similarity index 100%
rename from crdSchemas/triggerauthentication_v1alpha1.json
rename to crdSchemas/keda.sh/triggerauthentication_v1alpha1.json
diff --git a/crdSchemas/clusterkeycloakinstance_v1beta1.json b/crdSchemas/keycloak.hostzero.com/clusterkeycloakinstance_v1beta1.json
similarity index 100%
rename from crdSchemas/clusterkeycloakinstance_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/clusterkeycloakinstance_v1beta1.json
diff --git a/crdSchemas/clusterkeycloakrealm_v1beta1.json b/crdSchemas/keycloak.hostzero.com/clusterkeycloakrealm_v1beta1.json
similarity index 100%
rename from crdSchemas/clusterkeycloakrealm_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/clusterkeycloakrealm_v1beta1.json
diff --git a/crdSchemas/keycloakauthenticationflow_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakauthenticationflow_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakauthenticationflow_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakauthenticationflow_v1beta1.json
diff --git a/crdSchemas/keycloakclient_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakclient_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakclient_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakclient_v1beta1.json
diff --git a/crdSchemas/keycloakclientscope_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakclientscope_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakclientscope_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakclientscope_v1beta1.json
diff --git a/crdSchemas/keycloakcomponent_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakcomponent_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakcomponent_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakcomponent_v1beta1.json
diff --git a/crdSchemas/keycloakgroup_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakgroup_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakgroup_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakgroup_v1beta1.json
diff --git a/crdSchemas/keycloakidentityprovider_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakidentityprovider_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakidentityprovider_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakidentityprovider_v1beta1.json
diff --git a/crdSchemas/keycloakidentityprovidermapper_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakidentityprovidermapper_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakidentityprovidermapper_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakidentityprovidermapper_v1beta1.json
diff --git a/crdSchemas/keycloakinstance_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakinstance_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakinstance_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakinstance_v1beta1.json
diff --git a/crdSchemas/keycloakorganization_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakorganization_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakorganization_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakorganization_v1beta1.json
diff --git a/crdSchemas/keycloakprotocolmapper_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakprotocolmapper_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakprotocolmapper_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakprotocolmapper_v1beta1.json
diff --git a/crdSchemas/keycloakrealm_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakrealm_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakrealm_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakrealm_v1beta1.json
diff --git a/crdSchemas/keycloakrequiredaction_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakrequiredaction_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakrequiredaction_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakrequiredaction_v1beta1.json
diff --git a/crdSchemas/keycloakrole_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakrole_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakrole_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakrole_v1beta1.json
diff --git a/crdSchemas/keycloakrolemapping_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakrolemapping_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakrolemapping_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakrolemapping_v1beta1.json
diff --git a/crdSchemas/keycloakuser_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakuser_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakuser_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakuser_v1beta1.json
diff --git a/crdSchemas/keycloakusercredential_v1beta1.json b/crdSchemas/keycloak.hostzero.com/keycloakusercredential_v1beta1.json
similarity index 100%
rename from crdSchemas/keycloakusercredential_v1beta1.json
rename to crdSchemas/keycloak.hostzero.com/keycloakusercredential_v1beta1.json
diff --git a/crdSchemas/kustomization_v1.json b/crdSchemas/kustomize.toolkit.fluxcd.io/kustomization_v1.json
similarity index 100%
rename from crdSchemas/kustomization_v1.json
rename to crdSchemas/kustomize.toolkit.fluxcd.io/kustomization_v1.json
diff --git a/crdSchemas/backingimage_v1beta2.json b/crdSchemas/longhorn.io/backingimage_v1beta2.json
similarity index 100%
rename from crdSchemas/backingimage_v1beta2.json
rename to crdSchemas/longhorn.io/backingimage_v1beta2.json
diff --git a/crdSchemas/backingimagedatasource_v1beta2.json b/crdSchemas/longhorn.io/backingimagedatasource_v1beta2.json
similarity index 100%
rename from crdSchemas/backingimagedatasource_v1beta2.json
rename to crdSchemas/longhorn.io/backingimagedatasource_v1beta2.json
diff --git a/crdSchemas/backingimagemanager_v1beta2.json b/crdSchemas/longhorn.io/backingimagemanager_v1beta2.json
similarity index 100%
rename from crdSchemas/backingimagemanager_v1beta2.json
rename to crdSchemas/longhorn.io/backingimagemanager_v1beta2.json
diff --git a/crdSchemas/backupbackingimage_v1beta2.json b/crdSchemas/longhorn.io/backupbackingimage_v1beta2.json
similarity index 100%
rename from crdSchemas/backupbackingimage_v1beta2.json
rename to crdSchemas/longhorn.io/backupbackingimage_v1beta2.json
diff --git a/crdSchemas/backuptarget_v1beta2.json b/crdSchemas/longhorn.io/backuptarget_v1beta2.json
similarity index 100%
rename from crdSchemas/backuptarget_v1beta2.json
rename to crdSchemas/longhorn.io/backuptarget_v1beta2.json
diff --git a/crdSchemas/backupvolume_v1beta2.json b/crdSchemas/longhorn.io/backupvolume_v1beta2.json
similarity index 100%
rename from crdSchemas/backupvolume_v1beta2.json
rename to crdSchemas/longhorn.io/backupvolume_v1beta2.json
diff --git a/crdSchemas/engine_v1beta2.json b/crdSchemas/longhorn.io/engine_v1beta2.json
similarity index 100%
rename from crdSchemas/engine_v1beta2.json
rename to crdSchemas/longhorn.io/engine_v1beta2.json
diff --git a/crdSchemas/enginefrontend_v1beta2.json b/crdSchemas/longhorn.io/enginefrontend_v1beta2.json
similarity index 100%
rename from crdSchemas/enginefrontend_v1beta2.json
rename to crdSchemas/longhorn.io/enginefrontend_v1beta2.json
diff --git a/crdSchemas/engineimage_v1beta2.json b/crdSchemas/longhorn.io/engineimage_v1beta2.json
similarity index 100%
rename from crdSchemas/engineimage_v1beta2.json
rename to crdSchemas/longhorn.io/engineimage_v1beta2.json
diff --git a/crdSchemas/instancemanager_v1beta2.json b/crdSchemas/longhorn.io/instancemanager_v1beta2.json
similarity index 100%
rename from crdSchemas/instancemanager_v1beta2.json
rename to crdSchemas/longhorn.io/instancemanager_v1beta2.json
diff --git a/crdSchemas/node_v1beta2.json b/crdSchemas/longhorn.io/node_v1beta2.json
similarity index 100%
rename from crdSchemas/node_v1beta2.json
rename to crdSchemas/longhorn.io/node_v1beta2.json
diff --git a/crdSchemas/orphan_v1beta2.json b/crdSchemas/longhorn.io/orphan_v1beta2.json
similarity index 100%
rename from crdSchemas/orphan_v1beta2.json
rename to crdSchemas/longhorn.io/orphan_v1beta2.json
diff --git a/crdSchemas/recurringjob_v1beta2.json b/crdSchemas/longhorn.io/recurringjob_v1beta2.json
similarity index 100%
rename from crdSchemas/recurringjob_v1beta2.json
rename to crdSchemas/longhorn.io/recurringjob_v1beta2.json
diff --git a/crdSchemas/replica_v1beta2.json b/crdSchemas/longhorn.io/replica_v1beta2.json
similarity index 100%
rename from crdSchemas/replica_v1beta2.json
rename to crdSchemas/longhorn.io/replica_v1beta2.json
diff --git a/crdSchemas/setting_v1beta2.json b/crdSchemas/longhorn.io/setting_v1beta2.json
similarity index 100%
rename from crdSchemas/setting_v1beta2.json
rename to crdSchemas/longhorn.io/setting_v1beta2.json
diff --git a/crdSchemas/sharemanager_v1beta2.json b/crdSchemas/longhorn.io/sharemanager_v1beta2.json
similarity index 100%
rename from crdSchemas/sharemanager_v1beta2.json
rename to crdSchemas/longhorn.io/sharemanager_v1beta2.json
diff --git a/crdSchemas/snapshot_v1beta2.json b/crdSchemas/longhorn.io/snapshot_v1beta2.json
similarity index 100%
rename from crdSchemas/snapshot_v1beta2.json
rename to crdSchemas/longhorn.io/snapshot_v1beta2.json
diff --git a/crdSchemas/supportbundle_v1beta2.json b/crdSchemas/longhorn.io/supportbundle_v1beta2.json
similarity index 100%
rename from crdSchemas/supportbundle_v1beta2.json
rename to crdSchemas/longhorn.io/supportbundle_v1beta2.json
diff --git a/crdSchemas/systembackup_v1beta2.json b/crdSchemas/longhorn.io/systembackup_v1beta2.json
similarity index 100%
rename from crdSchemas/systembackup_v1beta2.json
rename to crdSchemas/longhorn.io/systembackup_v1beta2.json
diff --git a/crdSchemas/systemrestore_v1beta2.json b/crdSchemas/longhorn.io/systemrestore_v1beta2.json
similarity index 100%
rename from crdSchemas/systemrestore_v1beta2.json
rename to crdSchemas/longhorn.io/systemrestore_v1beta2.json
diff --git a/crdSchemas/volume_v1beta2.json b/crdSchemas/longhorn.io/volume_v1beta2.json
similarity index 100%
rename from crdSchemas/volume_v1beta2.json
rename to crdSchemas/longhorn.io/volume_v1beta2.json
diff --git a/crdSchemas/volumeattachment_v1beta2.json b/crdSchemas/longhorn.io/volumeattachment_v1beta2.json
similarity index 100%
rename from crdSchemas/volumeattachment_v1beta2.json
rename to crdSchemas/longhorn.io/volumeattachment_v1beta2.json
diff --git a/crdSchemas/master-standalone/accesscontrolpolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/accesscontrolpolicy-stable-v1alpha1.json
index 56a7592..e5287e1 100644
--- a/crdSchemas/master-standalone/accesscontrolpolicy-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/accesscontrolpolicy-stable-v1alpha1.json
@@ -162,7 +162,7 @@
},
"maxRetries": {
"default": 3,
- "description": "MaxRetries defines the number of retries for introspection requests.",
+ "description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
"type": "integer"
},
"timeoutSeconds": {
@@ -171,14 +171,14 @@
"type": "integer"
},
"tls": {
- "description": "TLS configures TLS communication with the Authorization Server.",
+ "description": "TLS configures TLS for the HTTP client.",
"properties": {
"ca": {
- "description": "CA sets the CA bundle used to sign the Authorization Server certificate.",
+ "description": "CA sets the CA bundle used to verify the server certificate.",
"type": "string"
},
"insecureSkipVerify": {
- "description": "InsecureSkipVerify skips the Authorization Server certificate validation.\nFor testing purposes only, do not use in production.",
+ "description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
"type": "boolean"
}
},
diff --git a/crdSchemas/master-standalone/alertmanager-stable-v1.json b/crdSchemas/master-standalone/alertmanager-stable-v1.json
index 2d7d8f0..20cc906 100644
--- a/crdSchemas/master-standalone/alertmanager-stable-v1.json
+++ b/crdSchemas/master-standalone/alertmanager-stable-v1.json
@@ -1392,7 +1392,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -3692,7 +3692,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -5236,7 +5236,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -7501,7 +7501,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -7650,7 +7650,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
@@ -8291,6 +8291,7 @@
"getConcurrency": {
"description": "getConcurrency defines the maximum number of GET requests processed concurrently. This corresponds to the\nAlertmanager's `--web.get-concurrency` flag.",
"format": "int32",
+ "minimum": 0,
"type": "integer"
},
"httpConfig": {
@@ -8343,6 +8344,7 @@
"timeout": {
"description": "timeout for HTTP requests. This corresponds to the Alertmanager's\n`--web.timeout` flag.",
"format": "int32",
+ "minimum": 0,
"type": "integer"
},
"tlsConfig": {
diff --git a/crdSchemas/master-standalone/alertmanagerconfig-stable-v1alpha1.json b/crdSchemas/master-standalone/alertmanagerconfig-stable-v1alpha1.json
index 13bc334..d8d0671 100644
--- a/crdSchemas/master-standalone/alertmanagerconfig-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/alertmanagerconfig-stable-v1alpha1.json
@@ -703,7 +703,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -1729,7 +1729,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -2455,7 +2455,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -3250,7 +3250,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -4062,7 +4062,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -4878,7 +4878,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5740,7 +5740,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6670,7 +6670,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6968,6 +6968,10 @@
"description": "titleLink defines the URL that the title will link to when clicked.",
"type": "string"
},
+ "updateMessage": {
+ "description": "updateMessage enables updating existing Slack messages instead of creating new ones\nwhen alert state changes. Please note that Webhook URLs do not support updates.\nIt requires Alertmanager >= v0.32.0.",
+ "type": "boolean"
+ },
"username": {
"description": "username defines the slack bot user name.",
"minLength": 1,
@@ -7437,7 +7441,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -7777,6 +7781,10 @@
"description": "topicARN defines the SNS topic ARN, e.g. arn:aws:sns:us-east-2:698519295917:My-Topic.\nIf you don't specify this value, you must specify a value for the PhoneNumber or TargetARN.",
"minLength": 1,
"type": "string"
+ },
+ "useAWSHTTPClient": {
+ "description": "useAWSHTTPClient forces the AWS SDK's BuildableClient instead of\nalertmanager's tracing-wrapped HTTP client. Auto-enabled when AWS_CA_BUNDLE\nis set; set explicitly when configuring ca_bundle via shared AWS config.\n\nIt requires Alertmanager >= 0.33.0.",
+ "type": "boolean"
}
},
"type": "object",
@@ -8273,7 +8281,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9040,7 +9048,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9755,7 +9763,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -10454,7 +10462,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -10690,6 +10698,11 @@
"minimum": 0,
"type": "integer"
},
+ "payload": {
+ "description": "payload define custom payload to be sent to the webhook endpoint.\nThis is an advanced configuration option that allows you\nto define a custom payload using Go templates.\nIt requires Alertmanager >= v0.32.0.",
+ "minLength": 1,
+ "type": "string"
+ },
"sendResolved": {
"description": "sendResolved defines whether or not to notify about resolved alerts.",
"type": "boolean"
@@ -11219,7 +11232,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
diff --git a/crdSchemas/master-standalone/api-stable-v1alpha1.json b/crdSchemas/master-standalone/api-stable-v1alpha1.json
index 85a3e02..8ccb3f6 100644
--- a/crdSchemas/master-standalone/api-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/api-stable-v1alpha1.json
@@ -208,6 +208,11 @@
}
]
},
+ "refreshInterval": {
+ "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
+ "format": "duration",
+ "type": "string"
+ },
"url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"type": "string",
diff --git a/crdSchemas/master-standalone/apiauth-stable-v1alpha1.json b/crdSchemas/master-standalone/apiauth-stable-v1alpha1.json
index 4d8c5c5..0c12738 100644
--- a/crdSchemas/master-standalone/apiauth-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/apiauth-stable-v1alpha1.json
@@ -59,6 +59,38 @@
"description": "AppIDClaim is the name of the claim holding the identifier of the application.\nThis field is sometimes named `client_id`.",
"type": "string"
},
+ "clientConfig": {
+ "description": "ClientConfig configures the HTTP client used to fetch the JWKS from the JWKS URL or the trusted issuers.",
+ "properties": {
+ "maxRetries": {
+ "default": 3,
+ "description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "default": 5,
+ "description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS configures TLS for the HTTP client.",
+ "properties": {
+ "ca": {
+ "description": "CA sets the CA bundle used to verify the server certificate.",
+ "type": "string"
+ },
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"forwardHeaders": {
"additionalProperties": {
"type": "string"
diff --git a/crdSchemas/master-standalone/apiportalauth-stable-v1alpha1.json b/crdSchemas/master-standalone/apiportalauth-stable-v1alpha1.json
index 9f4b8bf..9dd3a8c 100644
--- a/crdSchemas/master-standalone/apiportalauth-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/apiportalauth-stable-v1alpha1.json
@@ -162,6 +162,38 @@
"type": "object",
"additionalProperties": false
},
+ "clientConfig": {
+ "description": "ClientConfig configures the HTTP client used to communicate with the OIDC provider.",
+ "properties": {
+ "maxRetries": {
+ "default": 3,
+ "description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "default": 5,
+ "description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS configures TLS for the HTTP client.",
+ "properties": {
+ "ca": {
+ "description": "CA sets the CA bundle used to verify the server certificate.",
+ "type": "string"
+ },
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"issuerUrl": {
"description": "IssuerURL is the OIDC provider issuer URL.",
"type": "string",
diff --git a/crdSchemas/master-standalone/apiversion-stable-v1alpha1.json b/crdSchemas/master-standalone/apiversion-stable-v1alpha1.json
index e20bb0f..24ad814 100644
--- a/crdSchemas/master-standalone/apiversion-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/apiversion-stable-v1alpha1.json
@@ -208,6 +208,11 @@
}
]
},
+ "refreshInterval": {
+ "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
+ "format": "duration",
+ "type": "string"
+ },
"url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"type": "string",
diff --git a/crdSchemas/master-standalone/attunedefaults-stable-v1alpha1.json b/crdSchemas/master-standalone/attunedefaults-stable-v1alpha1.json
new file mode 100644
index 0000000..cc32433
--- /dev/null
+++ b/crdSchemas/master-standalone/attunedefaults-stable-v1alpha1.json
@@ -0,0 +1,763 @@
+{
+ "description": "AttuneDefaults is the Schema for the attunedefaults API.\nIt defines cluster-scoped default values for AttunePolicy resources.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "AttuneDefaultsSpec defines cluster-scoped default values for AttunePolicy resources.",
+ "properties": {
+ "costPricing": {
+ "description": "CostPricing configures the per-unit pricing used to compute\nEstimatedMonthlySavings. If omitted, defaults to standard\non-demand Linux pricing ($0.031/vCPU-hour, $0.004/GiB-hour).",
+ "properties": {
+ "cpuPerCoreHour": {
+ "description": "CPUPerCoreHour is the cost per vCPU-hour (e.g. \"0.031\").\nDefaults to 0.031 if not specified.",
+ "type": "string"
+ },
+ "memoryPerGiBHour": {
+ "description": "MemoryPerGiBHour is the cost per GiB-hour (e.g. \"0.004\").\nDefaults to 0.004 if not specified.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpu": {
+ "description": "CPU configures default CPU resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "excludeKnownSidecars": {
+ "description": "ExcludeKnownSidecars, when true (the default when unset on both\ndefaults and policy), automatically skips well-known mesh and\nsidecar container names. Set to false cluster-wide to restore\nexclude-only-via-excludedContainers behavior for policies that\ndo not set the field themselves.",
+ "type": "boolean"
+ },
+ "memory": {
+ "description": "Memory configures default memory resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metricsSource": {
+ "description": "MetricsSource configures default metrics source settings.",
+ "properties": {
+ "cloudwatch": {
+ "description": "CloudWatch configures an Amazon CloudWatch Container Insights metrics source.",
+ "properties": {
+ "clusterName": {
+ "description": "ClusterName is the EKS cluster name for Container Insights metrics.\nRequired for metric filtering.",
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the AWS region (e.g. \"us-east-1\"). Required.",
+ "type": "string"
+ },
+ "roleArn": {
+ "description": "RoleARN is an optional IAM role ARN to assume for cross-account access.\nIf not set, uses the pod's service account IAM role (IRSA/Pod Identity).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "clusterName",
+ "region"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpuRecordingMetric": {
+ "description": "CPURecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of rate(container_cpu_usage_seconds_total). Labels must include\nnamespace, pod, and container. When set, the operator does not wrap the\nmetric in rate(). Pair with MemoryRecordingMetric for a recording-rules-only path.",
+ "type": "string"
+ },
+ "datadog": {
+ "description": "Datadog configures a Datadog metrics source.",
+ "properties": {
+ "apiKeySecretRef": {
+ "description": "APIKeySecretRef references a Secret containing the Datadog API key.\nThe Secret must contain an \"api-key\" key and optionally an \"app-key\" key.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "site": {
+ "default": "datadoghq.com",
+ "description": "Site is the Datadog site (e.g. \"datadoghq.com\", \"datadoghq.eu\", \"us5.datadoghq.com\").\nDefaults to \"datadoghq.com\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "apiKeySecretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "historyWindow": {
+ "description": "HistoryWindow is the time window for historical metrics data.\nDefaults to 7d (168h) if not specified.",
+ "type": "string"
+ },
+ "memoryRecordingMetric": {
+ "description": "MemoryRecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of container_memory_working_set_bytes. Same label requirements\nas CPURecordingMetric.",
+ "type": "string"
+ },
+ "minimumDataPoints": {
+ "description": "MinimumDataPoints is the minimum number of data points required\nbefore generating recommendations. Minimum 1, default 48 samples.\nWith the default queryStep of 5m, 48 samples is about 4 hours of data.\nDefaults to 48 if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "podAggregation": {
+ "description": "PodAggregation controls how multi-pod series are reduced in Prometheus\nrange queries for this policy.\n Max (default): max by (container) \u2014 size for the busiest pod; O(containers) series.\n Avg: avg by (container) across pods.\n None: no aggregation (one series per pod; expensive for high replica counts).\nDatadog and CloudWatch already group by container; this field applies to Prometheus.",
+ "enum": [
+ "Max",
+ "Avg",
+ "None"
+ ],
+ "type": "string"
+ },
+ "prometheus": {
+ "description": "Prometheus configures a Prometheus metrics source.",
+ "properties": {
+ "address": {
+ "description": "Address is the URL of the Prometheus-compatible query endpoint.",
+ "type": "string"
+ },
+ "bearerTokenSecret": {
+ "description": "BearerTokenSecret references a Kubernetes Secret containing a bearer\ntoken for authenticating with managed Prometheus services.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Headers are custom HTTP headers added to every query request.\nUse for non-secret tenant or routing headers (e.g. \"X-Scope-OrgID\"\nfor Mimir). Do not put credentials here; use BearerTokenSecret for\nauthentication tokens.",
+ "type": "object"
+ },
+ "queryParameters": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "QueryParameters are appended to every query request URL.\nUse for backend-specific settings such as Thanos deduplication\n(e.g. {\"dedup\": \"true\", \"partial_response\": \"true\"}). Reserved\nquery keys controlled by the operator (`query`, `start`, `end`, `step`,\n`time`, `timeout`) are rejected.",
+ "type": "object"
+ },
+ "tls": {
+ "description": "TLS configures TLS settings for the connection.",
+ "properties": {
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify disables TLS certificate verification.\nUse only for self-signed certificates in development.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "address"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryStep": {
+ "description": "QueryStep is the step interval for Prometheus range queries and ETA\ncalculations. Should match your Prometheus scrape interval for\naccurate time estimates. Minimum 10s, maximum 1h. Default 5m.",
+ "type": "string"
+ },
+ "rateWindow": {
+ "description": "RateWindow is the window used in the PromQL rate() function for CPU\nqueries. Defaults to queryStep if not set. Must be >= 30s and <= historyWindow.\nAdvanced users may set this independently to control CPU rate smoothing\n(e.g. a short rateWindow for responsive tracking with a longer queryStep).",
+ "type": "string"
+ },
+ "vpa": {
+ "description": "VPA configures consumption of existing VerticalPodAutoscaler recommendations.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the VerticalPodAutoscaler object.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the VPA. Defaults to the policy's namespace.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "updateStrategy": {
+ "description": "UpdateStrategy configures default update strategy settings.",
+ "properties": {
+ "autoRevert": {
+ "description": "AutoRevert automatically reverts changes if degradation is detected.\nDefaults to true if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "type": "boolean"
+ },
+ "canary": {
+ "description": "Canary configures canary rollout behavior when Type is Canary.",
+ "properties": {
+ "autoPromote": {
+ "description": "AutoPromote controls whether the operator automatically promotes the\nresize to all pods after the observation period passes without safety\nviolations. When false (default), the user must manually switch the\nmode to Auto to resize the remaining pods.",
+ "type": "boolean"
+ },
+ "observationPeriod": {
+ "description": "ObservationPeriod is how long to observe canary pods before proceeding.",
+ "type": "string"
+ },
+ "percentage": {
+ "description": "Percentage is the percentage of pods to resize first.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "observationPeriod",
+ "percentage"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between successive resize operations.\nDefaults to 1h if not specified.",
+ "type": "string"
+ },
+ "export": {
+ "description": "Export configures how recommendations are exported for external\nconsumption (e.g. GitOps workflows with ArgoCD or Flux).",
+ "properties": {
+ "configMap": {
+ "description": "ConfigMap enables exporting recommendations to ConfigMaps.",
+ "type": "boolean"
+ },
+ "pullRequest": {
+ "description": "PullRequest enables opt-in GitOps PR automation (default off).\nRequires a token Secret and repository identity. Never logs the token.",
+ "properties": {
+ "apiUrl": {
+ "description": "APIURL overrides the API base URL (Enterprise GitHub or self-hosted GitLab).\nDefaults: https://api.github.com or https://gitlab.com/api/v4.",
+ "type": "string"
+ },
+ "baseBranch": {
+ "description": "BaseBranch is the PR target branch. Defaults to \"main\".",
+ "type": "string"
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between PR create/update attempts for this\npolicy. Defaults to 24h.",
+ "type": "string"
+ },
+ "dryRun": {
+ "description": "DryRun logs the intended PR and updates status without calling the\nremote API. Useful for CI and first enablement.",
+ "type": "boolean"
+ },
+ "enabled": {
+ "description": "Enabled turns on PR automation. Default false.",
+ "type": "boolean"
+ },
+ "labels": {
+ "description": "Labels are applied to the pull request when supported by the provider.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum absolute percent change (per container\nresource vs template) required to open or update a PR. Defaults to 10.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "provider": {
+ "description": "Provider is \"github\" or \"gitlab\". Default \"github\".",
+ "enum": [
+ "github",
+ "gitlab"
+ ],
+ "type": "string"
+ },
+ "repository": {
+ "description": "Repository is \"owner/name\" (GitHub) or \"group/project\" (GitLab path).\nRequired when Enabled is true.",
+ "type": "string"
+ },
+ "tokenSecretRef": {
+ "description": "TokenSecretRef references a Secret key holding a PAT / project token.\nGitHub: repo contents + pull requests. GitLab: api scope on the project.\nRequired when Enabled is true.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "includeExplanationsInStatus": {
+ "description": "IncludeExplanationsInStatus controls whether recommendation explanation\nchains are written to status. Set to false on large policies to shrink\nCR size. Default: true.",
+ "type": "boolean"
+ },
+ "initialSizing": {
+ "description": "InitialSizing enables a mutating admission webhook that sets resource\nrequests/limits on new pods at creation time, based on existing\nrecommendations. This eliminates the \"deploy with bad defaults, wait\nfor first reconcile\" gap. Requires the namespace label\nattune.io/initial-sizing=enabled. Defaults to false.",
+ "type": "boolean"
+ },
+ "maxConcurrentResizes": {
+ "default": 1,
+ "description": "MaxConcurrentResizes is the maximum number of pods to resize\nconcurrently within a single reconcile cycle. Default: 1 (serial).",
+ "format": "int32",
+ "maximum": 50,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxStatusRecommendations": {
+ "description": "MaxStatusRecommendations caps how many workload recommendations are\nwritten to status.recommendations. Resizes still use the full in-memory\nset. When the cap is hit, entries with the largest absolute CPU+memory\nrequest change are kept. Default: 100 (operator may override via flag).",
+ "format": "int32",
+ "maximum": 500,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxTotalCpuIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalCPUIncrease is the maximum aggregate CPU increase allowed\nacross all pods in a single reconcile cycle (e.g. \"2000m\", \"4\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxTotalMemoryIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalMemoryIncrease is the maximum aggregate memory increase\nallowed across all pods in a single reconcile cycle (e.g. \"4Gi\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resizeMethod": {
+ "description": "ResizeMethod controls what happens when an in-place resize fails.\n InPlaceOnly (default): skip the pod and retry next cycle.\n InPlaceOrRecreate: fall back to pod eviction if in-place resize\n fails or is marked Infeasible by kubelet. The owning controller\n recreates the pod with updated resources. Evictions respect\n PodDisruptionBudgets and never evict the last replica.\nDefaults to InPlaceOnly if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "InPlaceOnly",
+ "InPlaceOrRecreate"
+ ],
+ "type": "string"
+ },
+ "safetyObservationPeriod": {
+ "description": "SafetyObservationPeriod is how long to observe a pod after resize before\nconcluding the resize is safe. Applies to all modes (Auto, OneShot, Canary).\nTakes precedence over canary.observationPeriod when set. Must be >= 1m.\nDefaults to 5m if neither this nor canary.observationPeriod is set.",
+ "type": "string"
+ },
+ "schedule": {
+ "description": "Schedule restricts when resize operations can occur. Recommendations\nare always computed; only resize execution is gated. If omitted,\nresizes can occur at any time (current behavior).",
+ "properties": {
+ "daysOfWeek": {
+ "description": "DaysOfWeek restricts resizes to specific days. Values: Monday through Sunday.\nIf omitted, all days are allowed.",
+ "items": {
+ "enum": [
+ "Monday",
+ "Tuesday",
+ "Wednesday",
+ "Thursday",
+ "Friday",
+ "Saturday",
+ "Sunday"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "timezone": {
+ "default": "UTC",
+ "description": "Timezone for interpreting window start/end times. Must be a valid\nIANA timezone name (e.g. \"America/New_York\"). Default: \"UTC\".",
+ "type": "string"
+ },
+ "windows": {
+ "description": "Windows defines time-of-day ranges when resizes are allowed.\nIf multiple windows are specified, resizes are allowed during any of them.",
+ "items": {
+ "description": "TimeWindow defines a daily time range.",
+ "properties": {
+ "end": {
+ "description": "End time in HH:MM format (24-hour). If end < start, the window\nwraps past midnight (e.g. start=22:00, end=06:00).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ },
+ "start": {
+ "description": "Start time in HH:MM format (24-hour).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sloGuardrails": {
+ "description": "SLOGuardrails defines application-level SLO metrics to check after\na resize. If any metric breaches its threshold during the safety\nobservation period, the resize is automatically reverted.\nRequires a Prometheus-compatible metrics source.",
+ "items": {
+ "description": "SLOGuardrail defines an application-level metric that is checked after\na resize to detect degradation. If the metric breaches the threshold,\nthe safety monitor triggers an automatic revert.",
+ "properties": {
+ "comparison": {
+ "default": "above",
+ "description": "Comparison is \"above\" or \"below\". \"above\" reverts when value > threshold.",
+ "enum": [
+ "above",
+ "below"
+ ],
+ "type": "string"
+ },
+ "evaluationWindow": {
+ "description": "EvaluationWindow is how long after resize to check. Defaults to 5m.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name identifies this guardrail for logging and status reporting.",
+ "type": "string"
+ },
+ "query": {
+ "description": "Query is a PromQL query that returns a scalar value.\nTemplate variables: {{ .Namespace }}, {{ .WorkloadName }}, {{ .PodName }}",
+ "type": "string"
+ },
+ "threshold": {
+ "description": "Threshold is the value that triggers a revert.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "query",
+ "threshold"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "templatePersistence": {
+ "description": "TemplatePersistence optionally writes recommended resources into the\nworkload pod template (Deployment/StatefulSet) so new pods start\ncorrectly sized. Default off. Do not enable under unmanaged GitOps\nsync without adopting recommendations in Git; prefer export or\ninitialSizing in that case.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled turns on template persistence. When false or unset, templates\nare never mutated.",
+ "type": "boolean"
+ },
+ "when": {
+ "description": "When selects the trigger. Defaults to AfterSuccessfulResize when\nEnabled is true and When is empty.",
+ "enum": [
+ "AfterSuccessfulResize",
+ "OnRecommendation"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Mode determines the update behavior, graduated from safe to automated:\n Recommend: collects metrics and writes recommendations to status, no pod changes.\n OneShot: resizes one pod per reconcile cycle.\n Canary: resizes a percentage of pods first, then the rest after observation.\n Auto: resizes all eligible pods each cycle.\n Observe: collects metrics and tracks data points but does not surface recommendations or savings.\nStart with Recommend in production and promote after reviewing status.\nDefaults to Recommend if not set (applied by the controller, not the webhook,\nso that AttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "Observe",
+ "Recommend",
+ "OneShot",
+ "Canary",
+ "Auto"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/attunenamespacedefaults-stable-v1alpha1.json b/crdSchemas/master-standalone/attunenamespacedefaults-stable-v1alpha1.json
new file mode 100644
index 0000000..d0cb517
--- /dev/null
+++ b/crdSchemas/master-standalone/attunenamespacedefaults-stable-v1alpha1.json
@@ -0,0 +1,763 @@
+{
+ "description": "AttuneNamespaceDefaults is the Schema for namespace-scoped defaults.\nValues here override cluster-scoped AttuneDefaults but are overridden\nby per-policy values. Precedence: policy > namespace defaults > cluster defaults.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "AttuneDefaultsSpec defines cluster-scoped default values for AttunePolicy resources.",
+ "properties": {
+ "costPricing": {
+ "description": "CostPricing configures the per-unit pricing used to compute\nEstimatedMonthlySavings. If omitted, defaults to standard\non-demand Linux pricing ($0.031/vCPU-hour, $0.004/GiB-hour).",
+ "properties": {
+ "cpuPerCoreHour": {
+ "description": "CPUPerCoreHour is the cost per vCPU-hour (e.g. \"0.031\").\nDefaults to 0.031 if not specified.",
+ "type": "string"
+ },
+ "memoryPerGiBHour": {
+ "description": "MemoryPerGiBHour is the cost per GiB-hour (e.g. \"0.004\").\nDefaults to 0.004 if not specified.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpu": {
+ "description": "CPU configures default CPU resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "excludeKnownSidecars": {
+ "description": "ExcludeKnownSidecars, when true (the default when unset on both\ndefaults and policy), automatically skips well-known mesh and\nsidecar container names. Set to false cluster-wide to restore\nexclude-only-via-excludedContainers behavior for policies that\ndo not set the field themselves.",
+ "type": "boolean"
+ },
+ "memory": {
+ "description": "Memory configures default memory resource recommendation parameters.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metricsSource": {
+ "description": "MetricsSource configures default metrics source settings.",
+ "properties": {
+ "cloudwatch": {
+ "description": "CloudWatch configures an Amazon CloudWatch Container Insights metrics source.",
+ "properties": {
+ "clusterName": {
+ "description": "ClusterName is the EKS cluster name for Container Insights metrics.\nRequired for metric filtering.",
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the AWS region (e.g. \"us-east-1\"). Required.",
+ "type": "string"
+ },
+ "roleArn": {
+ "description": "RoleARN is an optional IAM role ARN to assume for cross-account access.\nIf not set, uses the pod's service account IAM role (IRSA/Pod Identity).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "clusterName",
+ "region"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpuRecordingMetric": {
+ "description": "CPURecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of rate(container_cpu_usage_seconds_total). Labels must include\nnamespace, pod, and container. When set, the operator does not wrap the\nmetric in rate(). Pair with MemoryRecordingMetric for a recording-rules-only path.",
+ "type": "string"
+ },
+ "datadog": {
+ "description": "Datadog configures a Datadog metrics source.",
+ "properties": {
+ "apiKeySecretRef": {
+ "description": "APIKeySecretRef references a Secret containing the Datadog API key.\nThe Secret must contain an \"api-key\" key and optionally an \"app-key\" key.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "site": {
+ "default": "datadoghq.com",
+ "description": "Site is the Datadog site (e.g. \"datadoghq.com\", \"datadoghq.eu\", \"us5.datadoghq.com\").\nDefaults to \"datadoghq.com\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "apiKeySecretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "historyWindow": {
+ "description": "HistoryWindow is the time window for historical metrics data.\nDefaults to 7d (168h) if not specified.",
+ "type": "string"
+ },
+ "memoryRecordingMetric": {
+ "description": "MemoryRecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of container_memory_working_set_bytes. Same label requirements\nas CPURecordingMetric.",
+ "type": "string"
+ },
+ "minimumDataPoints": {
+ "description": "MinimumDataPoints is the minimum number of data points required\nbefore generating recommendations. Minimum 1, default 48 samples.\nWith the default queryStep of 5m, 48 samples is about 4 hours of data.\nDefaults to 48 if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "podAggregation": {
+ "description": "PodAggregation controls how multi-pod series are reduced in Prometheus\nrange queries for this policy.\n Max (default): max by (container) \u2014 size for the busiest pod; O(containers) series.\n Avg: avg by (container) across pods.\n None: no aggregation (one series per pod; expensive for high replica counts).\nDatadog and CloudWatch already group by container; this field applies to Prometheus.",
+ "enum": [
+ "Max",
+ "Avg",
+ "None"
+ ],
+ "type": "string"
+ },
+ "prometheus": {
+ "description": "Prometheus configures a Prometheus metrics source.",
+ "properties": {
+ "address": {
+ "description": "Address is the URL of the Prometheus-compatible query endpoint.",
+ "type": "string"
+ },
+ "bearerTokenSecret": {
+ "description": "BearerTokenSecret references a Kubernetes Secret containing a bearer\ntoken for authenticating with managed Prometheus services.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Headers are custom HTTP headers added to every query request.\nUse for non-secret tenant or routing headers (e.g. \"X-Scope-OrgID\"\nfor Mimir). Do not put credentials here; use BearerTokenSecret for\nauthentication tokens.",
+ "type": "object"
+ },
+ "queryParameters": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "QueryParameters are appended to every query request URL.\nUse for backend-specific settings such as Thanos deduplication\n(e.g. {\"dedup\": \"true\", \"partial_response\": \"true\"}). Reserved\nquery keys controlled by the operator (`query`, `start`, `end`, `step`,\n`time`, `timeout`) are rejected.",
+ "type": "object"
+ },
+ "tls": {
+ "description": "TLS configures TLS settings for the connection.",
+ "properties": {
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify disables TLS certificate verification.\nUse only for self-signed certificates in development.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "address"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryStep": {
+ "description": "QueryStep is the step interval for Prometheus range queries and ETA\ncalculations. Should match your Prometheus scrape interval for\naccurate time estimates. Minimum 10s, maximum 1h. Default 5m.",
+ "type": "string"
+ },
+ "rateWindow": {
+ "description": "RateWindow is the window used in the PromQL rate() function for CPU\nqueries. Defaults to queryStep if not set. Must be >= 30s and <= historyWindow.\nAdvanced users may set this independently to control CPU rate smoothing\n(e.g. a short rateWindow for responsive tracking with a longer queryStep).",
+ "type": "string"
+ },
+ "vpa": {
+ "description": "VPA configures consumption of existing VerticalPodAutoscaler recommendations.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the VerticalPodAutoscaler object.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the VPA. Defaults to the policy's namespace.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "updateStrategy": {
+ "description": "UpdateStrategy configures default update strategy settings.",
+ "properties": {
+ "autoRevert": {
+ "description": "AutoRevert automatically reverts changes if degradation is detected.\nDefaults to true if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "type": "boolean"
+ },
+ "canary": {
+ "description": "Canary configures canary rollout behavior when Type is Canary.",
+ "properties": {
+ "autoPromote": {
+ "description": "AutoPromote controls whether the operator automatically promotes the\nresize to all pods after the observation period passes without safety\nviolations. When false (default), the user must manually switch the\nmode to Auto to resize the remaining pods.",
+ "type": "boolean"
+ },
+ "observationPeriod": {
+ "description": "ObservationPeriod is how long to observe canary pods before proceeding.",
+ "type": "string"
+ },
+ "percentage": {
+ "description": "Percentage is the percentage of pods to resize first.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "observationPeriod",
+ "percentage"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between successive resize operations.\nDefaults to 1h if not specified.",
+ "type": "string"
+ },
+ "export": {
+ "description": "Export configures how recommendations are exported for external\nconsumption (e.g. GitOps workflows with ArgoCD or Flux).",
+ "properties": {
+ "configMap": {
+ "description": "ConfigMap enables exporting recommendations to ConfigMaps.",
+ "type": "boolean"
+ },
+ "pullRequest": {
+ "description": "PullRequest enables opt-in GitOps PR automation (default off).\nRequires a token Secret and repository identity. Never logs the token.",
+ "properties": {
+ "apiUrl": {
+ "description": "APIURL overrides the API base URL (Enterprise GitHub or self-hosted GitLab).\nDefaults: https://api.github.com or https://gitlab.com/api/v4.",
+ "type": "string"
+ },
+ "baseBranch": {
+ "description": "BaseBranch is the PR target branch. Defaults to \"main\".",
+ "type": "string"
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between PR create/update attempts for this\npolicy. Defaults to 24h.",
+ "type": "string"
+ },
+ "dryRun": {
+ "description": "DryRun logs the intended PR and updates status without calling the\nremote API. Useful for CI and first enablement.",
+ "type": "boolean"
+ },
+ "enabled": {
+ "description": "Enabled turns on PR automation. Default false.",
+ "type": "boolean"
+ },
+ "labels": {
+ "description": "Labels are applied to the pull request when supported by the provider.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum absolute percent change (per container\nresource vs template) required to open or update a PR. Defaults to 10.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "provider": {
+ "description": "Provider is \"github\" or \"gitlab\". Default \"github\".",
+ "enum": [
+ "github",
+ "gitlab"
+ ],
+ "type": "string"
+ },
+ "repository": {
+ "description": "Repository is \"owner/name\" (GitHub) or \"group/project\" (GitLab path).\nRequired when Enabled is true.",
+ "type": "string"
+ },
+ "tokenSecretRef": {
+ "description": "TokenSecretRef references a Secret key holding a PAT / project token.\nGitHub: repo contents + pull requests. GitLab: api scope on the project.\nRequired when Enabled is true.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "includeExplanationsInStatus": {
+ "description": "IncludeExplanationsInStatus controls whether recommendation explanation\nchains are written to status. Set to false on large policies to shrink\nCR size. Default: true.",
+ "type": "boolean"
+ },
+ "initialSizing": {
+ "description": "InitialSizing enables a mutating admission webhook that sets resource\nrequests/limits on new pods at creation time, based on existing\nrecommendations. This eliminates the \"deploy with bad defaults, wait\nfor first reconcile\" gap. Requires the namespace label\nattune.io/initial-sizing=enabled. Defaults to false.",
+ "type": "boolean"
+ },
+ "maxConcurrentResizes": {
+ "default": 1,
+ "description": "MaxConcurrentResizes is the maximum number of pods to resize\nconcurrently within a single reconcile cycle. Default: 1 (serial).",
+ "format": "int32",
+ "maximum": 50,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxStatusRecommendations": {
+ "description": "MaxStatusRecommendations caps how many workload recommendations are\nwritten to status.recommendations. Resizes still use the full in-memory\nset. When the cap is hit, entries with the largest absolute CPU+memory\nrequest change are kept. Default: 100 (operator may override via flag).",
+ "format": "int32",
+ "maximum": 500,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxTotalCpuIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalCPUIncrease is the maximum aggregate CPU increase allowed\nacross all pods in a single reconcile cycle (e.g. \"2000m\", \"4\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxTotalMemoryIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalMemoryIncrease is the maximum aggregate memory increase\nallowed across all pods in a single reconcile cycle (e.g. \"4Gi\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resizeMethod": {
+ "description": "ResizeMethod controls what happens when an in-place resize fails.\n InPlaceOnly (default): skip the pod and retry next cycle.\n InPlaceOrRecreate: fall back to pod eviction if in-place resize\n fails or is marked Infeasible by kubelet. The owning controller\n recreates the pod with updated resources. Evictions respect\n PodDisruptionBudgets and never evict the last replica.\nDefaults to InPlaceOnly if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "InPlaceOnly",
+ "InPlaceOrRecreate"
+ ],
+ "type": "string"
+ },
+ "safetyObservationPeriod": {
+ "description": "SafetyObservationPeriod is how long to observe a pod after resize before\nconcluding the resize is safe. Applies to all modes (Auto, OneShot, Canary).\nTakes precedence over canary.observationPeriod when set. Must be >= 1m.\nDefaults to 5m if neither this nor canary.observationPeriod is set.",
+ "type": "string"
+ },
+ "schedule": {
+ "description": "Schedule restricts when resize operations can occur. Recommendations\nare always computed; only resize execution is gated. If omitted,\nresizes can occur at any time (current behavior).",
+ "properties": {
+ "daysOfWeek": {
+ "description": "DaysOfWeek restricts resizes to specific days. Values: Monday through Sunday.\nIf omitted, all days are allowed.",
+ "items": {
+ "enum": [
+ "Monday",
+ "Tuesday",
+ "Wednesday",
+ "Thursday",
+ "Friday",
+ "Saturday",
+ "Sunday"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "timezone": {
+ "default": "UTC",
+ "description": "Timezone for interpreting window start/end times. Must be a valid\nIANA timezone name (e.g. \"America/New_York\"). Default: \"UTC\".",
+ "type": "string"
+ },
+ "windows": {
+ "description": "Windows defines time-of-day ranges when resizes are allowed.\nIf multiple windows are specified, resizes are allowed during any of them.",
+ "items": {
+ "description": "TimeWindow defines a daily time range.",
+ "properties": {
+ "end": {
+ "description": "End time in HH:MM format (24-hour). If end < start, the window\nwraps past midnight (e.g. start=22:00, end=06:00).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ },
+ "start": {
+ "description": "Start time in HH:MM format (24-hour).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sloGuardrails": {
+ "description": "SLOGuardrails defines application-level SLO metrics to check after\na resize. If any metric breaches its threshold during the safety\nobservation period, the resize is automatically reverted.\nRequires a Prometheus-compatible metrics source.",
+ "items": {
+ "description": "SLOGuardrail defines an application-level metric that is checked after\na resize to detect degradation. If the metric breaches the threshold,\nthe safety monitor triggers an automatic revert.",
+ "properties": {
+ "comparison": {
+ "default": "above",
+ "description": "Comparison is \"above\" or \"below\". \"above\" reverts when value > threshold.",
+ "enum": [
+ "above",
+ "below"
+ ],
+ "type": "string"
+ },
+ "evaluationWindow": {
+ "description": "EvaluationWindow is how long after resize to check. Defaults to 5m.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name identifies this guardrail for logging and status reporting.",
+ "type": "string"
+ },
+ "query": {
+ "description": "Query is a PromQL query that returns a scalar value.\nTemplate variables: {{ .Namespace }}, {{ .WorkloadName }}, {{ .PodName }}",
+ "type": "string"
+ },
+ "threshold": {
+ "description": "Threshold is the value that triggers a revert.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "query",
+ "threshold"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "templatePersistence": {
+ "description": "TemplatePersistence optionally writes recommended resources into the\nworkload pod template (Deployment/StatefulSet) so new pods start\ncorrectly sized. Default off. Do not enable under unmanaged GitOps\nsync without adopting recommendations in Git; prefer export or\ninitialSizing in that case.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled turns on template persistence. When false or unset, templates\nare never mutated.",
+ "type": "boolean"
+ },
+ "when": {
+ "description": "When selects the trigger. Defaults to AfterSuccessfulResize when\nEnabled is true and When is empty.",
+ "enum": [
+ "AfterSuccessfulResize",
+ "OnRecommendation"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Mode determines the update behavior, graduated from safe to automated:\n Recommend: collects metrics and writes recommendations to status, no pod changes.\n OneShot: resizes one pod per reconcile cycle.\n Canary: resizes a percentage of pods first, then the rest after observation.\n Auto: resizes all eligible pods each cycle.\n Observe: collects metrics and tracks data points but does not surface recommendations or savings.\nStart with Recommend in production and promote after reviewing status.\nDefaults to Recommend if not set (applied by the controller, not the webhook,\nso that AttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "Observe",
+ "Recommend",
+ "OneShot",
+ "Canary",
+ "Auto"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/attunepolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/attunepolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..64820d0
--- /dev/null
+++ b/crdSchemas/master-standalone/attunepolicy-stable-v1alpha1.json
@@ -0,0 +1,1759 @@
+{
+ "description": "AttunePolicy is the Schema for the attunepolicies API.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "AttunePolicySpec defines the desired state of AttunePolicy.",
+ "properties": {
+ "cpu": {
+ "description": "CPU configures CPU resource recommendations.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "excludeKnownSidecars": {
+ "description": "ExcludeKnownSidecars, when true (the default), automatically skips\nwell-known mesh and sidecar container names (for example istio-proxy,\nlinkerd-proxy) in addition to ExcludedContainers. Set to false to\nrestore pre-feature behavior where only ExcludedContainers is used.",
+ "type": "boolean"
+ },
+ "excludedContainers": {
+ "description": "ExcludedContainers is a list of container names to skip when computing\nrecommendations and performing resizes. Use this for custom sidecars\nor agents. When ExcludeKnownSidecars is true (the default), this list\nis unioned with the built-in known-sidecar names (istio-proxy, etc.).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 100,
+ "type": "array"
+ },
+ "memory": {
+ "description": "Memory configures memory resource recommendations.",
+ "properties": {
+ "allowDecrease": {
+ "description": "AllowDecrease controls whether the resource value can be decreased.\nFor CPU: nil defaults to true (decreases allowed, throttle detected by safety monitor).\nFor memory: nil defaults to false (decreases blocked to prevent OOMKill).",
+ "type": "boolean"
+ },
+ "burstSensitivity": {
+ "description": "BurstSensitivity controls how much burst detection inflates the\nrecommendation. Expressed as a decimal string multiplied by\nlog2(burstMagnitude). Default \"0.1\" gives ~20% boost for magnitude 4,\n~30% for 8, ~40% for 16. Set \"0\" to disable burst boost entirely\n(e.g. for batch jobs). Must be >= 0, max 1.0.",
+ "type": "string"
+ },
+ "controlledValues": {
+ "description": "ControlledValues specifies which resource values to manage.\n\"RequestsOnly\" (default) adjusts only requests, leaving limits unchanged.\n\"RequestsAndLimits\" adjusts both requests and limits in lockstep.\nFor Guaranteed-QoS pods (where requests equal limits), use\n\"RequestsAndLimits\" or resizes will be skipped to preserve QoS class.",
+ "enum": [
+ "RequestsOnly",
+ "RequestsAndLimits"
+ ],
+ "type": "string"
+ },
+ "decreaseUsageMarginPercent": {
+ "description": "DecreaseUsageMarginPercent is the minimum headroom above recent memory\nusage required when decreasing memory limits (client-side pre-check).\nThe target limit must be at least usage * (1 + margin/100). Defaults to\n10. Only applied on the memory ResourceConfig when a limit decrease is\nattempted; ignored for CPU. Set 0 to require limit strictly above usage.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxAllowed is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change percentage per\nreconcile cycle for this resource (both directions). Limits how\naggressively the recommendation can deviate from the current value\nin a single step, forcing gradual convergence. Overridden by\nMaxIncreasePercent/MaxDecreasePercent if those are set.\nDefaults to 50 for CPU, 30 for memory.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxDecreasePercent": {
+ "description": "MaxDecreasePercent is the maximum allowed decrease percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for downward\nchanges. Memory decreases are riskier (OOM), so a lower cap is\nrecommended. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxIncreasePercent": {
+ "description": "MaxIncreasePercent is the maximum allowed increase percentage per\nreconcile cycle. Takes precedence over MaxChangePercent for upward\nchanges. Defaults to MaxChangePercent if not set.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "memoryFromCpuRatio": {
+ "description": "MemoryFromCPURatio derives memory recommendations from CPU recommendations\nusing a fixed ratio, instead of using Prometheus memory metrics. Useful for\nJVM, Go, and .NET workloads where heap scales linearly with CPU allocation\nand Prometheus memory metrics are unreliable (JVM reserves heap upfront,\nGo GC targets a fixed percentage of available memory).\nExample: \"2.0\" means memory = 2x the CPU recommendation in bytes\n(e.g., 500m CPU -> 1Gi memory). The derived value still passes through\nminAllowed, maxAllowed, and maxChangePercent bounds.\nOnly valid on the memory ResourceConfig; ignored on CPU.",
+ "type": "string"
+ },
+ "minAllowed": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAllowed is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "overhead": {
+ "description": "Overhead is the percentage of additional resources added on top of the\npercentile recommendation. Expressed as a string (e.g. \"20\" means 20%\nextra headroom above the target percentile). Must be >= 0, max 900.\nDefaults to \"20\" for CPU and \"30\" for memory.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?)?$",
+ "type": "string"
+ },
+ "percentile": {
+ "description": "Percentile is the usage percentile to target for recommendations.\nSupported values: 50, 90, 95, 99. Omit or set to 0 to use the default\n(95 for CPU, 99 for memory).",
+ "enum": [
+ 0,
+ 50,
+ 90,
+ 95,
+ 99
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "startupBoost": {
+ "description": "StartupBoost temporarily increases CPU requests for newly created or\nrestarted pods to accelerate JVM/.NET class loading, JIT compilation,\nand cache warming. After the duration expires (or the container reaches\nReady), the CPU is reduced to the steady-state recommendation.\nOnly applies to CPU resources.",
+ "properties": {
+ "duration": {
+ "description": "Duration is the maximum time the boost remains active after pod\ncreation or container restart. The boost is removed when the\ncontainer reaches Ready or this duration expires, whichever comes first.\nMust be >= 10s and <= 1h.",
+ "type": "string"
+ },
+ "multiplier": {
+ "description": "Multiplier scales the recommended CPU request during startup.\nFor example, \"3.0\" means 3x the steady-state recommendation.\nMust be > 1.0 and <= 10.0.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "duration",
+ "multiplier"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metricsSource": {
+ "description": "MetricsSource configures where and how to collect metrics.",
+ "properties": {
+ "cloudwatch": {
+ "description": "CloudWatch configures an Amazon CloudWatch Container Insights metrics source.",
+ "properties": {
+ "clusterName": {
+ "description": "ClusterName is the EKS cluster name for Container Insights metrics.\nRequired for metric filtering.",
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the AWS region (e.g. \"us-east-1\"). Required.",
+ "type": "string"
+ },
+ "roleArn": {
+ "description": "RoleARN is an optional IAM role ARN to assume for cross-account access.\nIf not set, uses the pod's service account IAM role (IRSA/Pod Identity).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "clusterName",
+ "region"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cpuRecordingMetric": {
+ "description": "CPURecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of rate(container_cpu_usage_seconds_total). Labels must include\nnamespace, pod, and container. When set, the operator does not wrap the\nmetric in rate(). Pair with MemoryRecordingMetric for a recording-rules-only path.",
+ "type": "string"
+ },
+ "datadog": {
+ "description": "Datadog configures a Datadog metrics source.",
+ "properties": {
+ "apiKeySecretRef": {
+ "description": "APIKeySecretRef references a Secret containing the Datadog API key.\nThe Secret must contain an \"api-key\" key and optionally an \"app-key\" key.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "site": {
+ "default": "datadoghq.com",
+ "description": "Site is the Datadog site (e.g. \"datadoghq.com\", \"datadoghq.eu\", \"us5.datadoghq.com\").\nDefaults to \"datadoghq.com\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "apiKeySecretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "historyWindow": {
+ "description": "HistoryWindow is the time window for historical metrics data.\nDefaults to 7d (168h) if not specified.",
+ "type": "string"
+ },
+ "memoryRecordingMetric": {
+ "description": "MemoryRecordingMetric is an optional pre-aggregated Prometheus metric name\nused instead of container_memory_working_set_bytes. Same label requirements\nas CPURecordingMetric.",
+ "type": "string"
+ },
+ "minimumDataPoints": {
+ "description": "MinimumDataPoints is the minimum number of data points required\nbefore generating recommendations. Minimum 1, default 48 samples.\nWith the default queryStep of 5m, 48 samples is about 4 hours of data.\nDefaults to 48 if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "podAggregation": {
+ "description": "PodAggregation controls how multi-pod series are reduced in Prometheus\nrange queries for this policy.\n Max (default): max by (container) \u2014 size for the busiest pod; O(containers) series.\n Avg: avg by (container) across pods.\n None: no aggregation (one series per pod; expensive for high replica counts).\nDatadog and CloudWatch already group by container; this field applies to Prometheus.",
+ "enum": [
+ "Max",
+ "Avg",
+ "None"
+ ],
+ "type": "string"
+ },
+ "prometheus": {
+ "description": "Prometheus configures a Prometheus metrics source.",
+ "properties": {
+ "address": {
+ "description": "Address is the URL of the Prometheus-compatible query endpoint.",
+ "type": "string"
+ },
+ "bearerTokenSecret": {
+ "description": "BearerTokenSecret references a Kubernetes Secret containing a bearer\ntoken for authenticating with managed Prometheus services.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Headers are custom HTTP headers added to every query request.\nUse for non-secret tenant or routing headers (e.g. \"X-Scope-OrgID\"\nfor Mimir). Do not put credentials here; use BearerTokenSecret for\nauthentication tokens.",
+ "type": "object"
+ },
+ "queryParameters": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "QueryParameters are appended to every query request URL.\nUse for backend-specific settings such as Thanos deduplication\n(e.g. {\"dedup\": \"true\", \"partial_response\": \"true\"}). Reserved\nquery keys controlled by the operator (`query`, `start`, `end`, `step`,\n`time`, `timeout`) are rejected.",
+ "type": "object"
+ },
+ "tls": {
+ "description": "TLS configures TLS settings for the connection.",
+ "properties": {
+ "insecureSkipVerify": {
+ "description": "InsecureSkipVerify disables TLS certificate verification.\nUse only for self-signed certificates in development.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "address"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryStep": {
+ "description": "QueryStep is the step interval for Prometheus range queries and ETA\ncalculations. Should match your Prometheus scrape interval for\naccurate time estimates. Minimum 10s, maximum 1h. Default 5m.",
+ "type": "string"
+ },
+ "rateWindow": {
+ "description": "RateWindow is the window used in the PromQL rate() function for CPU\nqueries. Defaults to queryStep if not set. Must be >= 30s and <= historyWindow.\nAdvanced users may set this independently to control CPU rate smoothing\n(e.g. a short rateWindow for responsive tracking with a longer queryStep).",
+ "type": "string"
+ },
+ "vpa": {
+ "description": "VPA configures consumption of existing VerticalPodAutoscaler recommendations.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the VerticalPodAutoscaler object.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the VPA. Defaults to the policy's namespace.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "paused": {
+ "description": "Paused stops the operator from reconciling this policy. Metrics\ncollection, recommendations, and resizes are all halted. Existing\nresizes are not reverted. Use this during maintenance windows or\nwhen debugging unexpected behavior. The operator sets Ready=False\nwith reason=Paused while this field is true.",
+ "type": "boolean"
+ },
+ "runtimeProfile": {
+ "description": "RuntimeProfile applies language/runtime-oriented defaults for memory\nresize safety. Unset or \"generic\" leaves policy fields unchanged.\nProfiles document recommended resizePolicy and decrease settings;\nthey do not auto-patch pod specs. Supported values: generic, java,\npython, golang, nodejs.",
+ "enum": [
+ "generic",
+ "java",
+ "python",
+ "golang",
+ "nodejs"
+ ],
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef identifies the workload(s) to be attuned.",
+ "properties": {
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Deployment",
+ "StatefulSet",
+ "DaemonSet",
+ "CronJob",
+ "Job",
+ "ReplicaSet"
+ ],
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of a specific target resource.",
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects target resources by labels.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "updateStrategy": {
+ "description": "UpdateStrategy configures how and when to apply resource changes.",
+ "properties": {
+ "autoRevert": {
+ "description": "AutoRevert automatically reverts changes if degradation is detected.\nDefaults to true if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "type": "boolean"
+ },
+ "canary": {
+ "description": "Canary configures canary rollout behavior when Type is Canary.",
+ "properties": {
+ "autoPromote": {
+ "description": "AutoPromote controls whether the operator automatically promotes the\nresize to all pods after the observation period passes without safety\nviolations. When false (default), the user must manually switch the\nmode to Auto to resize the remaining pods.",
+ "type": "boolean"
+ },
+ "observationPeriod": {
+ "description": "ObservationPeriod is how long to observe canary pods before proceeding.",
+ "type": "string"
+ },
+ "percentage": {
+ "description": "Percentage is the percentage of pods to resize first.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "observationPeriod",
+ "percentage"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between successive resize operations.\nDefaults to 1h if not specified.",
+ "type": "string"
+ },
+ "export": {
+ "description": "Export configures how recommendations are exported for external\nconsumption (e.g. GitOps workflows with ArgoCD or Flux).",
+ "properties": {
+ "configMap": {
+ "description": "ConfigMap enables exporting recommendations to ConfigMaps.",
+ "type": "boolean"
+ },
+ "pullRequest": {
+ "description": "PullRequest enables opt-in GitOps PR automation (default off).\nRequires a token Secret and repository identity. Never logs the token.",
+ "properties": {
+ "apiUrl": {
+ "description": "APIURL overrides the API base URL (Enterprise GitHub or self-hosted GitLab).\nDefaults: https://api.github.com or https://gitlab.com/api/v4.",
+ "type": "string"
+ },
+ "baseBranch": {
+ "description": "BaseBranch is the PR target branch. Defaults to \"main\".",
+ "type": "string"
+ },
+ "cooldown": {
+ "description": "Cooldown is the minimum time between PR create/update attempts for this\npolicy. Defaults to 24h.",
+ "type": "string"
+ },
+ "dryRun": {
+ "description": "DryRun logs the intended PR and updates status without calling the\nremote API. Useful for CI and first enablement.",
+ "type": "boolean"
+ },
+ "enabled": {
+ "description": "Enabled turns on PR automation. Default false.",
+ "type": "boolean"
+ },
+ "labels": {
+ "description": "Labels are applied to the pull request when supported by the provider.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum absolute percent change (per container\nresource vs template) required to open or update a PR. Defaults to 10.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "provider": {
+ "description": "Provider is \"github\" or \"gitlab\". Default \"github\".",
+ "enum": [
+ "github",
+ "gitlab"
+ ],
+ "type": "string"
+ },
+ "repository": {
+ "description": "Repository is \"owner/name\" (GitHub) or \"group/project\" (GitLab path).\nRequired when Enabled is true.",
+ "type": "string"
+ },
+ "tokenSecretRef": {
+ "description": "TokenSecretRef references a Secret key holding a PAT / project token.\nGitHub: repo contents + pull requests. GitLab: api scope on the project.\nRequired when Enabled is true.",
+ "properties": {
+ "key": {
+ "description": "Key within the Secret.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the Secret.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "includeExplanationsInStatus": {
+ "description": "IncludeExplanationsInStatus controls whether recommendation explanation\nchains are written to status. Set to false on large policies to shrink\nCR size. Default: true.",
+ "type": "boolean"
+ },
+ "initialSizing": {
+ "description": "InitialSizing enables a mutating admission webhook that sets resource\nrequests/limits on new pods at creation time, based on existing\nrecommendations. This eliminates the \"deploy with bad defaults, wait\nfor first reconcile\" gap. Requires the namespace label\nattune.io/initial-sizing=enabled. Defaults to false.",
+ "type": "boolean"
+ },
+ "maxConcurrentResizes": {
+ "default": 1,
+ "description": "MaxConcurrentResizes is the maximum number of pods to resize\nconcurrently within a single reconcile cycle. Default: 1 (serial).",
+ "format": "int32",
+ "maximum": 50,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxStatusRecommendations": {
+ "description": "MaxStatusRecommendations caps how many workload recommendations are\nwritten to status.recommendations. Resizes still use the full in-memory\nset. When the cap is hit, entries with the largest absolute CPU+memory\nrequest change are kept. Default: 100 (operator may override via flag).",
+ "format": "int32",
+ "maximum": 500,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "maxTotalCpuIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalCPUIncrease is the maximum aggregate CPU increase allowed\nacross all pods in a single reconcile cycle (e.g. \"2000m\", \"4\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxTotalMemoryIncrease": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxTotalMemoryIncrease is the maximum aggregate memory increase\nallowed across all pods in a single reconcile cycle (e.g. \"4Gi\").\nOnce exhausted, remaining pods are deferred to the next cycle.\nDecreases do not consume budget. Default: unlimited.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resizeMethod": {
+ "description": "ResizeMethod controls what happens when an in-place resize fails.\n InPlaceOnly (default): skip the pod and retry next cycle.\n InPlaceOrRecreate: fall back to pod eviction if in-place resize\n fails or is marked Infeasible by kubelet. The owning controller\n recreates the pod with updated resources. Evictions respect\n PodDisruptionBudgets and never evict the last replica.\nDefaults to InPlaceOnly if not set (applied by the controller so that\nAttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "InPlaceOnly",
+ "InPlaceOrRecreate"
+ ],
+ "type": "string"
+ },
+ "safetyObservationPeriod": {
+ "description": "SafetyObservationPeriod is how long to observe a pod after resize before\nconcluding the resize is safe. Applies to all modes (Auto, OneShot, Canary).\nTakes precedence over canary.observationPeriod when set. Must be >= 1m.\nDefaults to 5m if neither this nor canary.observationPeriod is set.",
+ "type": "string"
+ },
+ "schedule": {
+ "description": "Schedule restricts when resize operations can occur. Recommendations\nare always computed; only resize execution is gated. If omitted,\nresizes can occur at any time (current behavior).",
+ "properties": {
+ "daysOfWeek": {
+ "description": "DaysOfWeek restricts resizes to specific days. Values: Monday through Sunday.\nIf omitted, all days are allowed.",
+ "items": {
+ "enum": [
+ "Monday",
+ "Tuesday",
+ "Wednesday",
+ "Thursday",
+ "Friday",
+ "Saturday",
+ "Sunday"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "timezone": {
+ "default": "UTC",
+ "description": "Timezone for interpreting window start/end times. Must be a valid\nIANA timezone name (e.g. \"America/New_York\"). Default: \"UTC\".",
+ "type": "string"
+ },
+ "windows": {
+ "description": "Windows defines time-of-day ranges when resizes are allowed.\nIf multiple windows are specified, resizes are allowed during any of them.",
+ "items": {
+ "description": "TimeWindow defines a daily time range.",
+ "properties": {
+ "end": {
+ "description": "End time in HH:MM format (24-hour). If end < start, the window\nwraps past midnight (e.g. start=22:00, end=06:00).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ },
+ "start": {
+ "description": "Start time in HH:MM format (24-hour).",
+ "pattern": "^([01]\\d|2[0-3]):[0-5]\\d$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sloGuardrails": {
+ "description": "SLOGuardrails defines application-level SLO metrics to check after\na resize. If any metric breaches its threshold during the safety\nobservation period, the resize is automatically reverted.\nRequires a Prometheus-compatible metrics source.",
+ "items": {
+ "description": "SLOGuardrail defines an application-level metric that is checked after\na resize to detect degradation. If the metric breaches the threshold,\nthe safety monitor triggers an automatic revert.",
+ "properties": {
+ "comparison": {
+ "default": "above",
+ "description": "Comparison is \"above\" or \"below\". \"above\" reverts when value > threshold.",
+ "enum": [
+ "above",
+ "below"
+ ],
+ "type": "string"
+ },
+ "evaluationWindow": {
+ "description": "EvaluationWindow is how long after resize to check. Defaults to 5m.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name identifies this guardrail for logging and status reporting.",
+ "type": "string"
+ },
+ "query": {
+ "description": "Query is a PromQL query that returns a scalar value.\nTemplate variables: {{ .Namespace }}, {{ .WorkloadName }}, {{ .PodName }}",
+ "type": "string"
+ },
+ "threshold": {
+ "description": "Threshold is the value that triggers a revert.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "query",
+ "threshold"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "templatePersistence": {
+ "description": "TemplatePersistence optionally writes recommended resources into the\nworkload pod template (Deployment/StatefulSet) so new pods start\ncorrectly sized. Default off. Do not enable under unmanaged GitOps\nsync without adopting recommendations in Git; prefer export or\ninitialSizing in that case.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled turns on template persistence. When false or unset, templates\nare never mutated.",
+ "type": "boolean"
+ },
+ "when": {
+ "description": "When selects the trigger. Defaults to AfterSuccessfulResize when\nEnabled is true and When is empty.",
+ "enum": [
+ "AfterSuccessfulResize",
+ "OnRecommendation"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Mode determines the update behavior, graduated from safe to automated:\n Recommend: collects metrics and writes recommendations to status, no pod changes.\n OneShot: resizes one pod per reconcile cycle.\n Canary: resizes a percentage of pods first, then the rest after observation.\n Auto: resizes all eligible pods each cycle.\n Observe: collects metrics and tracks data points but does not surface recommendations or savings.\nStart with Recommend in production and promote after reviewing status.\nDefaults to Recommend if not set (applied by the controller, not the webhook,\nso that AttuneDefaults cluster configuration can override it).",
+ "enum": [
+ "Observe",
+ "Recommend",
+ "OneShot",
+ "Canary",
+ "Auto"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "default": 100,
+ "description": "Weight determines the priority of this policy when multiple policies\nmatch the same workload. Higher values take precedence.",
+ "format": "int32",
+ "maximum": 1000,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "cpu",
+ "memory",
+ "metricsSource",
+ "targetRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "AttunePolicyStatus defines the observed state of AttunePolicy.",
+ "properties": {
+ "canary": {
+ "description": "Canary tracks the canary rollout phase when autoPromote is enabled.",
+ "properties": {
+ "observedGeneration": {
+ "description": "ObservedGeneration is the policy generation when this canary cycle\nstarted. If the policy spec changes (generation increments), the\ncanary observation resets so the new configuration is re-validated.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "phase": {
+ "description": "Phase indicates the current canary state.\nCanaryInProgress: canary pods resized, observing for safety violations.\nFullRollout: observation passed with no violations, all pods are being resized.",
+ "type": "string"
+ },
+ "pods": {
+ "description": "Pods lists the names of pods selected for the canary subset.\nPopulated when Mode is Canary and pods have been resized.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 100,
+ "type": "array"
+ },
+ "startTime": {
+ "description": "StartTime is when the canary subset was first resized.",
+ "format": "date-time",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions represent the latest available observations of the policy's state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "cooldown": {
+ "description": "Cooldown exposes the effective cooldown including exponential backoff.",
+ "properties": {
+ "backoffMultiplier": {
+ "description": "BackoffMultiplier is the current backoff multiplier (1, 2, 4, 8, or 16).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveReverts": {
+ "description": "ConsecutiveReverts is the number of consecutive reverts driving the backoff.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "effectiveCooldown": {
+ "description": "EffectiveCooldown is the current cooldown duration including backoff.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "lastReconcileTime": {
+ "description": "LastReconcileTime is the timestamp of the most recent reconciliation.\nServes as a heartbeat to confirm the operator is actively evaluating\nthis policy, even when no state changes occur.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "recommendations": {
+ "description": "Recommendations contains per-workload resource recommendations.",
+ "items": {
+ "description": "WorkloadRecommendation contains recommendations for a single workload.",
+ "properties": {
+ "containers": {
+ "description": "Containers contains per-container recommendations.",
+ "items": {
+ "description": "ContainerRecommendation contains recommendations for a single container.",
+ "properties": {
+ "confidence": {
+ "description": "Confidence is the confidence score of the recommendation (0-1).",
+ "type": "number"
+ },
+ "current": {
+ "description": "Current contains the current resource values.",
+ "properties": {
+ "cpuLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPULimit is the CPU limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "cpuRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPURequest is the CPU request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryLimit is the memory limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryRequest is the memory request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "cpuLimit",
+ "cpuRequest",
+ "memoryLimit",
+ "memoryRequest"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dataPoints": {
+ "description": "DataPoints is the number of data points used to generate the recommendation.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "explanation": {
+ "description": "Explanation contains the reasoning chain behind the recommendation.",
+ "properties": {
+ "cpu": {
+ "description": "CPU contains the CPU recommendation reasoning.",
+ "properties": {
+ "afterBounds": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBounds is the value after bounds clamping.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterBurst": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBurst is the value after applying the burst factor.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterChangeFilter": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterChangeFilter is the value after change filtering.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterConfidence": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterConfidence is the value after applying the confidence adjustment.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterOverhead": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterOverhead is the value after applying the overhead.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "bounds": {
+ "description": "Bounds are the configured minimum and maximum limits.",
+ "properties": {
+ "max": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Max is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "min": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Min is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "max",
+ "min"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "boundsApplied": {
+ "description": "BoundsApplied indicates whether the value was clamped to min, max, or neither.",
+ "type": "string"
+ },
+ "burstFactor": {
+ "description": "BurstFactor is the multiplier applied when burst is detected (max > 3x p95).\n1.0 when no burst. Uses logarithmic scaling to avoid excessive inflation.",
+ "type": "number"
+ },
+ "changeFilterApplied": {
+ "description": "ChangeFilterApplied indicates whether the result was filtered or capped.",
+ "type": "string"
+ },
+ "confidence": {
+ "description": "Confidence is the profile confidence score used for adjustment.",
+ "type": "number"
+ },
+ "confidenceFactor": {
+ "description": "ConfidenceFactor is the multiplier derived from the confidence score.",
+ "type": "number"
+ },
+ "final": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Final is the final resource recommendation after any post-processing.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "finalAdjustment": {
+ "description": "FinalAdjustment describes any controller-level adjustment after the estimator chain.",
+ "type": "string"
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change threshold.",
+ "type": "number"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum change threshold required to alter the current value.",
+ "type": "number"
+ },
+ "overhead": {
+ "description": "Overhead is the configured overhead percentage applied to the raw percentile.",
+ "type": "number"
+ },
+ "rawPercentile": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "RawPercentile is the selected percentile before any adjustments.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "afterBounds",
+ "afterChangeFilter",
+ "afterConfidence",
+ "afterOverhead",
+ "bounds",
+ "confidence",
+ "confidenceFactor",
+ "final",
+ "maxChangePercent",
+ "minChangePercent",
+ "overhead",
+ "rawPercentile"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "memory": {
+ "description": "Memory contains the memory recommendation reasoning.",
+ "properties": {
+ "afterBounds": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBounds is the value after bounds clamping.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterBurst": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterBurst is the value after applying the burst factor.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterChangeFilter": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterChangeFilter is the value after change filtering.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterConfidence": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterConfidence is the value after applying the confidence adjustment.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "afterOverhead": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "AfterOverhead is the value after applying the overhead.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "bounds": {
+ "description": "Bounds are the configured minimum and maximum limits.",
+ "properties": {
+ "max": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Max is the maximum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "min": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Min is the minimum allowed resource value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "max",
+ "min"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "boundsApplied": {
+ "description": "BoundsApplied indicates whether the value was clamped to min, max, or neither.",
+ "type": "string"
+ },
+ "burstFactor": {
+ "description": "BurstFactor is the multiplier applied when burst is detected (max > 3x p95).\n1.0 when no burst. Uses logarithmic scaling to avoid excessive inflation.",
+ "type": "number"
+ },
+ "changeFilterApplied": {
+ "description": "ChangeFilterApplied indicates whether the result was filtered or capped.",
+ "type": "string"
+ },
+ "confidence": {
+ "description": "Confidence is the profile confidence score used for adjustment.",
+ "type": "number"
+ },
+ "confidenceFactor": {
+ "description": "ConfidenceFactor is the multiplier derived from the confidence score.",
+ "type": "number"
+ },
+ "final": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Final is the final resource recommendation after any post-processing.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "finalAdjustment": {
+ "description": "FinalAdjustment describes any controller-level adjustment after the estimator chain.",
+ "type": "string"
+ },
+ "maxChangePercent": {
+ "description": "MaxChangePercent is the maximum allowed change threshold.",
+ "type": "number"
+ },
+ "minChangePercent": {
+ "description": "MinChangePercent is the minimum change threshold required to alter the current value.",
+ "type": "number"
+ },
+ "overhead": {
+ "description": "Overhead is the configured overhead percentage applied to the raw percentile.",
+ "type": "number"
+ },
+ "rawPercentile": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "RawPercentile is the selected percentile before any adjustments.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "afterBounds",
+ "afterChangeFilter",
+ "afterConfidence",
+ "afterOverhead",
+ "bounds",
+ "confidence",
+ "confidenceFactor",
+ "final",
+ "maxChangePercent",
+ "minChangePercent",
+ "overhead",
+ "rawPercentile"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "lastUpdated": {
+ "description": "LastUpdated is the timestamp of the last recommendation update.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the container name.",
+ "type": "string"
+ },
+ "recommended": {
+ "description": "Recommended contains the recommended resource values.",
+ "properties": {
+ "cpuLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPULimit is the CPU limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "cpuRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "CPURequest is the CPU request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryLimit is the memory limit value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "memoryRequest": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MemoryRequest is the memory request value.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "cpuLimit",
+ "cpuRequest",
+ "memoryLimit",
+ "memoryRequest"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "confidence",
+ "current",
+ "dataPoints",
+ "lastUpdated",
+ "name",
+ "recommended"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "kind": {
+ "description": "Kind is the kind of the workload (e.g. Deployment, StatefulSet).",
+ "type": "string"
+ },
+ "lastDataTime": {
+ "description": "LastDataTime is the timestamp when Prometheus last returned non-empty\ndata for this workload. Used for staleness detection.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "stale": {
+ "description": "Stale indicates the recommendation is based on cached data because\nPrometheus did not return fresh data during the most recent query.\nResizes are not executed with stale recommendations.",
+ "type": "boolean"
+ },
+ "workload": {
+ "description": "Workload is the name of the workload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "containers",
+ "kind",
+ "workload"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 500,
+ "type": "array"
+ },
+ "resizeHistory": {
+ "description": "ResizeHistory records past resize operations.",
+ "items": {
+ "description": "ResizeHistoryEntry records a single resize operation.",
+ "properties": {
+ "container": {
+ "description": "Container is the name of the resized container.",
+ "type": "string"
+ },
+ "from": {
+ "description": "From is the previous resource value.",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method is the resize method used.",
+ "enum": [
+ "InPlace",
+ "Eviction",
+ "TemplatePersistence"
+ ],
+ "type": "string"
+ },
+ "reason": {
+ "description": "Reason explains why the resize was reverted or failed.\nOnly populated when Result is Reverted or Failed.\nValues include: oomkill, restart, notready, throttle,\nannotation-conflict, immediate-safety-check, slo:,\ninfeasible (kubelet Infeasible / InPlaceOnly skip).",
+ "type": "string"
+ },
+ "resource": {
+ "description": "Resource is the resource type that was resized, or \"template\" when the\nhistory entry records a workload template persistence patch.",
+ "enum": [
+ "cpu",
+ "memory",
+ "cpu+memory",
+ "template"
+ ],
+ "type": "string"
+ },
+ "result": {
+ "description": "Result is the outcome of the resize operation.",
+ "enum": [
+ "Success",
+ "Failed",
+ "Reverted",
+ "Evicted",
+ "TemplatePatched"
+ ],
+ "type": "string"
+ },
+ "timestamp": {
+ "description": "Timestamp is when the resize operation occurred.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "to": {
+ "description": "To is the new resource value.",
+ "type": "string"
+ },
+ "workload": {
+ "description": "Workload is the name of the resized workload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "container",
+ "from",
+ "method",
+ "resource",
+ "result",
+ "timestamp",
+ "to",
+ "workload"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "type": "array"
+ },
+ "savings": {
+ "description": "Savings summarizes estimated resource savings.",
+ "properties": {
+ "cpuRequestIncrease": {
+ "description": "CPURequestIncrease is the total CPU request increase for under-provisioned\nworkloads (e.g. \"500m\"). Empty when all recommendations are decreases.",
+ "type": "string"
+ },
+ "cpuRequestReduction": {
+ "description": "CPURequestReduction is the total CPU request reduction (e.g. \"200m\").",
+ "type": "string"
+ },
+ "cpuRequestTotal": {
+ "description": "CPURequestTotal is the total current CPU requests across all workloads (e.g. \"2000m\").",
+ "type": "string"
+ },
+ "estimatedMonthlyCostIncrease": {
+ "description": "EstimatedMonthlyCostIncrease is the estimated monthly cost increase for\nunder-provisioned workloads based on configured or default pricing (e.g. \"$5.00\").",
+ "type": "string"
+ },
+ "estimatedMonthlySavings": {
+ "description": "EstimatedMonthlySavings is the estimated monthly cost savings based on\nconfigured or default pricing (e.g. \"$12.50\").",
+ "type": "string"
+ },
+ "memoryRequestIncrease": {
+ "description": "MemoryRequestIncrease is the total memory request increase for under-provisioned\nworkloads (e.g. \"512Mi\"). Empty when all recommendations are decreases.",
+ "type": "string"
+ },
+ "memoryRequestReduction": {
+ "description": "MemoryRequestReduction is the total memory request reduction (e.g. \"256Mi\").",
+ "type": "string"
+ },
+ "memoryRequestTotal": {
+ "description": "MemoryRequestTotal is the total current memory requests across all workloads (e.g. \"2Gi\").",
+ "type": "string"
+ },
+ "reclaimedCpuRequest": {
+ "description": "ReclaimedCPURequest is estimated freeable CPU request capacity if recommended\ndecreases were applied (same quantity as cpuRequestReduction). Preferred field\nname for bin-packing and cluster-autoscaler capacity planning.",
+ "type": "string"
+ },
+ "reclaimedMemoryRequest": {
+ "description": "ReclaimedMemoryRequest is estimated freeable memory request capacity if\nrecommended decreases were applied (same quantity as memoryRequestReduction).",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "workloadErrors": {
+ "description": "WorkloadErrors records per-workload errors from the most recent\nreconcile cycle. Capped at 10 entries to limit status size.",
+ "items": {
+ "description": "WorkloadError records an error encountered while processing a specific workload.",
+ "properties": {
+ "error": {
+ "description": "Error is a human-readable description of the error.",
+ "type": "string"
+ },
+ "workload": {
+ "description": "Workload is the name of the affected workload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "error",
+ "workload"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "workloads": {
+ "description": "Workloads summarizes workload discovery and resize counts.",
+ "properties": {
+ "dataPointsCollected": {
+ "description": "DataPointsCollected is the maximum number of data points collected across\nall containers in the discovered workloads.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "dataPointsRequired": {
+ "description": "DataPointsRequired is the minimum number of data points needed before\ngenerating recommendations (from metricsSource.minimumDataPoints).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "deferred": {
+ "description": "Deferred is the number of pods whose in-place resize is Deferred by the\nkubelet (node cannot accept the change yet). Retried automatically when\nthe condition clears on a later reconcile.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "discovered": {
+ "description": "Discovered is the number of workloads matching the target selector.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "infeasible": {
+ "description": "Infeasible is the number of pods whose in-place resize is Infeasible on\nthe current node. With resizeMethod InPlaceOnly these pods are skipped;\nwith InPlaceOrRecreate the operator may fall back to eviction.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "pending": {
+ "description": "Pending is the number of workloads awaiting resize.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "resized": {
+ "description": "Resized is the number of workloads that have been resized.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "withRecommendations": {
+ "description": "WithRecommendations is the number of workloads with active recommendations.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "discovered",
+ "pending",
+ "resized",
+ "withRecommendations"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/backend-stable-v1alpha1.json b/crdSchemas/master-standalone/backend-stable-v1alpha1.json
new file mode 100644
index 0000000..66e4d17
--- /dev/null
+++ b/crdSchemas/master-standalone/backend-stable-v1alpha1.json
@@ -0,0 +1,418 @@
+{
+ "description": "Backend allows the user to configure the endpoints of a backend and\nthe behavior of the connection from Envoy Proxy to the backend.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of Backend.",
+ "properties": {
+ "appProtocols": {
+ "description": "AppProtocols defines the application protocols to be supported when connecting to the backend.",
+ "items": {
+ "description": "AppProtocolType defines various backend applications protocols supported by Envoy Gateway",
+ "enum": [
+ "gateway.envoyproxy.io/h2c",
+ "gateway.envoyproxy.io/ws",
+ "gateway.envoyproxy.io/wss"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "endpoints": {
+ "description": "Endpoints defines the endpoints to be used when connecting to the backend.",
+ "items": {
+ "description": "BackendEndpoint describes a backend endpoint, which can be either a fully-qualified domain name, IP address or unix domain socket\ncorresponding to Envoy's Address: https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/core/v3/address.proto#config-core-v3-address",
+ "properties": {
+ "fqdn": {
+ "description": "FQDN defines a FQDN endpoint",
+ "properties": {
+ "hostname": {
+ "description": "Hostname defines the FQDN hostname of the backend endpoint.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port defines the port of the backend endpoint.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "hostname",
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostname": {
+ "description": "Hostname defines an optional hostname for the backend endpoint.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "ip": {
+ "description": "IP defines an IP endpoint. Supports both IPv4 and IPv6 addresses.",
+ "properties": {
+ "address": {
+ "description": "Address defines the IP address of the backend endpoint.\nSupports both IPv4 and IPv6 addresses.",
+ "maxLength": 45,
+ "minLength": 3,
+ "pattern": "^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$|^(([0-9a-fA-F]{1,4}:){1,7}[0-9a-fA-F]{1,4}|::|(([0-9a-fA-F]{1,4}:){0,5})?(:[0-9a-fA-F]{1,4}){1,2})$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port defines the port of the backend endpoint.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "address",
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "unix": {
+ "description": "Unix defines the unix domain socket endpoint",
+ "properties": {
+ "path": {
+ "description": "Path defines the unix domain socket path of the backend endpoint.\nThe path length must not exceed 108 characters.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "unix domain socket path must not exceed 108 characters",
+ "rule": "size(self) <= 108"
+ }
+ ]
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "zone": {
+ "description": "Zone defines the service zone of the backend endpoint.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "one of fqdn, ip or unix must be specified",
+ "rule": "(has(self.fqdn) || has(self.ip) || has(self.unix))"
+ },
+ {
+ "message": "only one of fqdn, ip or unix can be specified",
+ "rule": "((has(self.fqdn) && !(has(self.ip) || has(self.unix))) || (has(self.ip) && !(has(self.fqdn) || has(self.unix))) || (has(self.unix) && !(has(self.ip) || has(self.fqdn))))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 256,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "fqdn addresses cannot be mixed with other address types",
+ "rule": "self.all(f, has(f.fqdn)) || !self.exists(f, has(f.fqdn))"
+ }
+ ]
+ },
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "tls": {
+ "description": "TLS defines the TLS settings for the backend.\nIf TLS is specified here and a BackendTLSPolicy is also configured for the backend, the final TLS settings will\nbe a merge of both configurations. In case of overlapping fields, the values defined in the BackendTLSPolicy will\ntake precedence.",
+ "properties": {
+ "alpnProtocols": {
+ "description": "ALPNProtocols supplies the list of ALPN protocols that should be\nexposed by the listener or used by the proxy to connect to the backend.\nDefaults:\n1. HTTPS Routes: h2 and http/1.1 are enabled in listener context.\n2. Other Routes: ALPN is disabled.\n3. Backends: proxy uses the appropriate ALPN options for the backend protocol.\nWhen an empty list is provided, the ALPN TLS extension is disabled.\n\nDefaults to [h2, http/1.1] if not specified.\n\nTypical Supported values are:\n- http/1.0\n- http/1.1\n- h2",
+ "items": {
+ "description": "ALPNProtocol specifies the protocol to be negotiated using ALPN",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes objects that\ncontain TLS certificates of the Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the backend.\n\nA single reference to a Kubernetes ConfigMap or a Kubernetes Secret,\nwith the CA certificate in a key named `ca.crt` is currently supported.\n\nIf CACertificateRefs is empty or unspecified, then WellKnownCACertificates must be\nspecified. Only one of CACertificateRefs or WellKnownCACertificates may be specified,\nnot both.",
+ "items": {
+ "description": "LocalObjectReference identifies an API object within the namespace of the\nreferrer.\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "ciphers": {
+ "description": "Ciphers specifies the set of cipher suites supported when\nnegotiating TLS 1.0 - 1.2. This setting has no effect for TLS 1.3.\nFor Envoy TLS cipher suite configuration semantics and default cipher\nlists, see the Envoy documentation:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/transport_sockets/tls/v3/common.proto#extensions-transport-sockets-tls-v3-tlsparameters\nSupported cipher suite names:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\n- ECDHE-ECDSA-CHACHA20-POLY1305\n- ECDHE-RSA-CHACHA20-POLY1305\n- ECDHE-ECDSA-AES128-SHA\n- ECDHE-RSA-AES128-SHA\n- AES128-GCM-SHA256\n- AES128-SHA\n- ECDHE-ECDSA-AES256-SHA\n- ECDHE-RSA-AES256-SHA\n- AES256-GCM-SHA384\n- AES256-SHA\nSupported IANA/RFC aliases:\n- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\n- TLS_RSA_WITH_AES_128_GCM_SHA256\n- TLS_RSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\n- TLS_RSA_WITH_AES_256_GCM_SHA384\n- TLS_RSA_WITH_AES_256_CBC_SHA\nIn non-FIPS Envoy Proxy builds the default cipher list is:\n- [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]\n- [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\nIn builds using BoringSSL FIPS the default cipher list is:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef defines the reference to a Kubernetes Secret that contains\nthe client certificate and private key for Envoy to use when connecting to\nbackend services and external services, such as ExtAuth, ALS, OpenTelemetry, etc.\nThis secret should be located within the same namespace as the Envoy proxy resource that references it.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ecdhCurves": {
+ "description": "ECDHCurves specifies the set of supported ECDH curves.\nIn non-FIPS Envoy Proxy builds the default curves are:\n- X25519\n- P-256\nIn builds using BoringSSL FIPS the default curve is:\n- P-256",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "fingerprints": {
+ "description": "Fingerprints specifies TLS client fingerprinting.\nWhen specified, a JAX fingerprint derived from the client\u2019s TLS handshake\nis generated. The fingerprint can be logged in access logs or\nforwarded to upstream services using request headers.\n\nFingerprinting is disabled if not specified.\n\nSupported values are:\n- JA3\n- JA4",
+ "items": {
+ "description": "TLSFingerprintType specifies the TLS client fingerprinting mode.",
+ "enum": [
+ "JA3",
+ "JA4"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "insecureSkipVerify": {
+ "default": false,
+ "description": "InsecureSkipVerify indicates whether the upstream's certificate verification\nshould be skipped. Defaults to \"false\".",
+ "type": "boolean"
+ },
+ "maxVersion": {
+ "description": "Max specifies the maximal TLS protocol version to allow\nThe default is TLS 1.3 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "minVersion": {
+ "description": "Min specifies the minimal TLS protocol version to allow.\nThe default is TLS 1.2 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "signatureAlgorithms": {
+ "description": "SignatureAlgorithms specifies which signature algorithms the listener should\nsupport.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "sni": {
+ "description": "SNI is specifies the SNI value used when establishing an upstream TLS connection to the backend.\n\nEnvoy Gateway will use the HTTP host header value for SNI, when all resources referenced in BackendRefs are:\n1. Backend resources that do not set SNI, or\n2. Service/ServiceImport resources that do not have a BackendTLSPolicy attached to them\n\nWhen a BackendTLSPolicy attaches to a Backend resource, the BackendTLSPolicy's Hostname value takes precedence\nover this value.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "wellKnownCACertificates": {
+ "description": "WellKnownCACertificates specifies whether system CA certificates may be used in\nthe TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(System|([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]))$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "must not contain both CACertificateRefs and WellKnownCACertificates",
+ "rule": "!(has(self.caCertificateRefs) && size(self.caCertificateRefs) > 0 && has(self.wellKnownCACertificates) && self.wellKnownCACertificates != \"\")"
+ },
+ {
+ "message": "must not contain either CACertificateRefs or WellKnownCACertificates when InsecureSkipVerify is enabled",
+ "rule": "!((has(self.insecureSkipVerify) && self.insecureSkipVerify) && ((has(self.caCertificateRefs) && size(self.caCertificateRefs) > 0) || (has(self.wellKnownCACertificates) && self.wellKnownCACertificates != \"\")))"
+ },
+ {
+ "message": "setting ciphers has no effect if the minimum possible TLS version is 1.3",
+ "rule": "has(self.minVersion) && self.minVersion == '1.3' ? !has(self.ciphers) : true"
+ },
+ {
+ "message": "minVersion must be smaller or equal to maxVersion",
+ "rule": "has(self.minVersion) && has(self.maxVersion) ? {\"Auto\":0,\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4}[self.minVersion] <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : !has(self.minVersion) && has(self.maxVersion) ? 3 <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Endpoints",
+ "description": "Type defines the type of the backend. Defaults to \"Endpoints\"",
+ "enum": [
+ "Endpoints",
+ "DynamicResolver"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "DynamicResolver type cannot have endpoints specified",
+ "rule": "self.type != 'DynamicResolver' || !has(self.endpoints)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of Backend.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describe the current conditions of the Backend.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/backendtlspolicy-stable-v1.json b/crdSchemas/master-standalone/backendtlspolicy-stable-v1.json
index b310b7f..8ba29db 100644
--- a/crdSchemas/master-standalone/backendtlspolicy-stable-v1.json
+++ b/crdSchemas/master-standalone/backendtlspolicy-stable-v1.json
@@ -27,7 +27,7 @@
"type": "object"
},
"targetRefs": {
- "description": "TargetRefs identifies an API object to apply the policy to.\nOnly Services have Extended support. Implementations MAY support\nadditional objects, with Implementation Specific support.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {name}.\n For example, a policy named `bar` is given precedence over a\n policy named `baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nSupport: Extended for Kubernetes Service\n\nSupport: Implementation-specific for any other resource",
+ "description": "TargetRefs identifies an API object to apply the policy to.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {namespace}/{name}.\n For example, a policy named `foo/bar` is given precedence over a\n policy named `foo/baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nImplementations SHOULD NOT support more than one targetRef at this\ntime. Although the API technically allows for this, the current guidance\nfor conflict resolution and status handling is lacking. Until that can be\nclarified in a future release, the safest approach is to support a single\ntargetRef.\n\nSupport Levels:\n\n* Extended: Kubernetes Service referenced by HTTPRoute backendRefs.\n\n* Implementation-Specific: Services not connected via HTTPRoute, and any\n other kind of backend. Implementations MAY use BackendTLSPolicy for:\n - Services not referenced by any Route (e.g., infrastructure services)\n - Gateway feature backends (e.g., ExternalAuth, rate-limiting services)\n - Service mesh workload-to-service communication\n - Other resource types beyond Service\n\nImplementations SHOULD aim to ensure that BackendTLSPolicy behavior is consistent,\neven outside of the extended HTTPRoute -(backendRef) -> Service path.\nThey SHOULD clearly document how BackendTLSPolicy is interpreted in these\nscenarios, including:\n - Which resources beyond Service are supported\n - How the policy is discovered and applied\n - Any implementation-specific semantics or restrictions\n\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.",
"items": {
"description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
"properties": {
@@ -185,10 +185,10 @@
"x-kubernetes-list-type": "atomic"
},
"wellKnownCACertificates": {
- "description": "WellKnownCACertificates specifies whether system CA certificates may be used in\nthe TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nSupport: Implementation-specific",
- "enum": [
- "System"
- ],
+ "description": "WellKnownCACertificates specifies whether a well-known set of CA certificates\nmay be used in the TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nValid values include:\n* \"System\" - indicates that well-known system CA certificates should be used.\n\nImplementations MAY define their own sets of CA certificates. Such definitions\nMUST use an implementation-specific, prefixed name, such as\n`mycompany.com/my-custom-ca-certificates`.\n\nSupport: Implementation-specific",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(System|([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]))$",
"type": "string"
}
},
@@ -249,14 +249,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/master-standalone/backendtlspolicy-stable-v1alpha3.json b/crdSchemas/master-standalone/backendtlspolicy-stable-v1alpha3.json
index b310b7f..8ba29db 100644
--- a/crdSchemas/master-standalone/backendtlspolicy-stable-v1alpha3.json
+++ b/crdSchemas/master-standalone/backendtlspolicy-stable-v1alpha3.json
@@ -27,7 +27,7 @@
"type": "object"
},
"targetRefs": {
- "description": "TargetRefs identifies an API object to apply the policy to.\nOnly Services have Extended support. Implementations MAY support\nadditional objects, with Implementation Specific support.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {name}.\n For example, a policy named `bar` is given precedence over a\n policy named `baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nSupport: Extended for Kubernetes Service\n\nSupport: Implementation-specific for any other resource",
+ "description": "TargetRefs identifies an API object to apply the policy to.\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.\n\nTargetRefs must be _distinct_. This means either that:\n\n* They select different targets. If this is the case, then targetRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, and `name` must\n be unique across all targetRef entries in the BackendTLSPolicy.\n* They select different sectionNames in the same target.\n\nWhen more than one BackendTLSPolicy selects the same target and\nsectionName, implementations MUST determine precedence using the\nfollowing criteria, continuing on ties:\n\n* The older policy by creation timestamp takes precedence. For\n example, a policy with a creation timestamp of \"2021-07-15\n 01:02:03\" MUST be given precedence over a policy with a\n creation timestamp of \"2021-07-15 01:02:04\".\n* The policy appearing first in alphabetical order by {namespace}/{name}.\n For example, a policy named `foo/bar` is given precedence over a\n policy named `foo/baz`.\n\nFor any BackendTLSPolicy that does not take precedence, the\nimplementation MUST ensure the `Accepted` Condition is set to\n`status: False`, with Reason `Conflicted`.\n\nImplementations SHOULD NOT support more than one targetRef at this\ntime. Although the API technically allows for this, the current guidance\nfor conflict resolution and status handling is lacking. Until that can be\nclarified in a future release, the safest approach is to support a single\ntargetRef.\n\nSupport Levels:\n\n* Extended: Kubernetes Service referenced by HTTPRoute backendRefs.\n\n* Implementation-Specific: Services not connected via HTTPRoute, and any\n other kind of backend. Implementations MAY use BackendTLSPolicy for:\n - Services not referenced by any Route (e.g., infrastructure services)\n - Gateway feature backends (e.g., ExternalAuth, rate-limiting services)\n - Service mesh workload-to-service communication\n - Other resource types beyond Service\n\nImplementations SHOULD aim to ensure that BackendTLSPolicy behavior is consistent,\neven outside of the extended HTTPRoute -(backendRef) -> Service path.\nThey SHOULD clearly document how BackendTLSPolicy is interpreted in these\nscenarios, including:\n - Which resources beyond Service are supported\n - How the policy is discovered and applied\n - Any implementation-specific semantics or restrictions\n\nNote that this config applies to the entire referenced resource\nby default, but this default may change in the future to provide\na more granular application of the policy.",
"items": {
"description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
"properties": {
@@ -185,10 +185,10 @@
"x-kubernetes-list-type": "atomic"
},
"wellKnownCACertificates": {
- "description": "WellKnownCACertificates specifies whether system CA certificates may be used in\nthe TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nSupport: Implementation-specific",
- "enum": [
- "System"
- ],
+ "description": "WellKnownCACertificates specifies whether a well-known set of CA certificates\nmay be used in the TLS handshake between the gateway and backend pod.\n\nIf WellKnownCACertificates is unspecified or empty (\"\"), then CACertificateRefs\nmust be specified with at least one entry for a valid configuration. Only one of\nCACertificateRefs or WellKnownCACertificates may be specified, not both.\nIf an implementation does not support the WellKnownCACertificates field, or\nthe supplied value is not recognized, the implementation MUST ensure the\n`Accepted` Condition on the BackendTLSPolicy is set to `status: False`, with\na Reason `Invalid`.\n\nValid values include:\n* \"System\" - indicates that well-known system CA certificates should be used.\n\nImplementations MAY define their own sets of CA certificates. Such definitions\nMUST use an implementation-specific, prefixed name, such as\n`mycompany.com/my-custom-ca-certificates`.\n\nSupport: Implementation-specific",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(System|([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]))$",
"type": "string"
}
},
@@ -249,14 +249,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/master-standalone/backendtrafficpolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/backendtrafficpolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..325d9e1
--- /dev/null
+++ b/crdSchemas/master-standalone/backendtrafficpolicy-stable-v1alpha1.json
@@ -0,0 +1,3416 @@
+{
+ "description": "BackendTrafficPolicy allows the user to configure the behavior of the connection\nbetween the Envoy Proxy listener and the backend service.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "spec defines the desired state of BackendTrafficPolicy.",
+ "properties": {
+ "admissionControl": {
+ "description": "AdmissionControl defines the admission control policy to be applied. This configuration\nprobabilistically rejects requests based on the success rate of previous requests in a\nconfigurable sliding time window.",
+ "properties": {
+ "maxRejectionPercent": {
+ "description": "MaxRejectionPercent represents the upper limit of the rejection probability,\nexpressed as a percentage in the range [0, 100]. Defaults to 80 if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "minRequestRate": {
+ "description": "MinRequestRate defines the minimum requests per second below which requests will\npass through the filter without rejection. Defaults to 0 if not specified.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "minSuccessRate": {
+ "description": "MinSuccessRate is the lowest request success rate, as a percentage in the\nrange [1, 100], at which the filter will not reject requests. Defaults to 95 if\nnot specified. Envoy rejects values below 1%, so values lower than 1 are not allowed.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "rejectionAggression": {
+ "description": "RejectionAggression controls how steeply the rejection probability rises\nas the observed success rate falls below MinSuccessRate. A value of 1\nproduces a linear curve; higher values reject more aggressively for a\ngiven drop in success rate. Must be greater than 0; values below 1 are\nclamped to 1. Defaults to 1.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "samplingWindow": {
+ "description": "SamplingWindow defines the time window over which request success rates are calculated.\nMust be at least 1s; Envoy truncates the window to whole seconds and uses it as the\ndenominator in RPS calculations, so sub-second values would produce a zero denominator.\nDefaults to 30s if not specified.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "successCriteria": {
+ "description": "SuccessCriteria defines what constitutes a successful request for both HTTP and gRPC.",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines success criteria for gRPC requests.",
+ "properties": {
+ "statusCodes": {
+ "description": "StatusCodes defines gRPC status codes that are considered successful.\nStatus codes are defined in https://github.com/grpc/grpc/blob/master/doc/statuscodes.md#status-codes-and-their-use-in-grpc.",
+ "items": {
+ "description": "GRPCSuccessCode defines gRPC status codes as defined in\nhttps://github.com/grpc/grpc/blob/master/doc/statuscodes.md#status-codes-and-their-use-in-grpc.",
+ "enum": [
+ "Ok",
+ "Cancelled",
+ "Unknown",
+ "InvalidArgument",
+ "DeadlineExceeded",
+ "NotFound",
+ "AlreadyExists",
+ "PermissionDenied",
+ "ResourceExhausted",
+ "FailedPrecondition",
+ "Aborted",
+ "OutOfRange",
+ "Unimplemented",
+ "Internal",
+ "Unavailable",
+ "DataLoss",
+ "Unauthenticated"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTP defines success criteria for HTTP requests.",
+ "properties": {
+ "statusCodes": {
+ "description": "StatusCodes defines HTTP status codes that are considered successful.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "minSuccessRate must be between 1 and 100",
+ "rule": "!has(self.minSuccessRate) || (self.minSuccessRate >= 1 && self.minSuccessRate <= 100)"
+ },
+ {
+ "message": "maxRejectionPercent must be between 0 and 100",
+ "rule": "!has(self.maxRejectionPercent) || (self.maxRejectionPercent >= 0 && self.maxRejectionPercent <= 100)"
+ },
+ {
+ "message": "samplingWindow must be at least 1s",
+ "rule": "!has(self.samplingWindow) || duration(self.samplingWindow) >= duration('1s')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "bandwidthLimit": {
+ "description": "BandwidthLimit allows the user to limit the bandwidth of traffic\nsent to and received from the backend.",
+ "properties": {
+ "request": {
+ "description": "Request configures bandwidth limits for traffic sent to the backend.",
+ "properties": {
+ "limit": {
+ "description": "Limit specifies the bandwidth limit as a bytes-per-unit throughput rate.",
+ "properties": {
+ "unit": {
+ "description": "Unit specifies the time unit for the bandwidth limit (e.g. Second, Minute, Hour).",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Value specifies the bandwidth limit.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "unit",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response configures bandwidth limits for traffic sent from the backend.",
+ "properties": {
+ "limit": {
+ "description": "Limit specifies the bandwidth limit as a bytes-per-unit throughput rate.",
+ "properties": {
+ "unit": {
+ "description": "Unit specifies the time unit for the bandwidth limit (e.g. Second, Minute, Hour).",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Value specifies the bandwidth limit.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "unit",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "responseTrailers": {
+ "description": "ResponseTrailers configures the trailer headers appended to responses\nwhen bandwidth limiting introduces delays.",
+ "properties": {
+ "prefix": {
+ "description": "Prefix is prepended to each trailer header name.\nIf not set, no prefix is added and the trailers are named as-is.\nFor example, setting \"x-eg\" produces trailers such as \"x-eg-bandwidth-request-delay-ms\",\nwhile leaving it unset produces \"bandwidth-request-delay-ms\".\n\nThe following four trailers can be added:\n\"bandwidth-request-delay-ms\" is delay time in milliseconds it took for the request stream transfer\nincluding request body transfer time and the time added by the filter.\n\"bandwidth-response-delay-ms\" is delay time in milliseconds it took for the response stream transfer\nincluding response body transfer time and the time added by the filter.\n\"bandwidth-request-filter-delay-ms\" is delay time in milliseconds in request stream transfer added by the filter.\n\"bandwidth-response-filter-delay-ms\" is delay time in milliseconds that added by the filter.",
+ "pattern": "^[^\\r\\n\\x00]*$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of request or response must be specified",
+ "rule": "has(self.request) || has(self.response)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "compression": {
+ "description": "The compression config for the http streams.\n\nDeprecated: Use Compressor instead.",
+ "items": {
+ "description": "Compression defines the config of enabling compression.\nThis can help reduce the bandwidth at the expense of higher CPU.",
+ "properties": {
+ "brotli": {
+ "description": "The configuration for Brotli compressor.",
+ "type": "object"
+ },
+ "gzip": {
+ "description": "The configuration for GZIP compressor.",
+ "type": "object"
+ },
+ "minContentLength": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinContentLength defines the minimum response size in bytes to apply compression.\nResponses smaller than this threshold will not be compressed.\nMust be at least 30 bytes as enforced by Envoy Proxy.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 30 bytes",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "CompressorType defines the compressor type to use for compression.",
+ "enum": [
+ "Gzip",
+ "Brotli",
+ "Zstd"
+ ],
+ "type": "string"
+ },
+ "zstd": {
+ "description": "The configuration for Zstd compressor.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "compressor": {
+ "description": "The compressor config for the http streams.\nThis provides more granular control over compression configuration.\nOrder matters: The first compressor in the list is preferred when q-values in Accept-Encoding are equal.",
+ "items": {
+ "description": "Compression defines the config of enabling compression.\nThis can help reduce the bandwidth at the expense of higher CPU.",
+ "properties": {
+ "brotli": {
+ "description": "The configuration for Brotli compressor.",
+ "type": "object"
+ },
+ "gzip": {
+ "description": "The configuration for GZIP compressor.",
+ "type": "object"
+ },
+ "minContentLength": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinContentLength defines the minimum response size in bytes to apply compression.\nResponses smaller than this threshold will not be compressed.\nMust be at least 30 bytes as enforced by Envoy Proxy.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 30 bytes",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "CompressorType defines the compressor type to use for compression.",
+ "enum": [
+ "Gzip",
+ "Brotli",
+ "Zstd"
+ ],
+ "type": "string"
+ },
+ "zstd": {
+ "description": "The configuration for Zstd compressor.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "faultInjection": {
+ "description": "FaultInjection defines the fault injection policy to be applied. This configuration can be used to\ninject delays and abort requests to mimic failure scenarios such as service failures and overloads",
+ "properties": {
+ "abort": {
+ "description": "If specified, the request will be aborted if it meets the configuration criteria.",
+ "properties": {
+ "grpcStatus": {
+ "description": "GrpcStatus specifies the GRPC status code to be returned",
+ "format": "int32",
+ "maximum": 16,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "httpStatus": {
+ "description": "StatusCode specifies the HTTP status code to be returned",
+ "format": "int32",
+ "maximum": 600,
+ "minimum": 200,
+ "type": "integer"
+ },
+ "percentage": {
+ "default": 100,
+ "description": "Percentage specifies the percentage of requests to be aborted. Default 100%, if set 0, no requests will be aborted. Accuracy to 0.0001%.",
+ "type": "number"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "httpStatus and grpcStatus cannot be simultaneously defined.",
+ "rule": " !(has(self.httpStatus) && has(self.grpcStatus)) "
+ },
+ {
+ "message": "httpStatus and grpcStatus are set at least one.",
+ "rule": " has(self.httpStatus) || has(self.grpcStatus) "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "delay": {
+ "description": "If specified, a delay will be injected into the request.",
+ "properties": {
+ "fixedDelay": {
+ "description": "FixedDelay specifies the fixed delay duration",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "percentage": {
+ "default": 100,
+ "description": "Percentage specifies the percentage of requests to be delayed. Default 100%, if set 0, no requests will be delayed. Accuracy to 0.0001%.",
+ "type": "number"
+ }
+ },
+ "required": [
+ "fixedDelay"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Delay and abort faults are set at least one.",
+ "rule": " has(self.delay) || has(self.abort) "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpUpgrade": {
+ "description": "HTTPUpgrade defines the configuration for HTTP protocol upgrades.\nIf not specified, the default upgrade configuration (websocket) will be used.\nHowever, if requestBuffer is configured, the default upgrade configuration\nwill be ignored.",
+ "items": {
+ "description": "ProtocolUpgradeConfig specifies the configuration for protocol upgrades.",
+ "properties": {
+ "connect": {
+ "description": "Connect specifies the configuration for the CONNECT config.\nThis is allowed only when type is CONNECT.",
+ "properties": {
+ "terminate": {
+ "description": "Terminate the CONNECT request, and forwards the payload as raw TCP data.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type is the case-insensitive type of protocol upgrade.\ne.g. `websocket`, `CONNECT`, `spdy/3.1` etc.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "The connect configuration is only allowed when the type is CONNECT.",
+ "rule": "!has(self.connect) || self.type == 'CONNECT'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "mergeType": {
+ "description": "MergeType determines how this configuration is merged with existing BackendTrafficPolicy\nconfigurations targeting a parent resource. When set, this configuration will be merged\ninto a parent BackendTrafficPolicy (i.e. the one targeting a Gateway or Listener).\nThis field cannot be set when targeting a parent resource (Gateway).\nIf unset, no merging occurs, and only the most specific configuration takes effect.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Replace is not a valid MergeType for BackendTrafficPolicySpec",
+ "rule": "self != 'Replace'"
+ }
+ ]
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "rateLimit": {
+ "description": "RateLimit allows the user to limit the number of incoming requests\nto a predefined value based on attributes within the traffic flow.",
+ "properties": {
+ "global": {
+ "description": "Global defines global rate limit configuration.",
+ "properties": {
+ "rules": {
+ "description": "Rules are a list of RateLimit selectors and limits. Each rule and its\nassociated limit is applied in a mutually exclusive way. If a request\nmatches multiple rules, each of their associated limits get applied, so a\nsingle request might increase the rate limit counters for multiple rules\nif selected. The rate limit service will return a logical OR of the individual\nrate limit decisions of all matching rules. For example, if a request\nmatches two rules, one rate limited and one not, the final decision will be\nto rate limit the request.",
+ "items": {
+ "description": "RateLimitRule defines the semantics for matching attributes\nfrom the incoming requests, and setting limits for them.",
+ "properties": {
+ "clientSelectors": {
+ "description": "ClientSelectors holds the list of select conditions to select\nspecific clients using attributes from the traffic flow.\nAll individual select conditions must hold True for this rule\nand its limit to be applied.\n\nIf no client selectors are specified, the rule applies to all traffic of\nthe targeted Route.\n\nIf the policy targets a Gateway, the rule applies to each Route of the Gateway.\nPlease note that each Route has its own rate limit counters. For example,\nif a Gateway has two Routes, and the policy has a rule with limit 10rps,\neach Route will have its own 10rps limit.",
+ "items": {
+ "description": "RateLimitSelectCondition specifies the attributes within the traffic flow that can\nbe used to select a subset of clients to be ratelimited.\nAll the individual conditions must hold True for the overall condition to hold True.\nAnd, at least one of headers or methods or path or sourceCIDR or queryParams condition must be specified.",
+ "properties": {
+ "headers": {
+ "description": "Headers is a list of request headers to match. Multiple header values are ANDed together,\nmeaning, a request MUST match all the specified headers.",
+ "items": {
+ "description": "HeaderMatch defines the match attributes within the HTTP Headers of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the HTTP header.\nThe header name is case-insensitive unless PreserveHeaderCase is set to true.\nFor example, \"Foo\" and \"foo\" are considered the same header.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the header.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value within the HTTP header.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "methods": {
+ "description": "Methods is a list of request methods to match. Multiple method values are ORed together,\nmeaning, a request can match any one of the specified methods. If not specified, it matches all methods.",
+ "items": {
+ "description": "MethodMatch defines the matching criteria for the HTTP method of a request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "value": {
+ "description": "Value specifies the HTTP method.",
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "path": {
+ "description": "Path is the request path to match.\nSupport Exact, PathPrefix and RegularExpression match types.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "PathPrefix",
+ "description": "Type specifies how to match against the value of the path.",
+ "enum": [
+ "Exact",
+ "PathPrefix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "default": "/",
+ "description": "Value specifies the HTTP path.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryParams": {
+ "description": "QueryParams is a list of query parameters to match. Multiple query parameter values are ANDed together,\nmeaning, a request MUST match all the specified query parameters.",
+ "items": {
+ "description": "QueryParamMatch defines the match attributes within the query parameters of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the query parameter.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the query parameter.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the query parameter.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "sourceCIDR": {
+ "description": "SourceCIDR is the client IP Address range to match on.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the source range match result will be inverted.\nWhen true, the rule matches when the client IP is not in the specified range(s).",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "Exact",
+ "enum": [
+ "Exact",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the IP CIDR that represents the range of Source IP Addresses of the client.\nThese could also be the intermediate addresses through which the request has flown through and is part of the `X-Forwarded-For` header.\nFor example, `192.168.0.1/32`, `192.168.0.0/24`, `001:db8::/64`.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of headers, methods, path, sourceCIDR or queryParams must be specified",
+ "rule": "has(self.headers) || has(self.methods) || has(self.path) || has(self.sourceCIDR) || has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "cost": {
+ "description": "Cost specifies the cost of requests and responses for the rule.\n\nThis is optional and if not specified, the default behavior is to reduce the rate limit counters by 1 on\nthe request path and do not reduce the rate limit counters on the response path.",
+ "properties": {
+ "request": {
+ "description": "Request specifies the number to reduce the rate limit counters\non the request path. If this is not specified, the default behavior\nis to reduce the rate limit counters by 1.\n\nWhen Envoy receives a request that matches the rule, it tries to reduce the\nrate limit counters by the specified number. If the counter doesn't have\nenough capacity, the request is rate limited.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response specifies the number to reduce the rate limit counters\nafter the response is sent back to the client or the request stream is closed.\n\nThe cost is used to reduce the rate limit counters for the matching requests.\nSince the reduction happens after the request stream is complete, the rate limit\nwon't be enforced for the current request, but for the subsequent matching requests.\n\nThis is optional and if not specified, the rate limit counters are not reduced\non the response path.\n\nCurrently, this is only supported for HTTP Global Rate Limits.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "limit": {
+ "description": "Limit holds the rate limit values.\nThis limit is applied for traffic flows when the selectors\ncompute to True, causing the request to be counted towards the limit.\nThe limit is enforced and the request is ratelimited, i.e. a response with\n429 HTTP status code is sent back to the client when\nthe selected requests have reached the limit.",
+ "properties": {
+ "requests": {
+ "description": "Requests is the number of requests (or cost units, when used with\ncost-based rate limiting) allowed per Unit.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "unit": {
+ "description": "RateLimitUnit specifies the intervals for setting rate limits.\nValid RateLimitUnit values are \"Second\", \"Minute\", \"Hour\", \"Day\", \"Month\" and \"Year\".",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour",
+ "Day",
+ "Month",
+ "Year"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "requests",
+ "unit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "shadowMode": {
+ "description": "ShadowMode indicates whether this rate-limit rule runs in shadow mode.\nWhen enabled, all rate-limiting operations are performed (cache lookups,\ncounter updates, telemetry generation), but the outcome is never enforced.\nThe request always succeeds, even if the configured limit is exceeded.\n\nOnly supported for Global Rate Limits.",
+ "type": "boolean"
+ },
+ "shared": {
+ "description": "Shared determines whether this rate limit rule applies across all the policy targets.\nIf set to true, the rule is treated as a common bucket and is shared across all policy targets (xRoutes).\nDefault: false.",
+ "type": "boolean"
+ },
+ "xRateLimitHeaders": {
+ "description": "XRateLimitHeaders controls whether X-RateLimit response headers are emitted for this rate limit rule.\nWhen set, this overrides the global DisableRateLimitHeaders setting in ClientTrafficPolicy for this rule.\nIf not set, the rule inherits the listener-level setting (default behavior).",
+ "enum": [
+ "Off",
+ "DraftVersion03"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 256,
+ "type": "array"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "local": {
+ "description": "Local defines local rate limit configuration.",
+ "properties": {
+ "rules": {
+ "description": "Rules are a list of RateLimit selectors and limits. If a request matches\nmultiple rules, the strictest limit is applied. For example, if a request\nmatches two rules, one with 10rps and one with 20rps, the final limit will\nbe based on the rule with 10rps.",
+ "items": {
+ "description": "RateLimitRule defines the semantics for matching attributes\nfrom the incoming requests, and setting limits for them.",
+ "properties": {
+ "clientSelectors": {
+ "description": "ClientSelectors holds the list of select conditions to select\nspecific clients using attributes from the traffic flow.\nAll individual select conditions must hold True for this rule\nand its limit to be applied.\n\nIf no client selectors are specified, the rule applies to all traffic of\nthe targeted Route.\n\nIf the policy targets a Gateway, the rule applies to each Route of the Gateway.\nPlease note that each Route has its own rate limit counters. For example,\nif a Gateway has two Routes, and the policy has a rule with limit 10rps,\neach Route will have its own 10rps limit.",
+ "items": {
+ "description": "RateLimitSelectCondition specifies the attributes within the traffic flow that can\nbe used to select a subset of clients to be ratelimited.\nAll the individual conditions must hold True for the overall condition to hold True.\nAnd, at least one of headers or methods or path or sourceCIDR or queryParams condition must be specified.",
+ "properties": {
+ "headers": {
+ "description": "Headers is a list of request headers to match. Multiple header values are ANDed together,\nmeaning, a request MUST match all the specified headers.",
+ "items": {
+ "description": "HeaderMatch defines the match attributes within the HTTP Headers of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the HTTP header.\nThe header name is case-insensitive unless PreserveHeaderCase is set to true.\nFor example, \"Foo\" and \"foo\" are considered the same header.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the header.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value within the HTTP header.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the header.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "methods": {
+ "description": "Methods is a list of request methods to match. Multiple method values are ORed together,\nmeaning, a request can match any one of the specified methods. If not specified, it matches all methods.",
+ "items": {
+ "description": "MethodMatch defines the matching criteria for the HTTP method of a request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "value": {
+ "description": "Value specifies the HTTP method.",
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "path": {
+ "description": "Path is the request path to match.\nSupport Exact, PathPrefix and RegularExpression match types.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "PathPrefix",
+ "description": "Type specifies how to match against the value of the path.",
+ "enum": [
+ "Exact",
+ "PathPrefix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "default": "/",
+ "description": "Value specifies the HTTP path.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "queryParams": {
+ "description": "QueryParams is a list of query parameters to match. Multiple query parameter values are ANDed together,\nmeaning, a request MUST match all the specified query parameters.",
+ "items": {
+ "description": "QueryParamMatch defines the match attributes within the query parameters of the request.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the value match result will be inverted.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the query parameter.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the query parameter.",
+ "enum": [
+ "Exact",
+ "RegularExpression",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the query parameter.\nDo not set this field when Type=\"Distinct\", implying matching on any/all unique\nvalues within the query parameter.",
+ "maxLength": 1024,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "sourceCIDR": {
+ "description": "SourceCIDR is the client IP Address range to match on.",
+ "properties": {
+ "invert": {
+ "default": false,
+ "description": "Invert specifies whether the source range match result will be inverted.\nWhen true, the rule matches when the client IP is not in the specified range(s).",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "Exact",
+ "enum": [
+ "Exact",
+ "Distinct"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the IP CIDR that represents the range of Source IP Addresses of the client.\nThese could also be the intermediate addresses through which the request has flown through and is part of the `X-Forwarded-For` header.\nFor example, `192.168.0.1/32`, `192.168.0.0/24`, `001:db8::/64`.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of headers, methods, path, sourceCIDR or queryParams must be specified",
+ "rule": "has(self.headers) || has(self.methods) || has(self.path) || has(self.sourceCIDR) || has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "cost": {
+ "description": "Cost specifies the cost of requests and responses for the rule.\n\nThis is optional and if not specified, the default behavior is to reduce the rate limit counters by 1 on\nthe request path and do not reduce the rate limit counters on the response path.",
+ "properties": {
+ "request": {
+ "description": "Request specifies the number to reduce the rate limit counters\non the request path. If this is not specified, the default behavior\nis to reduce the rate limit counters by 1.\n\nWhen Envoy receives a request that matches the rule, it tries to reduce the\nrate limit counters by the specified number. If the counter doesn't have\nenough capacity, the request is rate limited.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response specifies the number to reduce the rate limit counters\nafter the response is sent back to the client or the request stream is closed.\n\nThe cost is used to reduce the rate limit counters for the matching requests.\nSince the reduction happens after the request stream is complete, the rate limit\nwon't be enforced for the current request, but for the subsequent matching requests.\n\nThis is optional and if not specified, the rate limit counters are not reduced\non the response path.\n\nCurrently, this is only supported for HTTP Global Rate Limits.",
+ "properties": {
+ "from": {
+ "description": "From specifies where to get the rate limit cost. Currently, only \"Number\" and \"Metadata\" are supported.",
+ "enum": [
+ "Number",
+ "Metadata"
+ ],
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata specifies the per-request metadata to retrieve the usage number from.",
+ "properties": {
+ "key": {
+ "description": "Key is the key to retrieve the usage number from the filter metadata.",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the dynamic metadata.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "number": {
+ "description": "Number specifies the fixed usage number to reduce the rate limit counters.\nUsing zero can be used to only check the rate limit counters without reducing them.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of number or metadata can be specified",
+ "rule": "!(has(self.number) && has(self.metadata))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "limit": {
+ "description": "Limit holds the rate limit values.\nThis limit is applied for traffic flows when the selectors\ncompute to True, causing the request to be counted towards the limit.\nThe limit is enforced and the request is ratelimited, i.e. a response with\n429 HTTP status code is sent back to the client when\nthe selected requests have reached the limit.",
+ "properties": {
+ "requests": {
+ "description": "Requests is the number of requests (or cost units, when used with\ncost-based rate limiting) allowed per Unit.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "unit": {
+ "description": "RateLimitUnit specifies the intervals for setting rate limits.\nValid RateLimitUnit values are \"Second\", \"Minute\", \"Hour\", \"Day\", \"Month\" and \"Year\".",
+ "enum": [
+ "Second",
+ "Minute",
+ "Hour",
+ "Day",
+ "Month",
+ "Year"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "requests",
+ "unit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "shadowMode": {
+ "description": "ShadowMode indicates whether this rate-limit rule runs in shadow mode.\nWhen enabled, all rate-limiting operations are performed (cache lookups,\ncounter updates, telemetry generation), but the outcome is never enforced.\nThe request always succeeds, even if the configured limit is exceeded.\n\nOnly supported for Global Rate Limits.",
+ "type": "boolean"
+ },
+ "shared": {
+ "description": "Shared determines whether this rate limit rule applies across all the policy targets.\nIf set to true, the rule is treated as a common bucket and is shared across all policy targets (xRoutes).\nDefault: false.",
+ "type": "boolean"
+ },
+ "xRateLimitHeaders": {
+ "description": "XRateLimitHeaders controls whether X-RateLimit response headers are emitted for this rate limit rule.\nWhen set, this overrides the global DisableRateLimitHeaders setting in ClientTrafficPolicy for this rule.\nIf not set, the rule inherits the listener-level setting (default behavior).",
+ "enum": [
+ "Off",
+ "DraftVersion03"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "limit"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "response cost is not supported for Local Rate Limits",
+ "rule": "self.all(r, !has(r.cost) || !has(r.cost.response))"
+ }
+ ]
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the scope for the RateLimits.\nValid RateLimitType values are \"Global\" or \"Local\".\n\nDeprecated: Use Global and/or Local fields directly instead. Both can be specified simultaneously for combined rate limiting.",
+ "enum": [
+ "Global",
+ "Local"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestBuffer": {
+ "description": "RequestBuffer allows the gateway to buffer and fully receive each request from a client before continuing to send the request\nupstream to the backends. This can be helpful to shield your backend servers from slow clients, and also to enforce a maximum size per request\nas any requests larger than the buffer size will be rejected.\n\nThis can have a negative performance impact so should only be enabled when necessary.\n\nWhen enabling this option, you should also configure your connection buffer size to account for these request buffers. There will also be an\nincrease in memory usage for Envoy that should be accounted for in your deployment settings.\n\nRequest buffering is incompatible with streaming APIs and protocol upgrades such as gRPC streaming and WebSocket. Do not enable this option\non routes that need those protocols, because requests can hang instead of being forwarded upstream.",
+ "properties": {
+ "limit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Limit specifies the maximum allowed size in bytes for each incoming request buffer.\nIf exceeded, the request will be rejected with HTTP 413 Content Too Large.\n\nAccepts values in resource.Quantity format (e.g., \"10Mi\", \"500Ki\").",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "responseOverride": {
+ "description": "ResponseOverride defines the configuration to override specific responses with a custom one.\nIf multiple configurations are specified, the first one to match wins.",
+ "items": {
+ "description": "ResponseOverride defines the configuration to override specific responses with a custom one.",
+ "properties": {
+ "match": {
+ "description": "Match configuration.",
+ "properties": {
+ "statusCodes": {
+ "description": "Status code to match on. The match evaluates to true if any of the matches are successful.",
+ "items": {
+ "description": "StatusCodeMatch defines the configuration for matching a status code.",
+ "properties": {
+ "range": {
+ "description": "Range contains the range of status codes.",
+ "properties": {
+ "end": {
+ "description": "End of the range, including the end value.",
+ "type": "integer"
+ },
+ "start": {
+ "description": "Start of the range, including the start value.",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "end must be greater than start",
+ "rule": "self.end > self.start"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Value",
+ "Range"
+ ]
+ },
+ {
+ "enum": [
+ "Value",
+ "Range"
+ ]
+ }
+ ],
+ "default": "Value",
+ "description": "Type is the type of value.\nValid values are Value and Range, default is Value.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value contains the value of the status code.",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "value must be set for type Value",
+ "rule": "(!has(self.type) || self.type == 'Value')? has(self.value) : true"
+ },
+ {
+ "message": "range must be set for type Range",
+ "rule": "(has(self.type) && self.type == 'Range')? has(self.range) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "statusCodes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "redirect": {
+ "description": "Redirect configuration",
+ "properties": {
+ "hostname": {
+ "description": "Hostname is the hostname to be used in the value of the `Location`\nheader in the response.\nWhen empty, the hostname in the `Host` header of the request is used.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines parameters used to modify the path of the incoming request.\nThe modified path is then used to construct the `Location` header. When\nempty, the request path is used as-is.\nOnly ReplaceFullPath path modifier is supported currently.",
+ "properties": {
+ "replaceFullPath": {
+ "description": "ReplaceFullPath specifies the value with which to replace the full path\nof a request during a rewrite or redirect.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "replacePrefixMatch": {
+ "description": "ReplacePrefixMatch specifies the value with which to replace the prefix\nmatch of a request during a rewrite or redirect. For example, a request\nto \"/foo/bar\" with a prefix match of \"/foo\" and a ReplacePrefixMatch\nof \"/xyz\" would be modified to \"/xyz/bar\".\n\nNote that this matches the behavior of the PathPrefix match type. This\nmatches full path elements. A path element refers to the list of labels\nin the path split by the `/` separator. When specified, a trailing `/` is\nignored. For example, the paths `/abc`, `/abc/`, and `/abc/def` would all\nmatch the prefix `/abc`, but the path `/abcd` would not.\n\nReplacePrefixMatch is only compatible with a `PathPrefix` HTTPRouteMatch.\nUsing any other HTTPRouteMatch type on the same HTTPRouteRule will result in\nthe implementation setting the Accepted Condition for the Route to `status: False`.\n\nRequest Path | Prefix Match | Replace Prefix | Modified Path",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "type": {
+ "description": "Type defines the type of path modifier. Additional types may be\nadded in a future release of the API.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.",
+ "enum": [
+ "ReplaceFullPath",
+ "ReplacePrefixMatch"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only ReplaceFullPath is supported for path.type",
+ "rule": "self.type == 'ReplaceFullPath'"
+ },
+ {
+ "message": "replaceFullPath must be specified when type is set to 'ReplaceFullPath'",
+ "rule": "self.type == 'ReplaceFullPath' ? has(self.replaceFullPath) : true"
+ },
+ {
+ "message": "type must be 'ReplaceFullPath' when replaceFullPath is set",
+ "rule": "has(self.replaceFullPath) ? self.type == 'ReplaceFullPath' : true"
+ },
+ {
+ "message": "replacePrefixMatch must be specified when type is set to 'ReplacePrefixMatch'",
+ "rule": "self.type == 'ReplacePrefixMatch' ? has(self.replacePrefixMatch) : true"
+ },
+ {
+ "message": "type must be 'ReplacePrefixMatch' when replacePrefixMatch is set",
+ "rule": "has(self.replacePrefixMatch) ? self.type == 'ReplacePrefixMatch' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "port": {
+ "description": "Port is the port to be used in the value of the `Location`\nheader in the response.\n\nIf redirect scheme is not-empty, the well-known port associated with the redirect scheme will be used.\nSpecifically \"http\" to port 80 and \"https\" to port 443. If the redirect scheme does not have a\nwell-known port or redirect scheme is empty, the listener port of the Gateway will be used.\n\nPort will not be added in the 'Location' header if scheme is HTTP and port is 80\nor scheme is HTTPS and port is 443.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "scheme": {
+ "description": "Scheme is the scheme to be used in the value of the `Location` header in\nthe response. When empty, the scheme of the request is used.",
+ "enum": [
+ "http",
+ "https"
+ ],
+ "type": "string"
+ },
+ "statusCode": {
+ "default": 302,
+ "description": "StatusCode is the HTTP status code to be used in response.",
+ "enum": [
+ 301,
+ 302
+ ],
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Response configuration.",
+ "properties": {
+ "body": {
+ "description": "Body of the Custom Response\nSupports Envoy command operators for dynamic content (see https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators).",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the value as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ },
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ }
+ ],
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the body value.\nValid values are Inline and ValueRef, default is Inline.",
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef contains the contents of the body\nspecified as a local object reference.\nOnly a reference to ConfigMap is supported.\n\nThe value of key `response.body` in the ConfigMap will be used as the response body.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "inline must be set for type Inline",
+ "rule": "(!has(self.type) || self.type == 'Inline')? has(self.inline) : true"
+ },
+ {
+ "message": "valueRef must be set for type ValueRef",
+ "rule": "(has(self.type) && self.type == 'ValueRef')? has(self.valueRef) : true"
+ },
+ {
+ "message": "only ConfigMap is supported for ValueRef",
+ "rule": "has(self.valueRef) ? self.valueRef.kind == 'ConfigMap' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "contentType": {
+ "description": "Content Type of the response. This will be set in the Content-Type header.",
+ "type": "string"
+ },
+ "header": {
+ "description": "Header defines headers to add, set or remove from the response.\nThis allows the response policy to append, add or override headers\nof the final response before it is sent to a downstream client.\nNote: Header removal is not supported for responseOverride.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Remove is not supported for header in CustomResponse",
+ "rule": "!has(self.remove) || size(self.remove) == 0"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "statusCode": {
+ "description": "Status Code of the Custom Response\nIf unset, does not override the status of response.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "source": {
+ "description": "Source specifies which responses this rule applies to.\nLocal overrides only Envoy-generated responses (e.g. auth failures).\nBackend overrides only upstream responses.\nAll (default) overrides both.",
+ "enum": [
+ "All",
+ "Local",
+ "Backend"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "match"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one of response or redirect must be specified",
+ "rule": "(has(self.response) && !has(self.redirect)) || (!has(self.response) && has(self.redirect))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "routingType": {
+ "description": "RoutingType can be set to \"Service\" to use the Service Cluster IP for routing to the backend,\nor it can be set to \"Endpoint\" to use Endpoint routing.\nWhen specified, this overrides the EnvoyProxy-level setting for the relevant targetRefs.\nIf not specified, the EnvoyProxy-level setting is used.",
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "telemetry": {
+ "description": "Telemetry configures the telemetry settings for the policy target (Gateway or xRoute).\nThis will override the telemetry settings in the EnvoyProxy resource.",
+ "properties": {
+ "metrics": {
+ "description": "Metrics defines metrics configuration for the backend or Route.",
+ "properties": {
+ "routeStatName": {
+ "description": "RouteStatName defines the value of the Route stat_prefix, determining how the route stats are named.\nFor more details, see envoy docs: https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/route/v3/route_components.proto#config-route-v3-route\nThe supported operators for this pattern are:\n%ROUTE_NAME%: name of Gateway API xRoute resource\n%ROUTE_NAMESPACE%: namespace of Gateway API xRoute resource\n%ROUTE_KIND%: kind of Gateway API xRoute resource\nExample: %ROUTE_KIND%/%ROUTE_NAMESPACE%/%ROUTE_NAME% => httproute/my-ns/my-route\nDisabled by default.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tracing": {
+ "description": "Tracing configures the tracing settings for the backend or HTTPRoute.\n\nThis takes precedence over EnvoyProxy tracing when set.",
+ "properties": {
+ "customTags": {
+ "additionalProperties": {
+ "properties": {
+ "environment": {
+ "description": "Environment adds value from environment variable to each span.\nIt's required when the type is \"Environment\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the environment variable is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the environment variable which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "literal": {
+ "description": "Literal adds hard-coded value to each span.\nIt's required when the type is \"Literal\".",
+ "properties": {
+ "value": {
+ "description": "Value defines the hard-coded value to add to each span.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestHeader": {
+ "description": "RequestHeader adds value from request header to each span.\nIt's required when the type is \"RequestHeader\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the request header is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the request header which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Literal",
+ "description": "Type defines the type of custom tag.",
+ "enum": [
+ "Literal",
+ "Environment",
+ "RequestHeader"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "description": "CustomTags defines the custom tags to add to each span.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nDeprecated: Use Tags instead.",
+ "type": "object"
+ },
+ "samplingFraction": {
+ "description": "SamplingFraction represents the fraction of requests that should be\nselected for tracing if no prior sampling decision has been made.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "spanName": {
+ "description": "SpanName defines the name of the span which will be used for tracing.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\n\nIf not set, the span name is provider specific.\ne.g. Datadog use `ingress` as the default client span name,\nand `router egress` as the server span name.",
+ "properties": {
+ "client": {
+ "description": "Client defines operation name of the span which will be used for tracing.",
+ "type": "string"
+ },
+ "server": {
+ "description": "Server defines the operation name of the upstream span which will be used for tracing.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "client",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tags": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Tags defines the custom tags to add to each span.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nSame keys take precedence over CustomTags.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "useClientProtocol": {
+ "description": "UseClientProtocol configures Envoy to prefer sending requests to backends using\nthe same HTTP protocol that the incoming request used. Defaults to false, which means\nthat Envoy will use the protocol indicated by the attached BackendRef.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true "
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRef) ? self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute'] : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true "
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute']) : true "
+ },
+ {
+ "message": "either compression or compressor can be set, not both",
+ "rule": "!has(self.compression) || !has(self.compressor)"
+ },
+ {
+ "message": "requestBuffer cannot be used together with httpUpgrade",
+ "rule": "!has(self.requestBuffer) || !has(self.httpUpgrade) || self.httpUpgrade.size() == 0"
+ },
+ {
+ "message": "admissionControl can only be used with HTTPRoute, GRPCRoute, or Gateway targets",
+ "rule": "!has(self.admissionControl) || ((!has(self.targetRef) || self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute']) && (!has(self.targetRefs) || self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute'])) && (!has(self.targetSelectors) || self.targetSelectors.all(sel, sel.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute'])))"
+ },
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "status defines the current status of BackendTrafficPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/ciliumclusterwidenetworkpolicy-stable-v2.json b/crdSchemas/master-standalone/ciliumclusterwidenetworkpolicy-stable-v2.json
index 4cada59..dc459e3 100644
--- a/crdSchemas/master-standalone/ciliumclusterwidenetworkpolicy-stable-v2.json
+++ b/crdSchemas/master-standalone/ciliumclusterwidenetworkpolicy-stable-v2.json
@@ -387,9 +387,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -398,18 +398,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -593,13 +597,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -622,14 +631,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -637,14 +638,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -770,57 +763,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -829,9 +771,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -1248,9 +1190,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1259,18 +1201,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -1369,13 +1315,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -1798,9 +1749,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1809,18 +1760,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2060,13 +2015,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2089,14 +2049,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -2104,14 +2056,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -2237,57 +2181,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -2296,9 +2189,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -2566,9 +2459,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -2577,18 +2470,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2743,13 +2640,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2775,13 +2677,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -3246,9 +3148,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -3257,18 +3159,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -3452,13 +3358,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -3481,14 +3392,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -3496,14 +3399,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -3629,57 +3524,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -3688,9 +3532,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -4107,9 +3951,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4118,18 +3962,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4228,13 +4076,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4657,9 +4510,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4668,18 +4521,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4919,13 +4776,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4948,14 +4810,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -4963,14 +4817,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -5096,57 +4942,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -5155,9 +4950,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -5425,9 +5220,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -5436,18 +5231,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -5602,13 +5401,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -5634,13 +5438,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -5819,5 +5623,11 @@
"required": [
"metadata"
],
- "type": "object"
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "spec or specs must be provided",
+ "rule": "has(self.spec) || has(self.specs)"
+ }
+ ]
}
diff --git a/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2.json b/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2.json
index 87aedb0..87232b0 100644
--- a/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2.json
+++ b/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2.json
@@ -1,5 +1,5 @@
{
- "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to to allocate\nand advertise IPs for Services of type LoadBalancer.",
+ "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to allocate\nand advertise IPs for Services of type LoadBalancer.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
diff --git a/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2alpha1.json b/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2alpha1.json
index 87aedb0..87232b0 100644
--- a/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2alpha1.json
+++ b/crdSchemas/master-standalone/ciliumloadbalancerippool-stable-v2alpha1.json
@@ -1,5 +1,5 @@
{
- "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to to allocate\nand advertise IPs for Services of type LoadBalancer.",
+ "description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to allocate\nand advertise IPs for Services of type LoadBalancer.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
diff --git a/crdSchemas/master-standalone/ciliumnetworkpolicy-stable-v2.json b/crdSchemas/master-standalone/ciliumnetworkpolicy-stable-v2.json
index 20b88bd..b746e60 100644
--- a/crdSchemas/master-standalone/ciliumnetworkpolicy-stable-v2.json
+++ b/crdSchemas/master-standalone/ciliumnetworkpolicy-stable-v2.json
@@ -387,9 +387,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -398,18 +398,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -593,13 +597,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -622,14 +631,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -637,14 +638,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -770,57 +763,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -829,9 +771,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -1248,9 +1190,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1259,18 +1201,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -1369,13 +1315,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -1798,9 +1749,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -1809,18 +1760,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2060,13 +2015,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2089,14 +2049,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -2104,14 +2056,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -2237,57 +2181,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -2296,9 +2189,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -2566,9 +2459,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -2577,18 +2470,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -2743,13 +2640,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -2775,13 +2677,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -3246,9 +3148,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -3257,18 +3159,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -3452,13 +3358,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -3481,14 +3392,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -3496,14 +3399,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -3629,57 +3524,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -3688,9 +3532,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -4107,9 +3951,9 @@
"type": "array"
},
"toGroups": {
- "description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4118,18 +3962,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4228,13 +4076,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4657,9 +4510,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -4668,18 +4521,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -4919,13 +4776,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -4948,14 +4810,6 @@
"http"
]
},
- {
- "properties": {
- "kafka": {}
- },
- "required": [
- "kafka"
- ]
- },
{
"properties": {
"dns": {}
@@ -4963,14 +4817,6 @@
"required": [
"dns"
]
- },
- {
- "properties": {
- "l7proto": {}
- },
- "required": [
- "l7proto"
- ]
}
],
"properties": {
@@ -5096,57 +4942,6 @@
"additionalProperties": false
},
"type": "array"
- },
- "kafka": {
- "description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
- "items": {
- "description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
- "properties": {
- "apiKey": {
- "description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
- "type": "string"
- },
- "apiVersion": {
- "description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
- "type": "string"
- },
- "clientID": {
- "description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
- "type": "string"
- },
- "role": {
- "description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
- "enum": [
- "produce",
- "consume"
- ],
- "type": "string"
- },
- "topic": {
- "description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
- "maxLength": 255,
- "type": "string"
- }
- },
- "type": "object",
- "additionalProperties": false
- },
- "type": "array"
- },
- "l7": {
- "description": "Key-value pair rules.",
- "items": {
- "additionalProperties": {
- "type": "string"
- },
- "description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
- "type": "object"
- },
- "type": "array"
- },
- "l7proto": {
- "description": "Name of the L7 protocol for which the Key-value pair rules apply.",
- "type": "string"
}
},
"type": "object",
@@ -5155,9 +4950,9 @@
"serverNames": {
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
"items": {
- "description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
+ "description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
"maxLength": 255,
- "pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
+ "pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
"type": "string"
},
"minItems": 1,
@@ -5425,9 +5220,9 @@
"type": "array"
},
"fromGroups": {
- "description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
+ "description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
"items": {
- "description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
+ "description": "Groups allows referencing CIDRs that are resolved from an external integration.",
"properties": {
"aws": {
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
@@ -5436,18 +5231,22 @@
"additionalProperties": {
"type": "string"
},
+ "description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
"type": "object"
},
"region": {
+ "description": "Deprecated: Region is unused.",
"type": "string"
},
"securityGroupsIds": {
+ "description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
"type": "array"
},
"securityGroupsNames": {
+ "description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
"items": {
"type": "string"
},
@@ -5602,13 +5401,18 @@
"type": "string"
},
"protocol": {
- "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
+ "description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
"enum": [
"TCP",
"UDP",
"SCTP",
"VRRP",
"IGMP",
+ "GRE",
+ "IPIP",
+ "IPV6",
+ "ESP",
+ "AH",
"ANY"
],
"type": "string"
@@ -5634,13 +5438,13 @@
"labels": {
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
"items": {
- "description": "Label is the Cilium's representation of a container label.",
+ "description": "Label is Cilium's representation of a label.",
"properties": {
"key": {
"type": "string"
},
"source": {
- "description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
+ "description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
"type": "string"
},
"value": {
@@ -5819,5 +5623,11 @@
"required": [
"metadata"
],
- "type": "object"
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "spec or specs must be provided",
+ "rule": "has(self.spec) || has(self.specs)"
+ }
+ ]
}
diff --git a/crdSchemas/master-standalone/ciliumnode-stable-v2.json b/crdSchemas/master-standalone/ciliumnode-stable-v2.json
index c4c6087..f997432 100644
--- a/crdSchemas/master-standalone/ciliumnode-stable-v2.json
+++ b/crdSchemas/master-standalone/ciliumnode-stable-v2.json
@@ -43,6 +43,7 @@
},
"cidr-block": {
"description": "CIDRBlock is vpc ipv4 CIDR",
+ "format": "cidr",
"type": "string"
},
"instance-type": {
@@ -138,33 +139,14 @@
"minimum": 0,
"type": "integer"
},
- "instance-id": {
- "description": "InstanceID is the AWS InstanceId of the node. The InstanceID is used\nto retrieve AWS metadata for the node.\n\nOBSOLETE: This field is obsolete, please use Spec.InstanceID",
- "type": "string"
- },
"instance-type": {
"description": "InstanceType is the AWS EC2 instance type, e.g. \"m5.large\"",
"type": "string"
},
- "max-above-watermark": {
- "description": "MaxAboveWatermark is the maximum number of addresses to allocate\nbeyond the addresses needed to reach the PreAllocate watermark.\nGoing above the watermark can help reduce the number of API calls to\nallocate IPs, e.g. when a new ENI is allocated, as many secondary\nIPs as possible are allocated. Limiting the amount can help reduce\nwaste of IPs.\n\nOBSOLETE: This field is obsolete, please use Spec.IPAM.MaxAboveWatermark",
- "minimum": 0,
- "type": "integer"
- },
- "min-allocate": {
- "description": "MinAllocate is the minimum number of IPs that must be allocated when\nthe node is first bootstrapped. It defines the minimum base socket\nof addresses that must be available. After reaching this watermark,\nthe PreAllocate and MaxAboveWatermark logic takes over to continue\nallocating IPs.\n\nOBSOLETE: This field is obsolete, please use Spec.IPAM.MinAllocate",
- "minimum": 0,
- "type": "integer"
- },
"node-subnet-id": {
"description": "NodeSubnetID is the subnet of the primary ENI the instance was brought up\nwith. It is used as a sensible default subnet to create ENIs in.",
"type": "string"
},
- "pre-allocate": {
- "description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMspec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.\n\nOBSOLETE: This field is obsolete, please use Spec.IPAM.PreAllocate",
- "minimum": 0,
- "type": "integer"
- },
"security-group-tags": {
"additionalProperties": {
"type": "string"
@@ -277,6 +259,7 @@
"podCIDRs": {
"description": "PodCIDRs is the list of CIDRs available to the node for allocation.\nWhen an IP is used, the IP will be added to Status.IPAM.Used",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -308,10 +291,17 @@
"items": {
"description": "IPAMPoolAllocation describes an allocation of an IPAM pool from the operator to the\nnode. It contains the assigned PodCIDRs allocated from this pool",
"properties": {
+ "allowFirstIP": {
+ "description": "AllowFirstIP allows the first IP of each allocated CIDR to be used.",
+ "type": "boolean"
+ },
+ "allowLastIP": {
+ "description": "AllowLastIP allows the last IP of each allocated CIDR to be used.",
+ "type": "boolean"
+ },
"cidrs": {
"description": "CIDRs contains a list of pod CIDRs currently allocated from this pool",
"items": {
- "description": "IPAMPodCIDR is a pod CIDR",
"format": "cidr",
"type": "string"
},
@@ -369,7 +359,7 @@
"additionalProperties": false
},
"pre-allocate": {
- "description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMspec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.",
+ "description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMSpec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.",
"minimum": 0,
"type": "integer"
},
@@ -383,11 +373,6 @@
},
"type": "object",
"additionalProperties": false
- },
- "nodeidentity": {
- "description": "NodeIdentity is the Cilium numeric identity allocated for the node, if any.",
- "format": "int64",
- "type": "integer"
}
},
"type": "object",
@@ -459,15 +444,18 @@
"properties": {
"cidr": {
"description": "CIDRBlock is the VPC IPv4 CIDR",
+ "format": "cidr",
"type": "string"
},
"ipv6-cidr": {
"description": "IPv6CIDRBlock is the VPC IPv6 CIDR",
+ "format": "cidr",
"type": "string"
},
"secondary-cidrs": {
"description": "SecondaryCIDRs is the list of Secondary CIDRs associated with the VPC",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -485,10 +473,12 @@
"properties": {
"cidr": {
"description": "CIDRBlock is the vSwitch IPv4 CIDR",
+ "format": "cidr",
"type": "string"
},
"ipv6-cidr": {
"description": "IPv6CIDRBlock is the vSwitch IPv6 CIDR",
+ "format": "cidr",
"type": "string"
},
"vswitch-id": {
@@ -522,12 +512,8 @@
"items": {
"description": "AzureInterface represents an Azure Interface",
"properties": {
- "GatewayIP": {
- "description": "GatewayIP is the interface's subnet's default route\n\nOBSOLETE: This field is obsolete, please use Gateway field instead.",
- "type": "string"
- },
"addresses": {
- "description": "Addresses is the list of all IPs associated with the interface,\nincluding all secondary addresses",
+ "description": "Addresses is the list of secondary IPs associated with the interface.\nThe primary IP is tracked separately in the IP field, but is also\nincluded here when the operator is configured to expose it for\nallocation.",
"items": {
"description": "AzureAddress is an IP address assigned to an AzureInterface",
"properties": {
@@ -540,7 +526,7 @@
"type": "string"
},
"subnet": {
- "description": "Subnet is the subnet the address belongs to",
+ "description": "Subnet is the subnet the address belongs to.\n\nDeprecated: use AzureInterface.Subnet.ID. Populated as a mirror for one\nrelease so external consumers of CiliumNode.Status.Azure can migrate.",
"type": "string"
}
},
@@ -550,7 +536,8 @@
"type": "array"
},
"cidr": {
- "description": "CIDR is the range that the interface belongs to.",
+ "description": "CIDR is the range that the interface belongs to.\n\nDeprecated: use Subnet.CIDR. Retained for one release so agent/operator\nrolling upgrades work in either order.",
+ "format": "cidr",
"type": "string"
},
"gateway": {
@@ -561,6 +548,10 @@
"description": "ID is the identifier",
"type": "string"
},
+ "ip": {
+ "description": "IP is the primary IP of the interface",
+ "type": "string"
+ },
"mac": {
"description": "MAC is the mac address",
"type": "string"
@@ -576,6 +567,22 @@
"state": {
"description": "State is the provisioning state",
"type": "string"
+ },
+ "subnet": {
+ "description": "Subnet is the subnet the interface is attached to.",
+ "properties": {
+ "cidr": {
+ "description": "CIDR is the CIDR range associated with the subnet",
+ "format": "cidr",
+ "type": "string"
+ },
+ "id": {
+ "description": "ID is the resource ID of the subnet",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
}
},
"type": "object",
@@ -617,6 +624,14 @@
"description": "IP is the primary IP of the ENI",
"type": "string"
},
+ "ipv6-prefixes": {
+ "description": "IPv6Prefixes is the list of all IPv6 /80 delegated prefixes associated with the ENI",
+ "items": {
+ "format": "cidr",
+ "type": "string"
+ },
+ "type": "array"
+ },
"mac": {
"description": "MAC is the mac address of the ENI",
"type": "string"
@@ -626,8 +641,9 @@
"type": "integer"
},
"prefixes": {
- "description": "Prefixes is the list of all /28 prefixes associated with the ENI",
+ "description": "Prefixes is the list of all IPv4 /28 delegated prefixes associated with the ENI",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -648,6 +664,7 @@
"properties": {
"cidr": {
"description": "CIDR is the CIDR range associated with the subnet",
+ "format": "cidr",
"type": "string"
},
"id": {
@@ -671,6 +688,7 @@
"cidrs": {
"description": "CIDRs is the list of CIDR ranges associated with the VPC",
"items": {
+ "format": "cidr",
"type": "string"
},
"type": "array"
@@ -681,6 +699,7 @@
},
"primary-cidr": {
"description": "PrimaryCIDR is the primary CIDR of the VPC",
+ "format": "cidr",
"type": "string"
}
},
diff --git a/crdSchemas/master-standalone/ciliumpodippool-stable-v2.json b/crdSchemas/master-standalone/ciliumpodippool-stable-v2.json
new file mode 100644
index 0000000..1d3e3b9
--- /dev/null
+++ b/crdSchemas/master-standalone/ciliumpodippool-stable-v2.json
@@ -0,0 +1,330 @@
+{
+ "description": "CiliumPodIPPool defines an IP pool that can be used for pooled IPAM (i.e. the multi-pool IPAM\nmode).",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "properties": {
+ "allowFirstIP": {
+ "default": false,
+ "description": "AllowFirstIP allows the first IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowFirstIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "allowLastIP": {
+ "default": false,
+ "description": "AllowLastIP allows the last IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowLastIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "ipv4": {
+ "description": "IPv4 specifies the IPv4 CIDRs and mask sizes of the pool",
+ "properties": {
+ "cidrs": {
+ "description": "CIDRs is a list of IPv4 CIDRs that are part of the pool.",
+ "items": {
+ "description": "PoolCIDR is an IP pool CIDR.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "maskSize": {
+ "description": "MaskSize is the mask size of the pool.",
+ "maximum": 32,
+ "minimum": 1,
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "pool": {
+ "description": "Pool contains per-CIDR configuration for a subset of CIDRs listed in CIDRs.\nEach entry must reference a CIDR in CIDRs.",
+ "items": {
+ "properties": {
+ "cidr": {
+ "description": "CIDR references one of the CIDRs listed in the parent pool spec.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "reservedRanges": {
+ "description": "ReservedRanges is a list of IP ranges within CIDR that must not be allocated.",
+ "items": {
+ "properties": {
+ "end": {
+ "description": "The last IP in the reserved range.",
+ "type": "string"
+ },
+ "start": {
+ "description": "The first IP in the reserved range.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "cidr"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "cidr"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "cidrs",
+ "maskSize"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If pool is set, each pool entry must reference a CIDR from cidrs",
+ "rule": "!has(self.pool) || self.pool.all(p, p.cidr in self.cidrs)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "ipv6": {
+ "description": "IPv6 specifies the IPv6 CIDRs and mask sizes of the pool",
+ "properties": {
+ "cidrs": {
+ "description": "CIDRs is a list of IPv6 CIDRs that are part of the pool.",
+ "items": {
+ "description": "PoolCIDR is an IP pool CIDR.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "maskSize": {
+ "description": "MaskSize is the mask size of the pool.",
+ "maximum": 128,
+ "minimum": 1,
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "pool": {
+ "description": "Pool contains per-CIDR configuration for a subset of CIDRs listed in CIDRs.\nEach entry must reference a CIDR in CIDRs.",
+ "items": {
+ "properties": {
+ "cidr": {
+ "description": "CIDR references one of the CIDRs listed in the parent pool spec.",
+ "format": "cidr",
+ "type": "string"
+ },
+ "reservedRanges": {
+ "description": "ReservedRanges is a list of IP ranges within CIDR that must not be allocated.",
+ "items": {
+ "properties": {
+ "end": {
+ "description": "The last IP in the reserved range.",
+ "type": "string"
+ },
+ "start": {
+ "description": "The first IP in the reserved range.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "end",
+ "start"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "cidr"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "cidr"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "cidrs",
+ "maskSize"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If pool is set, each pool entry must reference a CIDR from cidrs",
+ "rule": "!has(self.pool) || self.pool.all(p, p.cidr in self.cidrs)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "namespaceSelector": {
+ "description": "NamespaceSelector selects the set of Namespaces that are eligible to use\nthis pool. If both PodSelector and NamespaceSelector are specified, a Pod\nmust match both selectors to be eligible for IP allocation from this pool.\n\nIf NamespaceSelector is empty, the pool can be used by Pods in any namespace\n(subject to PodSelector constraints).",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "enum": [
+ "In",
+ "NotIn",
+ "Exists",
+ "DoesNotExist"
+ ],
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
+ "maxLength": 63,
+ "pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "podSelector": {
+ "description": "PodSelector selects the set of Pods that are eligible to receive IPs from\nthis pool when neither the Pod nor its Namespace specify an explicit\n`ipam.cilium.io/*` annotation.\n\nThe selector can match on regular Pod labels and on the following synthetic\nlabels that Cilium adds for convenience:\n\nio.kubernetes.pod.namespace \u2013 the Pod's namespace\nio.kubernetes.pod.name \u2013 the Pod's name\n\nA single Pod must not match more than one pool for the same IP family.\nIf multiple pools match, IP allocation fails for that Pod and a warning event\nis emitted in the namespace of the Pod.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "enum": [
+ "In",
+ "NotIn",
+ "Exists",
+ "DoesNotExist"
+ ],
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
+ "maxLength": 63,
+ "pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/ciliumpodippool-stable-v2alpha1.json b/crdSchemas/master-standalone/ciliumpodippool-stable-v2alpha1.json
index b5afe8c..ae09cb4 100644
--- a/crdSchemas/master-standalone/ciliumpodippool-stable-v2alpha1.json
+++ b/crdSchemas/master-standalone/ciliumpodippool-stable-v2alpha1.json
@@ -14,6 +14,28 @@
},
"spec": {
"properties": {
+ "allowFirstIP": {
+ "default": false,
+ "description": "AllowFirstIP allows the first IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowFirstIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "allowLastIP": {
+ "default": false,
+ "description": "AllowLastIP allows the last IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
+ "type": "boolean",
+ "x-kubernetes-validations": [
+ {
+ "message": "allowLastIP is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
"ipv4": {
"description": "IPv4 specifies the IPv4 CIDRs and mask sizes of the pool",
"properties": {
@@ -31,7 +53,13 @@
"description": "MaskSize is the mask size of the pool.",
"maximum": 32,
"minimum": 1,
- "type": "integer"
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
}
},
"required": [
@@ -58,7 +86,13 @@
"description": "MaskSize is the mask size of the pool.",
"maximum": 128,
"minimum": 1,
- "type": "integer"
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maskSize is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
}
},
"required": [
diff --git a/crdSchemas/master-standalone/clienttrafficpolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/clienttrafficpolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..87dc29b
--- /dev/null
+++ b/crdSchemas/master-standalone/clienttrafficpolicy-stable-v1alpha1.json
@@ -0,0 +1,1662 @@
+{
+ "description": "ClientTrafficPolicy allows the user to configure the behavior of the connection\nbetween the downstream client and Envoy Proxy listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of ClientTrafficPolicy.",
+ "properties": {
+ "clientIPDetection": {
+ "description": "ClientIPDetectionSettings provides configuration for determining the original client IP address for requests.",
+ "properties": {
+ "customHeader": {
+ "description": "CustomHeader provides configuration for determining the client IP address for a request based on\na trusted custom HTTP header. This uses the custom_header original IP detection extension.\nRefer to https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/http/original_ip_detection/custom_header/v3/custom_header.proto\nfor more details.",
+ "properties": {
+ "failClosed": {
+ "description": "FailClosed is a switch used to control the flow of traffic when client IP detection\nfails. If set to true, the listener will respond with 403 Forbidden when the client\nIP address cannot be determined.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name of the header containing the original downstream remote address, if present.",
+ "maxLength": 255,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9-]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "xForwardedFor": {
+ "description": "XForwardedForSettings provides configuration for using X-Forwarded-For headers for determining the client IP address.",
+ "properties": {
+ "numTrustedHops": {
+ "description": "NumTrustedHops specifies how many trusted hops to count from the rightmost side of\nthe X-Forwarded-For (XFF) header when determining the original client\u2019s IP address.\n\nIf NumTrustedHops is set to N, the client IP is taken from the Nth address from the\nright end of the XFF header.\n\nExample:\n XFF = \"203.0.113.128, 203.0.113.10, 203.0.113.1\"\n NumTrustedHops = 2\n \u2192 Trusted client address = 203.0.113.10\n\nOnly one of NumTrustedHops or TrustedCIDRs should be configured.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "trustedCIDRs": {
+ "description": "TrustedCIDRs is a list of CIDR ranges to trust when evaluating\nthe remote IP address to determine the original client\u2019s IP address.\nWhen the remote IP address matches a trusted CIDR and the x-forwarded-for header was sent,\neach entry in the x-forwarded-for header is evaluated from right to left\nand the first public non-trusted address is used as the original client address.\nIf all addresses in x-forwarded-for are within the trusted list, the first (leftmost) entry is used.\nOnly one of NumTrustedHops and TrustedCIDRs must be set.",
+ "items": {
+ "description": "CIDR defines a CIDR Address range.\nA CIDR can be an IPv4 address range such as \"192.168.1.0/24\" or an IPv6 address range such as \"2001:0db8:11a3:09d7::/64\".",
+ "pattern": "((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]+))|((([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))\\/([0-9]+))",
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of numTrustedHops or trustedCIDRs must be set",
+ "rule": "(has(self.numTrustedHops) && !has(self.trustedCIDRs)) || (!has(self.numTrustedHops) && has(self.trustedCIDRs))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "customHeader cannot be used in conjunction with xForwardedFor",
+ "rule": "!(has(self.xForwardedFor) && has(self.customHeader))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes client connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit provides configuration for the maximum buffer size in bytes for each incoming connection.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 32768 bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "connectionLimit": {
+ "description": "ConnectionLimit defines limits related to connections",
+ "properties": {
+ "closeDelay": {
+ "description": "CloseDelay defines the delay to use before closing connections that are rejected\nonce the limit value is reached.\nDefault: none.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "MaxConnectionDuration is the maximum amount of time a connection can remain established\n(usually via TCP/HTTP Keepalive packets) before being drained and/or closed.\nIf not specified, there is no limit.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxRequestsPerConnection": {
+ "description": "MaxRequestsPerConnection defines the maximum number of requests allowed over a single connection.\nIf not specified, there is no limit. Setting this parameter to 1 will effectively disable keep alive.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum amount of time to keep alive an http stream. When the limit is reached\nthe stream will be reset independent of any other timeouts. If not specified, no value is set.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the maximum concurrent connections limit.\nWhen the limit is reached, incoming connections will be closed after the CloseDelay duration.",
+ "format": "int64",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "closeDelay can only be configured when value is set",
+ "rule": "!has(self.closeDelay) || has(self.value)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxAcceptPerSocketEvent": {
+ "default": 1,
+ "description": "MaxAcceptPerSocketEvent provides configuration for the maximum number of connections to accept from the kernel\nper socket event. If there are more than MaxAcceptPerSocketEvent connections pending accept, connections over\nthis threshold will be accepted in later event loop iterations.\nDefaults to 1 and can be disabled by setting to 0 for allowing unlimited accepted connections.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each incoming socket.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "enableProxyProtocol": {
+ "description": "EnableProxyProtocol interprets the ProxyProtocol header and adds the\nClient Address into the X-Forwarded-For header.\nNote Proxy Protocol must be present when this field is set, else the connection\nis closed.\n\nDeprecated: Use ProxyProtocol instead.",
+ "type": "boolean"
+ },
+ "grpc": {
+ "description": "GRPC provides gRPC configuration on the listener.",
+ "properties": {
+ "enableWeb": {
+ "description": "EnableWeb configures the gRPC-web filter on the listener.\nThe gRPC-web filter allows clients (typically browsers) to make gRPC calls\nusing HTTP/1.1 or HTTP/2.\n\nThis is enabled by default for GRPCRoute and opt-in for HTTPRoute.\nIn general, gRPC traffic should be handled via GRPCRoute, but there are cases where\nusers want to route gRPC using HTTPRoute for its richer matching capabilities.\nTherefore, we enable this behavior only when it is explicitly opted in.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "HeaderSettings provides configuration for header management.",
+ "properties": {
+ "disableRateLimitHeaders": {
+ "description": "DisableRateLimitHeaders configures Envoy Proxy to omit the \"X-RateLimit-\" response headers\nwhen rate limiting is enabled.",
+ "type": "boolean"
+ },
+ "earlyRequestHeaders": {
+ "description": "EarlyRequestHeaders defines settings for early request header modification, before envoy performs\nrouting, tracing and built-in header manipulation.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "addIfAbsent": {
+ "description": "AddIfAbsent adds the given header(s) (name, value) to the request/response\nonly if the header does not already exist. Unlike Add which appends to\nexisting values, this is a no-op if the header is already present.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n addIfAbsent:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "removeOnMatch": {
+ "description": "RemoveOnMatch removes headers whose names match the specified string matchers.\nMatching is performed on the header name (case-insensitive).",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "enableEnvoyHeaders": {
+ "description": "EnableEnvoyHeaders configures Envoy Proxy to add the \"X-Envoy-\" headers to requests\nand responses.",
+ "type": "boolean"
+ },
+ "lateResponseHeaders": {
+ "description": "LateResponseHeaders defines settings for global response header modification.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "addIfAbsent": {
+ "description": "AddIfAbsent adds the given header(s) (name, value) to the request/response\nonly if the header does not already exist. Unlike Add which appends to\nexisting values, this is a no-op if the header is already present.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n addIfAbsent:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "removeOnMatch": {
+ "description": "RemoveOnMatch removes headers whose names match the specified string matchers.\nMatching is performed on the header name (case-insensitive).",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "preserveXRequestID": {
+ "description": "PreserveXRequestID configures Envoy to keep the X-Request-ID header if passed for a request that is edge\n(Edge request is the request from external clients to front Envoy) and not reset it, which is the current Envoy behaviour.\nDefaults to false and cannot be combined with RequestID.\n\nDeprecated: use RequestID=PreserveOrGenerate instead",
+ "type": "boolean"
+ },
+ "requestID": {
+ "description": "RequestID configures Envoy's behavior for handling the `X-Request-ID` header.\nWhen omitted default behavior is `Generate` which builds the `X-Request-ID` for every request\n and ignores pre-existing values from the edge.\n(An \"edge request\" refers to a request from an external client to the Envoy entrypoint.)",
+ "enum": [
+ "PreserveOrGenerate",
+ "Preserve",
+ "Generate",
+ "Disable"
+ ],
+ "type": "string"
+ },
+ "withUnderscoresAction": {
+ "description": "WithUnderscoresAction configures the action to take when an HTTP header with underscores\nis encountered. The default action is to reject the request.",
+ "enum": [
+ "Allow",
+ "RejectRequest",
+ "DropHeader"
+ ],
+ "type": "string"
+ },
+ "xForwardedClientCert": {
+ "description": "XForwardedClientCert configures how Envoy Proxy handle the x-forwarded-client-cert (XFCC) HTTP header.\n\nx-forwarded-client-cert (XFCC) is an HTTP header used to forward the certificate\ninformation of part or all of the clients or proxies that a request has flowed through,\non its way from the client to the server.\n\nEnvoy proxy may choose to sanitize/append/forward the XFCC header before proxying the request.\n\nIf not set, the default behavior is sanitizing the XFCC header.",
+ "properties": {
+ "certDetailsToAdd": {
+ "description": "CertDetailsToAdd specifies the fields in the client certificate to be forwarded in the XFCC header.\n\nHash(the SHA 256 digest of the current client certificate) and By(the Subject Alternative Name)\nare always included if the client certificate is forwarded.\n\nThis field is only applicable when the mode is set to `AppendForward` or\n`SanitizeSet` and the client connection is mTLS.",
+ "items": {
+ "description": "XFCCCertData specifies the fields in the client certificate to be forwarded in the XFCC header.",
+ "enum": [
+ "Subject",
+ "Cert",
+ "Chain",
+ "DNS",
+ "URI"
+ ],
+ "type": "string"
+ },
+ "maxItems": 5,
+ "type": "array"
+ },
+ "mode": {
+ "description": "Mode defines how XFCC header is handled by Envoy Proxy.\nIf not set, the default mode is `Sanitize`.",
+ "enum": [
+ "Sanitize",
+ "ForwardOnly",
+ "AppendForward",
+ "SanitizeSet",
+ "AlwaysForwardOnly"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "certDetailsToAdd can only be set when mode is AppendForward or SanitizeSet",
+ "rule": "(has(self.certDetailsToAdd) && self.certDetailsToAdd.size() > 0) ? (self.mode == 'AppendForward' || self.mode == 'SanitizeSet') : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "preserveXRequestID and requestID cannot both be set.",
+ "rule": "!(has(self.preserveXRequestID) && has(self.requestID))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck provides configuration for determining whether the HTTP/HTTPS listener is healthy.",
+ "properties": {
+ "path": {
+ "description": "Path specifies the HTTP path to match on for health check requests.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http1": {
+ "description": "HTTP1 provides HTTP/1 configuration on the listener.",
+ "properties": {
+ "disableSafeMaxConnectionDuration": {
+ "description": "DisableSafeMaxConnectionDuration controls the close behavior for HTTP/1 connections.\nBy default, connection closure is delayed until the next request arrives after maxConnectionDuration is exceeded.\nIt then adds a Connection: close header and gracefully closes the connection after the response completes.\nWhen set to true (disabled), Envoy uses its default drain behavior, closing the connection shortly after maxConnectionDuration elapses.\nHas no effect unless maxConnectionDuration is set.",
+ "type": "boolean"
+ },
+ "enableTrailers": {
+ "description": "EnableTrailers defines if HTTP/1 trailers should be proxied by Envoy.",
+ "type": "boolean"
+ },
+ "http10": {
+ "description": "HTTP10 turns on support for HTTP/1.0 and HTTP/0.9 requests.",
+ "properties": {
+ "useDefaultHost": {
+ "description": "UseDefaultHost specifies whether a default Host header should be injected\ninto HTTP/1.0 requests that do not include one.\n\nWhen set to true, Envoy Gateway injects the hostname associated with the\nlistener or route into the request, in the following order:\n\n 1. If the targeted listener has a non-wildcard hostname, use that hostname.\n 2. If there is exactly one HTTPRoute with a non-wildcard hostname under\n the targeted listener, use that hostname.\n\n Note: Setting this field to true without a non-wildcard hostname makes the\nClientTrafficPolicy invalid.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ignoredUpgradeTypes": {
+ "description": "IgnoredUpgradeTypes specifies a list of upgrade types for which\nHTTP/1.1 Upgrade requests should be ignored by Envoy instead of being\nrejected with a 403 response. When a client sends an HTTP/1.1 request\nwith Connection: Upgrade and an Upgrade header matching one of these\nmatchers, Envoy will strip the upgrade headers and process the request\nas a normal HTTP/1.1 request.\n\nExample: To ignore TLS upgrade requests (RFC 2817), use a Prefix match with value \"TLS/\".",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "preserveHeaderCase": {
+ "description": "PreserveHeaderCase defines if Envoy should preserve the letter case of headers.\nBy default, Envoy will lowercase all the headers.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration on the listener.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http3": {
+ "description": "HTTP3 provides HTTP/3 configuration on the listener.",
+ "type": "object"
+ },
+ "path": {
+ "description": "Path enables managing how the incoming path set by clients can be normalized.",
+ "properties": {
+ "disableMergeSlashes": {
+ "description": "DisableMergeSlashes allows disabling the default configuration of merging adjacent\nslashes in the path.\nNote that slash merging is not part of the HTTP spec and is provided for convenience.",
+ "type": "boolean"
+ },
+ "escapedSlashesAction": {
+ "description": "EscapedSlashesAction determines how %2f, %2F, %5c, or %5C sequences in the path URI\nshould be handled.\nThe default is UnescapeAndRedirect.",
+ "enum": [
+ "KeepUnchanged",
+ "RejectRequest",
+ "UnescapeAndForward",
+ "UnescapeAndRedirect"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol configures the Proxy Protocol settings. When configured,\nthe Proxy Protocol header will be interpreted and the Client Address\nwill be added into the X-Forwarded-For header.\nIf both EnableProxyProtocol and ProxyProtocol are set, ProxyProtocol takes precedence.",
+ "minProperties": 0,
+ "properties": {
+ "optional": {
+ "description": "Optional allows requests without a Proxy Protocol header to be proxied.\nIf set to true, the listener will accept requests without a Proxy Protocol header.\nIf set to false, the listener will reject requests without a Proxy Protocol header.\nIf not set, the default behavior is to reject requests without a Proxy Protocol header.\nWarning: Optional breaks conformance with the specification. Only enable if ALL traffic to the listener comes from a trusted source.\nFor more information on security implications, see haproxy.org/download/2.1/doc/proxy-protocol.txt",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scheme": {
+ "description": "Scheme configures how the :scheme pseudo-header is set for requests forwarded to backends.\n\n- Preserve (default): Preserves the :scheme from the original client request.\n Use this when backends need to know the original client scheme for URL generation or redirects.\n\n- MatchBackend: Sets the :scheme to match the backend transport protocol.\n If the backend uses TLS, the scheme is \"https\", otherwise \"http\".\n Use this when backends require the scheme to match the actual transport protocol,\n such as strictly HTTPS services that validate the :scheme header.",
+ "enum": [
+ "Preserve",
+ "MatchBackend"
+ ],
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the downstream client connection.\nIf defined, sets SO_KEEPALIVE on the listener socket to enable TCP Keepalives.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the client connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "idleTimeout": {
+ "description": "IdleTimeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestReceivedTimeout": {
+ "description": "RequestReceivedTimeout is the duration envoy waits for the complete request reception. This timer starts upon request\ninitiation and stops when either the last byte of the request is sent upstream or when the response begins.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n Default: 5 minutes.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "idleTimeout": {
+ "description": "IdleTimeout for a TCP connection. Idle time is defined as a period in which there are no\nbytes sent or received on either the upstream or downstream connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tls": {
+ "description": "TLS settings configure TLS termination settings with the downstream client.",
+ "properties": {
+ "alpnProtocols": {
+ "description": "ALPNProtocols supplies the list of ALPN protocols that should be\nexposed by the listener or used by the proxy to connect to the backend.\nDefaults:\n1. HTTPS Routes: h2 and http/1.1 are enabled in listener context.\n2. Other Routes: ALPN is disabled.\n3. Backends: proxy uses the appropriate ALPN options for the backend protocol.\nWhen an empty list is provided, the ALPN TLS extension is disabled.\n\nDefaults to [h2, http/1.1] if not specified.\n\nTypical Supported values are:\n- http/1.0\n- http/1.1\n- h2",
+ "items": {
+ "description": "ALPNProtocol specifies the protocol to be negotiated using ALPN",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "ciphers": {
+ "description": "Ciphers specifies the set of cipher suites supported when\nnegotiating TLS 1.0 - 1.2. This setting has no effect for TLS 1.3.\nFor Envoy TLS cipher suite configuration semantics and default cipher\nlists, see the Envoy documentation:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/transport_sockets/tls/v3/common.proto#extensions-transport-sockets-tls-v3-tlsparameters\nSupported cipher suite names:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\n- ECDHE-ECDSA-CHACHA20-POLY1305\n- ECDHE-RSA-CHACHA20-POLY1305\n- ECDHE-ECDSA-AES128-SHA\n- ECDHE-RSA-AES128-SHA\n- AES128-GCM-SHA256\n- AES128-SHA\n- ECDHE-ECDSA-AES256-SHA\n- ECDHE-RSA-AES256-SHA\n- AES256-GCM-SHA384\n- AES256-SHA\nSupported IANA/RFC aliases:\n- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\n- TLS_RSA_WITH_AES_128_GCM_SHA256\n- TLS_RSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\n- TLS_RSA_WITH_AES_256_GCM_SHA384\n- TLS_RSA_WITH_AES_256_CBC_SHA\nIn non-FIPS Envoy Proxy builds the default cipher list is:\n- [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]\n- [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\nIn builds using BoringSSL FIPS the default cipher list is:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "clientValidation": {
+ "description": "ClientValidation specifies the configuration to validate the client\ninitiating the TLS connection to the Gateway listener.",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to\nKubernetes objects that contain TLS certificates of\nthe Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the client.\n\nA single reference to a Kubernetes ConfigMap or a Kubernetes Secret,\nwith the CA certificate in a key named `ca.crt` is currently supported.\n\nReferences to a resource in different namespace are invalid UNLESS there\nis a ReferenceGrant in the target namespace that allows the certificate\nto be attached.",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "certificateHashes": {
+ "description": "An optional list of hex-encoded SHA-256 hashes. If specified, Envoy will\nverify that the SHA-256 of the DER-encoded presented certificate matches\none of the specified values.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "crl": {
+ "description": "Crl specifies the crl configuration that can be used to validate the client initiating the TLS connection",
+ "properties": {
+ "onlyVerifyLeafCertificate": {
+ "description": "If this option is set to true, Envoy will only verify the certificate at the end of the certificate chain against the CRL.\nDefaults to false, which will verify the entire certificate chain against the CRL.",
+ "type": "boolean"
+ },
+ "refs": {
+ "description": "Refs contains one or more references to a Kubernetes ConfigMap or a Kubernetes Secret,\ncontaining the certificate revocation list in PEM format\nExpects the content in a key named `ca.crl`.\n\nReferences to a resource in different namespace are invalid UNLESS there\nis a ReferenceGrant in the target namespace that allows the crl\nto be attached.",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "refs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Mode defines how the Gateway or Listener validates client certificates.\nIf not specified, defaults to RequireAndVerify.",
+ "enum": [
+ "Request",
+ "RequireAny",
+ "VerifyIfGiven",
+ "RequireAndVerify"
+ ],
+ "type": "string"
+ },
+ "optional": {
+ "description": "Optional set to true accepts connections even when a client doesn't present a certificate.\nDefaults to false, which rejects connections without a valid client certificate.\n\nDeprecated: Use Mode instead.",
+ "type": "boolean"
+ },
+ "spkiHashes": {
+ "description": "An optional list of base64-encoded SHA-256 hashes. If specified, Envoy will\nverify that the SHA-256 of the DER-encoded Subject Public Key Information\n(SPKI) of the presented certificate matches one of the specified values.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "subjectAltNames": {
+ "description": "An optional list of Subject Alternative name matchers. If specified, Envoy\nwill verify that the Subject Alternative Name of the presented certificate\nmatches one of the specified matchers",
+ "properties": {
+ "dnsNames": {
+ "description": "DNS names matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "emailAddresses": {
+ "description": "Email addresses matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "ipAddresses": {
+ "description": "IP addresses matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "otherNames": {
+ "description": "Other names matchers",
+ "items": {
+ "properties": {
+ "oid": {
+ "description": "OID Value",
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "oid",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "uris": {
+ "description": "URIs matchers",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ecdhCurves": {
+ "description": "ECDHCurves specifies the set of supported ECDH curves.\nIn non-FIPS Envoy Proxy builds the default curves are:\n- X25519\n- P-256\nIn builds using BoringSSL FIPS the default curve is:\n- P-256",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "fingerprints": {
+ "description": "Fingerprints specifies TLS client fingerprinting.\nWhen specified, a JAX fingerprint derived from the client\u2019s TLS handshake\nis generated. The fingerprint can be logged in access logs or\nforwarded to upstream services using request headers.\n\nFingerprinting is disabled if not specified.\n\nSupported values are:\n- JA3\n- JA4",
+ "items": {
+ "description": "TLSFingerprintType specifies the TLS client fingerprinting mode.",
+ "enum": [
+ "JA3",
+ "JA4"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "maxVersion": {
+ "description": "Max specifies the maximal TLS protocol version to allow\nThe default is TLS 1.3 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "minVersion": {
+ "description": "Min specifies the minimal TLS protocol version to allow.\nThe default is TLS 1.2 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "session": {
+ "description": "Session defines settings related to TLS session management.",
+ "properties": {
+ "resumption": {
+ "description": "Resumption determines the proxy's supported TLS session resumption option.\nBy default, Envoy Gateway does not enable session resumption. Use sessionResumption to\nenable stateful and stateless session resumption. Users should consider security impacts\nof different resumption methods. Performance gains from resumption are diminished when\nEnvoy proxy is deployed with more than one replica.",
+ "properties": {
+ "stateful": {
+ "description": "Stateful defines setting for stateful (session-id based) session resumption",
+ "type": "object"
+ },
+ "stateless": {
+ "description": "Stateless defines setting for stateless (session-ticket based) session resumption",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "signatureAlgorithms": {
+ "description": "SignatureAlgorithms specifies which signature algorithms the listener should\nsupport.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "setting ciphers has no effect if the minimum possible TLS version is 1.3",
+ "rule": "has(self.minVersion) && self.minVersion == '1.3' ? !has(self.ciphers) : true"
+ },
+ {
+ "message": "minVersion must be smaller or equal to maxVersion",
+ "rule": "has(self.minVersion) && has(self.maxVersion) ? {\"Auto\":0,\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4}[self.minVersion] <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : !has(self.minVersion) && has(self.maxVersion) ? 3 <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true"
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway",
+ "rule": "has(self.targetRef) ? self.targetRef.kind == 'Gateway' : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind == 'Gateway') : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of ClientTrafficPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/cloudflareaccessapplication-stable-v1alpha1.json b/crdSchemas/master-standalone/cloudflareaccessapplication-stable-v1alpha1.json
new file mode 100644
index 0000000..20461ba
--- /dev/null
+++ b/crdSchemas/master-standalone/cloudflareaccessapplication-stable-v1alpha1.json
@@ -0,0 +1,733 @@
+{
+ "description": "CloudflareAccessApplication binds Gateway API targets to reusable Cloudflare Access policies.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareAccessApplicationSpec defines Gateway API target bindings to reusable Access policies.",
+ "properties": {
+ "application": {
+ "description": "Application defines Access Application settings shared by generated apps.\nThe path field overrides any path derived from HTTPRoute rules.",
+ "properties": {
+ "allowedIdps": {
+ "description": "AllowedIdps restricts which identity providers can authenticate.\nValues are Cloudflare Identity Provider UUIDs.\nWhen empty, all IdPs configured in the account are allowed.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 25,
+ "type": "array"
+ },
+ "appLauncherVisible": {
+ "default": true,
+ "description": "AppLauncherVisible controls whether the application appears in the\nCloudflare App Launcher dashboard. Use pointer to distinguish\nexplicit false (hidden) from absent (default visible).",
+ "type": "boolean"
+ },
+ "autoRedirectToIdentity": {
+ "description": "AutoRedirectToIdentity auto-redirects to the identity provider\nwhen a single IdP is configured in allowedIdps. Skips the IdP\nselection page.",
+ "type": "boolean"
+ },
+ "corsHeaders": {
+ "description": "CORSHeaders configures CORS for browser-based APIs behind Access.\nWhen set, Cloudflare responds to OPTIONS preflight on behalf of the origin.\nMutually exclusive with optionsPreflightBypass.",
+ "properties": {
+ "allowAllHeaders": {
+ "description": "AllowAllHeaders allows all HTTP request headers.",
+ "type": "boolean"
+ },
+ "allowAllMethods": {
+ "description": "AllowAllMethods allows all HTTP request methods.",
+ "type": "boolean"
+ },
+ "allowAllOrigins": {
+ "description": "AllowAllOrigins allows all origins.",
+ "type": "boolean"
+ },
+ "allowCredentials": {
+ "description": "AllowCredentials includes credentials (cookies, authorization headers,\nor TLS client certificates) with CORS requests.",
+ "type": "boolean"
+ },
+ "allowedHeaders": {
+ "description": "AllowedHeaders lists specific allowed HTTP request headers.\nIgnored when allowAllHeaders is true.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ },
+ "allowedMethods": {
+ "description": "AllowedMethods lists specific allowed HTTP request methods.\nIgnored when allowAllMethods is true.",
+ "items": {
+ "description": "CORSAllowedMethod is an HTTP method allowed for CORS requests.",
+ "enum": [
+ "GET",
+ "POST",
+ "HEAD",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array"
+ },
+ "allowedOrigins": {
+ "description": "AllowedOrigins lists specific allowed origins.\nIgnored when allowAllOrigins is true.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ },
+ "maxAge": {
+ "description": "MaxAge is the maximum number of seconds preflight results can be cached.",
+ "maximum": 86400,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "customDenyMessage": {
+ "description": "CustomDenyMessage shown when access is denied.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "customDenyUrl": {
+ "description": "CustomDenyURL redirects to this URL when denied (instead of message).",
+ "type": "string"
+ },
+ "customNonIdentityDenyUrl": {
+ "description": "CustomNonIdentityDenyURL is the URL users are redirected to when\ndenied by a non-identity (service auth) policy. Separate from\ncustomDenyUrl which handles identity-based denials.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "domain": {
+ "description": "Domain is the protected domain (auto-generated from routes if omitted).\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)",
+ "rule": "self == '' || self.split('.').all(s, size(s) <= 63)"
+ }
+ ]
+ },
+ "enableBindingCookie": {
+ "default": false,
+ "description": "EnableBindingCookie enables binding cookies for sticky sessions.",
+ "type": "boolean"
+ },
+ "httpOnlyCookieAttribute": {
+ "default": true,
+ "description": "HttpOnlyCookieAttribute adds HttpOnly to session cookies.",
+ "type": "boolean"
+ },
+ "logoUrl": {
+ "description": "LogoURL is the application logo in dashboard.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the display name in Cloudflare dashboard.\nDefaults to CR name if omitted.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "optionsPreflightBypass": {
+ "description": "OptionsPreflightBypass allows OPTIONS preflight requests to bypass\nAccess authentication and go directly to the origin. Enabling this\nremoves all CORS header settings. Mutually exclusive with corsHeaders.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "Path restricts protection to a specific absolute path prefix.\nCloudflare Access paths must not include query strings or fragments.",
+ "maxLength": 1024,
+ "pattern": "^/[^?#]*$",
+ "type": "string"
+ },
+ "pathCookieAttribute": {
+ "description": "PathCookieAttribute scopes the Access JWT cookie to the application\npath instead of the hostname. When enabled, users must re-authenticate\nfor different paths on the same hostname.",
+ "type": "boolean"
+ },
+ "readServiceTokensFromHeader": {
+ "description": "ReadServiceTokensFromHeader enables reading service tokens from a\nsingle custom HTTP header instead of the standard CF-Access-Client-Id\nand CF-Access-Client-Secret header pair. The value is the header name.\nThe header value must contain a JSON object with \"cf-access-client-id\"\nand \"cf-access-client-secret\" keys.",
+ "maxLength": 256,
+ "type": "string"
+ },
+ "sameSiteCookieAttribute": {
+ "default": "lax",
+ "description": "SameSiteCookieAttribute controls cross-site cookie behavior.",
+ "enum": [
+ "strict",
+ "lax",
+ "none"
+ ],
+ "type": "string"
+ },
+ "serviceAuth401Redirect": {
+ "description": "ServiceAuth401Redirect returns a 401 status code instead of\nredirecting to the Access login page when a request is blocked by a\nService Auth (non_identity) policy. Enable for API consumers.",
+ "type": "boolean"
+ },
+ "sessionDuration": {
+ "default": "24h",
+ "description": "SessionDuration controls session cookie lifetime.",
+ "pattern": "^([0-9]+(ns|us|ms|s|m|h))+$",
+ "type": "string"
+ },
+ "skipInterstitial": {
+ "default": false,
+ "description": "SkipInterstitial bypasses the Access login page for API requests.",
+ "type": "boolean"
+ },
+ "type": {
+ "default": "self_hosted",
+ "description": "Type is the application type.",
+ "enum": [
+ "self_hosted"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "corsHeaders and optionsPreflightBypass are mutually exclusive",
+ "rule": "!(has(self.corsHeaders) && has(self.optionsPreflightBypass) && self.optionsPreflightBypass)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "cloudflareRef": {
+ "description": "CloudflareRef references Cloudflare credentials. When omitted, credentials\nare inherited from each target's route -> Gateway -> CloudflareTunnel chain.\nMultiple targets must inherit the same Cloudflare account.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare account name (looked up via API).",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the secret containing credentials.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret (defaults to policy namespace).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "policyRefs": {
+ "description": "PolicyRefs lists reusable CloudflareAccessPolicy resources to attach.",
+ "items": {
+ "description": "AccessPolicyReference references a reusable CloudflareAccessPolicy.",
+ "properties": {
+ "name": {
+ "description": "Name is the CloudflareAccessPolicy name.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "default": "",
+ "description": "Namespace is the CloudflareAccessPolicy namespace. Empty defaults to application namespace.\nCross-namespace references require ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "precedence": {
+ "description": "Precedence determines policy evaluation order for the application. Lower values run first.\nWhen omitted, the controller uses list order starting at 1.",
+ "maximum": 9999,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name",
+ "namespace"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "targetRef": {
+ "description": "TargetRef identifies a single Gateway API target.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs identifies multiple Gateway API targets.",
+ "items": {
+ "description": "PolicyTargetReference identifies a Gateway API resource for Access application attachment.\n\nPolicyTargetReference follows the Gateway API LocalPolicyTargetReferenceWithSectionName\npattern. It targets Gateway API Gateway and HTTPRoute resources and extracts\nhostnames and paths from those resources to create corresponding Cloudflare Access\napplications.\n\nCross-namespace references require a ReferenceGrant in the target namespace that permits\nCloudflareAccessApplication resources from the application's namespace.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "policyRefs"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be specified",
+ "rule": "has(self.targetRef) || has(self.targetRefs)"
+ },
+ {
+ "message": "targetRef and targetRefs are mutually exclusive",
+ "rule": "!(has(self.targetRef) && has(self.targetRefs))"
+ },
+ {
+ "message": "policyRefs must either all omit precedence or all specify precedence",
+ "rule": "self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p, has(p.precedence))"
+ },
+ {
+ "message": "policyRefs precedence values must be unique",
+ "rule": "self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p, has(p.precedence) && self.policyRefs.exists_one(q, has(q.precedence) && q.precedence == p.precedence))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareAccessApplicationStatus defines observed Access application state.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the resolved Cloudflare account ID used for Access application cleanup.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "ancestors": {
+ "description": "Ancestors contains status for each targetRef.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the policy attachment status for a specific target.\n\nPolicyAncestorStatus follows the Gateway API PolicyAncestorStatus pattern to report\nper-target attachment status. Each target reference in the spec has a corresponding\nancestor status entry showing whether the policy was successfully attached.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef identifies the target.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions for this specific target.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "controllerName": {
+ "description": "ControllerName identifies the controller managing this attachment.",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "applications": {
+ "description": "Applications are Cloudflare Access Applications managed by this resource.",
+ "items": {
+ "description": "AccessApplicationObserved records a Cloudflare Access Application created for one host/path target.",
+ "properties": {
+ "aud": {
+ "description": "AUD is the Application Audience Tag.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "domain": {
+ "description": "Domain is the protected hostname/path in Cloudflare.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "id": {
+ "description": "ID is the Cloudflare Access Application ID.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "targetRef": {
+ "description": "TargetRef identifies the Gateway API target that produced this application.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the API group of the target resource.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the target resource.",
+ "enum": [
+ "Gateway",
+ "HTTPRoute"
+ ],
+ "maxLength": 63,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the target resource.\nCross-namespace targeting requires ReferenceGrant.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName targets specific listener (Gateway) or rule (Route).",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "self.group == 'gateway.networking.k8s.io'"
+ },
+ {
+ "message": "kind must be Gateway or HTTPRoute",
+ "rule": "self.kind in ['Gateway', 'HTTPRoute']"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array"
+ },
+ "attachedTargets": {
+ "description": "AttachedTargets is the count of successfully attached Gateway API targets.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "conditions": {
+ "description": "Conditions describe current state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "credentialSecretRef": {
+ "description": "CredentialSecretRef is the resolved credentials Secret used for cleanup.\nThe namespace is always stored explicitly.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the last generation processed.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/cloudflareaccesspolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/cloudflareaccesspolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..23424ca
--- /dev/null
+++ b/crdSchemas/master-standalone/cloudflareaccesspolicy-stable-v1alpha1.json
@@ -0,0 +1,1014 @@
+{
+ "description": "CloudflareAccessPolicy is the Schema for the cloudflareaccesspolicies API.\n\nCloudflareAccessPolicy manages a reusable account-level Cloudflare Access Policy.\nCloudflareAccessApplication attaches reusable policies to Gateway API targets.\n\nAccess rules are organized into implementation tiers based on IdP requirements:\n - P0: IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken (no IdP)\n - P1: Email, EmailList, EmailDomain, OIDCClaim (basic IdP required)\n - P2: GSuiteGroup (Google Workspace required)\n - P3: not in current product scope (Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.)\n\nStatus conditions:\n - Ready: policy is synced and service tokens are ready when configured\n - CredentialsValid: Cloudflare credentials have been validated\n - ServiceTokensReady: all service tokens have been created\n - PolicySynced: reusable Access policy exists in Cloudflare",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareAccessPolicySpec defines a reusable Cloudflare Access policy.\n\nCloudflareAccessPolicySpec manages account-level reusable Access policies. Applications\nattach these policies through CloudflareAccessApplication policyRefs.",
+ "properties": {
+ "approvalGroups": {
+ "description": "ApprovalGroups defines who can approve access.",
+ "items": {
+ "description": "ApprovalGroup defines who can approve access requests for approval-required policies.\n\nApprovalGroup specifies approvers by email address or email list UUID. When a\npolicy requires approval, users matching this group can approve or deny access requests.",
+ "properties": {
+ "approvalsNeeded": {
+ "default": 1,
+ "description": "ApprovalsNeeded is number of approvals required.",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "emailListUuid": {
+ "description": "EmailListUUID is a Cloudflare Access email list UUID whose members can approve.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "emails": {
+ "description": "Emails of approvers.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one approver (emails or emailListUuid) must be specified",
+ "rule": "(has(self.emails) && size(self.emails) > 0) || has(self.emailListUuid)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "approvalRequired": {
+ "default": false,
+ "description": "ApprovalRequired requires approval from specific users.",
+ "type": "boolean"
+ },
+ "cloudflareRef": {
+ "description": "CloudflareRef references Cloudflare credentials.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare account name (looked up via API).",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the secret containing credentials.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret (defaults to policy namespace).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "decision": {
+ "default": "allow",
+ "description": "Decision is the policy action.",
+ "enum": [
+ "allow",
+ "deny",
+ "bypass",
+ "non_identity"
+ ],
+ "type": "string"
+ },
+ "exclude": {
+ "description": "Exclude rules (if ANY match, policy does not apply).",
+ "items": {
+ "description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
+ "properties": {
+ "anyValidServiceToken": {
+ "description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
+ "type": "boolean"
+ },
+ "country": {
+ "description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
+ "properties": {
+ "codes": {
+ "description": "Codes are ISO 3166-1 alpha-2 country codes.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "codes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "email": {
+ "description": "Email matches specific email addresses.\nSDK: EmailRule",
+ "properties": {
+ "addresses": {
+ "description": "Addresses to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "addresses"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailDomain": {
+ "description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
+ "properties": {
+ "domain": {
+ "description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "domain"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailList": {
+ "description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the Access list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "everyone": {
+ "description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
+ "type": "boolean"
+ },
+ "group": {
+ "description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
+ "properties": {
+ "id": {
+ "description": "ID is the Cloudflare Access Group ID.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "id"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gsuiteGroup": {
+ "description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
+ "properties": {
+ "email": {
+ "description": "Email is the Google Workspace group email.",
+ "maxLength": 320,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "email",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ip": {
+ "description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
+ "properties": {
+ "ranges": {
+ "description": "Ranges are CIDR blocks (IPv4 or IPv6).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "ranges"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipList": {
+ "description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the IP list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "oidcClaim": {
+ "description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
+ "properties": {
+ "claimName": {
+ "description": "ClaimName is the OIDC claim to match.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "claimValue": {
+ "description": "ClaimValue is the expected value.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "claimName",
+ "claimValue",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "serviceToken": {
+ "description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
+ "properties": {
+ "name": {
+ "description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "tokenId": {
+ "description": "TokenID is the Cloudflare service token ID.",
+ "maxLength": 36,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tokenId or name must be specified",
+ "rule": "has(self.tokenId) || has(self.name)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one rule type must be specified",
+ "rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 25,
+ "type": "array"
+ },
+ "include": {
+ "description": "Include rules (ANY must match for policy to apply).",
+ "items": {
+ "description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
+ "properties": {
+ "anyValidServiceToken": {
+ "description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
+ "type": "boolean"
+ },
+ "country": {
+ "description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
+ "properties": {
+ "codes": {
+ "description": "Codes are ISO 3166-1 alpha-2 country codes.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "codes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "email": {
+ "description": "Email matches specific email addresses.\nSDK: EmailRule",
+ "properties": {
+ "addresses": {
+ "description": "Addresses to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "addresses"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailDomain": {
+ "description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
+ "properties": {
+ "domain": {
+ "description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "domain"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailList": {
+ "description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the Access list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "everyone": {
+ "description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
+ "type": "boolean"
+ },
+ "group": {
+ "description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
+ "properties": {
+ "id": {
+ "description": "ID is the Cloudflare Access Group ID.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "id"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gsuiteGroup": {
+ "description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
+ "properties": {
+ "email": {
+ "description": "Email is the Google Workspace group email.",
+ "maxLength": 320,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "email",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ip": {
+ "description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
+ "properties": {
+ "ranges": {
+ "description": "Ranges are CIDR blocks (IPv4 or IPv6).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "ranges"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipList": {
+ "description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the IP list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "oidcClaim": {
+ "description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
+ "properties": {
+ "claimName": {
+ "description": "ClaimName is the OIDC claim to match.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "claimValue": {
+ "description": "ClaimValue is the expected value.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "claimName",
+ "claimValue",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "serviceToken": {
+ "description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
+ "properties": {
+ "name": {
+ "description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "tokenId": {
+ "description": "TokenID is the Cloudflare service token ID.",
+ "maxLength": 36,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tokenId or name must be specified",
+ "rule": "has(self.tokenId) || has(self.name)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one rule type must be specified",
+ "rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 25,
+ "minItems": 1,
+ "type": "array"
+ },
+ "name": {
+ "description": "Name is the Cloudflare Access policy display name.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "purposeJustificationPrompt": {
+ "description": "PurposeJustificationPrompt is the prompt shown to user.",
+ "maxLength": 1024,
+ "type": "string"
+ },
+ "purposeJustificationRequired": {
+ "default": false,
+ "description": "PurposeJustificationRequired requires user to provide justification.",
+ "type": "boolean"
+ },
+ "require": {
+ "description": "Require rules (ALL must match for policy to apply).",
+ "items": {
+ "description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
+ "properties": {
+ "anyValidServiceToken": {
+ "description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
+ "type": "boolean"
+ },
+ "country": {
+ "description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
+ "properties": {
+ "codes": {
+ "description": "Codes are ISO 3166-1 alpha-2 country codes.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "codes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "email": {
+ "description": "Email matches specific email addresses.\nSDK: EmailRule",
+ "properties": {
+ "addresses": {
+ "description": "Addresses to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "addresses"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailDomain": {
+ "description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
+ "properties": {
+ "domain": {
+ "description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "domain"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emailList": {
+ "description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the Access list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "everyone": {
+ "description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
+ "type": "boolean"
+ },
+ "group": {
+ "description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
+ "properties": {
+ "id": {
+ "description": "ID is the Cloudflare Access Group ID.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "id"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gsuiteGroup": {
+ "description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
+ "properties": {
+ "email": {
+ "description": "Email is the Google Workspace group email.",
+ "maxLength": 320,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "email",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ip": {
+ "description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
+ "properties": {
+ "ranges": {
+ "description": "Ranges are CIDR blocks (IPv4 or IPv6).",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "ranges"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipList": {
+ "description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
+ "properties": {
+ "id": {
+ "description": "ID of the IP list in Cloudflare.",
+ "maxLength": 36,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "id must be specified",
+ "rule": "has(self.id)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "oidcClaim": {
+ "description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
+ "properties": {
+ "claimName": {
+ "description": "ClaimName is the OIDC claim to match.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "claimValue": {
+ "description": "ClaimValue is the expected value.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "identityProviderId": {
+ "description": "IdentityProviderID in Cloudflare.",
+ "maxLength": 36,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "claimName",
+ "claimValue",
+ "identityProviderId"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "serviceToken": {
+ "description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
+ "properties": {
+ "name": {
+ "description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "tokenId": {
+ "description": "TokenID is the Cloudflare service token ID.",
+ "maxLength": 36,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tokenId or name must be specified",
+ "rule": "has(self.tokenId) || has(self.name)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one rule type must be specified",
+ "rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 25,
+ "type": "array"
+ },
+ "serviceTokens": {
+ "description": "ServiceTokens for machine-to-machine authentication.",
+ "items": {
+ "description": "ServiceTokenConfig defines configuration for Cloudflare Access service tokens.\n\nServiceTokenConfig enables machine-to-machine authentication. The controller creates\nthe service token in Cloudflare and stores the credentials (client ID and secret) in\nthe referenced Kubernetes Secret. The secret is only visible at creation time.",
+ "properties": {
+ "duration": {
+ "default": "8760h",
+ "description": "Duration is the token validity period using Go duration format.\nOnly hours (h) supported by Cloudflare API. Use \"8760h\" for 1 year.",
+ "pattern": "^[0-9]+h$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the token display name.",
+ "maxLength": 255,
+ "minLength": 1,
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "SecretRef stores the generated token credentials.",
+ "properties": {
+ "name": {
+ "description": "Name of the Secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "secretRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "sessionDuration": {
+ "description": "SessionDuration overrides application session duration for this policy.",
+ "maxLength": 32,
+ "pattern": "^([0-9]+(ns|us|ms|s|m|h))+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "cloudflareRef",
+ "decision",
+ "include",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "include rules are required",
+ "rule": "size(self.include) > 0"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareAccessPolicyStatus defines the observed state of a CloudflareAccessPolicy resource.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare account ID used for this policy.",
+ "type": "string"
+ },
+ "appCount": {
+ "description": "AppCount is the number of Access Applications currently using this policy.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "conditions": {
+ "description": "Conditions describe current state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "credentialSecretRef": {
+ "description": "CredentialSecretRef is the resolved credentials Secret used for cleanup.\nThe namespace is always stored explicitly.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the last generation processed.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "policyId": {
+ "description": "PolicyID is the Cloudflare Access reusable policy ID.",
+ "type": "string"
+ },
+ "reusable": {
+ "description": "Reusable reports whether Cloudflare returned this policy as reusable.",
+ "type": "boolean"
+ },
+ "serviceTokenIds": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ServiceTokenIDs maps token names to Cloudflare IDs.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/cloudflaredns-stable-v1alpha1.json b/crdSchemas/master-standalone/cloudflaredns-stable-v1alpha1.json
new file mode 100644
index 0000000..9a368e5
--- /dev/null
+++ b/crdSchemas/master-standalone/cloudflaredns-stable-v1alpha1.json
@@ -0,0 +1,591 @@
+{
+ "description": "CloudflareDNS is the Schema for the cloudflarednses API.\n\nCloudflareDNS manages DNS record synchronization independently from CloudflareTunnel resources.\nIt supports two target modes: tunnel references (for tunnel-based CNAME records) and external\ntargets (for non-tunnel DNS management). DNS records can be sourced from Gateway API routes\nor explicitly defined.\n\nCloudflareDNS implements ownership tracking via TXT records (aligned with external-dns patterns)\nto enable safe multi-cluster deployments and prevent accidental deletion of records created\nby other installations.\n\nStatus conditions:\n - Ready: DNS sync is fully operational\n - CredentialsValid: Cloudflare credentials have been validated\n - ZonesResolved: All configured zones have been resolved via API\n - RecordsSynced: DNS records have been synchronized to Cloudflare\n - OwnershipVerified: TXT ownership records have been verified, when enabled",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareDNSSpec defines the desired state of a CloudflareDNS resource.\n\nCloudflareDNSSpec configures DNS record synchronization, including the target\n(tunnel or external), zones to manage, hostname sources, and ownership tracking.\nEither tunnelRef or externalTarget must be specified (mutually exclusive).",
+ "properties": {
+ "cleanupPolicy": {
+ "description": "CleanupPolicy defines cleanup behavior for records.",
+ "properties": {
+ "deleteOnResourceRemoval": {
+ "description": "DeleteOnResourceRemoval deletes records when CloudflareDNS resource is deleted.\nnil defaults to true.",
+ "type": "boolean"
+ },
+ "deleteOnRouteRemoval": {
+ "description": "DeleteOnRouteRemoval deletes records when the source route is deleted.\nnil defaults to true.",
+ "type": "boolean"
+ },
+ "onlyManaged": {
+ "description": "OnlyManaged only deletes records that were created by cfgate (verified via ownership).\nnil defaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cloudflare": {
+ "description": "Cloudflare API credentials (required when using externalTarget).\nWhen using tunnelRef, credentials are inherited from the tunnel.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare Account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare Account name. Will be looked up via API.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "secretKeys": {
+ "description": "SecretKeys defines the key mappings within the secret.",
+ "properties": {
+ "apiToken": {
+ "default": "CLOUDFLARE_API_TOKEN",
+ "description": "APIToken is the key name for the Cloudflare API token.",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secretRef": {
+ "description": "SecretRef references the Secret containing Cloudflare API credentials.\nThe secret must contain an API token (not tunnel token).",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the tunnel's namespace.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "secretRef"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either accountId or accountName must be specified",
+ "rule": "has(self.accountId) || has(self.accountName)"
+ },
+ {
+ "message": "accountId must be a 32-character hex string",
+ "rule": "!has(self.accountId) || self.accountId.matches('^[a-f0-9]{32}$')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "defaults": {
+ "description": "Defaults defines default settings for DNS records.",
+ "properties": {
+ "proxied": {
+ "default": true,
+ "description": "Proxied enables Cloudflare proxy by default.",
+ "type": "boolean"
+ },
+ "ttl": {
+ "default": 1,
+ "description": "TTL is the default DNS record TTL in seconds.\nValid values: 1 (auto) or 60-86400 (explicit).",
+ "format": "int32",
+ "maximum": 86400,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "TTL must be 1 (auto) or between 60 and 86400 seconds",
+ "rule": "!has(self.ttl) || self.ttl == 1 || (self.ttl >= 60 && self.ttl <= 86400)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "externalTarget": {
+ "description": "ExternalTarget specifies a non-tunnel DNS target.",
+ "properties": {
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "CNAME",
+ "A",
+ "AAAA"
+ ]
+ },
+ {
+ "enum": [
+ "CNAME",
+ "A",
+ "AAAA"
+ ]
+ }
+ ],
+ "description": "Type is the DNS record type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the target value (domain for CNAME, IP for A/AAAA).\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "type",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fallbackCredentialsRef": {
+ "description": "FallbackCredentialsRef references fallback Cloudflare API credentials.\nUsed during deletion when primary credentials are unavailable.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ownership": {
+ "description": "Ownership defines how to track record ownership.",
+ "properties": {
+ "comment": {
+ "description": "Comment configures comment-based ownership.\n\nDeprecated: since v0.1.0-alpha.13. All fields are ignored. Will be removed in a future cleanup release.",
+ "properties": {
+ "enabled": {
+ "default": false,
+ "description": "Enabled enables comment-based ownership tracking.\n\nDeprecated: since v0.1.0-alpha.13. This field is ignored. The controller always\nwrites a \"managed by cfgate\" comment. Will be removed in a future cleanup release.",
+ "type": "boolean"
+ },
+ "template": {
+ "default": "managed by cfgate",
+ "description": "Template is the comment template.\n\nDeprecated: since v0.1.0-alpha.13. This field is ignored. The controller always\nuses \"managed by cfgate\" as the comment. Will be removed in a future cleanup release.",
+ "maxLength": 255,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ownerId": {
+ "description": "OwnerID is the cluster/installation identifier used in TXT ownership records.\nUsed to distinguish records created by different cfgate installations.\nDefaults to the CloudflareDNS resource's namespace/name if not specified.",
+ "maxLength": 253,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(/[a-z0-9]([-a-z0-9]*[a-z0-9])?)?$",
+ "type": "string"
+ },
+ "txtRecord": {
+ "description": "TXTRecord configures TXT record-based ownership.",
+ "properties": {
+ "enabled": {
+ "description": "Enabled enables TXT record ownership tracking.\nnil defaults to true.",
+ "type": "boolean"
+ },
+ "prefix": {
+ "default": "_cfgate",
+ "description": "Prefix is the prefix for TXT record names.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "policy": {
+ "allOf": [
+ {
+ "enum": [
+ "sync",
+ "upsert-only",
+ "create-only"
+ ]
+ },
+ {
+ "enum": [
+ "sync",
+ "upsert-only",
+ "create-only"
+ ]
+ }
+ ],
+ "default": "sync",
+ "description": "Policy controls DNS record lifecycle.",
+ "type": "string"
+ },
+ "source": {
+ "description": "Source defines where to get hostnames to sync.",
+ "properties": {
+ "explicit": {
+ "description": "Explicit defines explicit hostnames to sync.",
+ "items": {
+ "description": "DNSExplicitHostname defines an explicit hostname to sync with optional per-hostname configuration.\n\nDNSExplicitHostname provides direct specification of DNS hostnames without depending on\nGateway API route discovery. The Target field supports the template\nvariable for dynamic resolution when using tunnelRef.",
+ "properties": {
+ "hostname": {
+ "description": "Hostname is the DNS hostname to create.\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)",
+ "rule": "self.split('.').all(s, size(s) <= 63)"
+ }
+ ]
+ },
+ "proxied": {
+ "description": "Proxied enables Cloudflare proxy for this record.\nnil inherits from zone or defaults.",
+ "type": "boolean"
+ },
+ "target": {
+ "description": "Target overrides the resolved record target for this hostname.\nSupports template variable when tunnelRef is used.\nDefaults to the resource-level resolved target when omitted.\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "ttl": {
+ "default": 1,
+ "description": "TTL is the DNS record TTL in seconds. 1 means auto (Cloudflare managed).\nValid values: 1 (auto) or 60-86400 (explicit).",
+ "format": "int32",
+ "maximum": 86400,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "hostname"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "TTL must be 1 (auto) or between 60 and 86400 seconds",
+ "rule": "!has(self.ttl) || self.ttl == 1 || (self.ttl >= 60 && self.ttl <= 86400)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 100,
+ "type": "array"
+ },
+ "gatewayRoutes": {
+ "description": "GatewayRoutes configures watching Gateway API routes.",
+ "properties": {
+ "annotationFilter": {
+ "description": "AnnotationFilter only syncs routes with this annotation.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "enabled": {
+ "default": true,
+ "description": "Enabled enables watching Gateway API routes.",
+ "type": "boolean"
+ },
+ "namespaceSelector": {
+ "description": "NamespaceSelector limits route discovery to specific namespaces.",
+ "properties": {
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels selects namespaces with matching labels.",
+ "maxProperties": 10,
+ "type": "object"
+ },
+ "matchNames": {
+ "description": "MatchNames selects namespaces by name.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 50,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one selector must be specified",
+ "rule": "has(self.matchLabels) || has(self.matchNames)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tunnelRef": {
+ "description": "TunnelRef references a CloudflareTunnel for CNAME target resolution.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the CloudflareTunnel.",
+ "maxLength": 63,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the CloudflareTunnel.\nDefaults to the CloudflareDNS's namespace.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "zones": {
+ "description": "Zones defines the DNS zones to manage.",
+ "items": {
+ "description": "DNSZoneConfig defines a DNS zone where records will be managed.\n\nDNSZoneConfig identifies a Cloudflare DNS zone either by name (requiring API lookup)\nor by explicit zone ID. The optional Proxied field sets the default proxy behavior\nfor all records in this zone.",
+ "properties": {
+ "id": {
+ "description": "ID is the optional explicit zone ID (skips API lookup).",
+ "maxLength": 32,
+ "pattern": "^[a-f0-9]{32}$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the zone domain name (e.g., example.com).\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)",
+ "rule": "self.split('.').all(s, size(s) <= 63)"
+ }
+ ]
+ },
+ "proxied": {
+ "description": "Proxied sets the default proxied setting for this zone.\nnil inherits from spec.defaults.proxied.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "zones"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either tunnelRef or externalTarget must be specified",
+ "rule": "has(self.tunnelRef) || has(self.externalTarget)"
+ },
+ {
+ "message": "tunnelRef and externalTarget are mutually exclusive",
+ "rule": "!(has(self.tunnelRef) && has(self.externalTarget))"
+ },
+ {
+ "message": "cloudflare credentials required when using externalTarget",
+ "rule": "has(self.tunnelRef) || has(self.cloudflare)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareDNSStatus defines the observed state of a CloudflareDNS resource.\n\nCloudflareDNSStatus captures the synchronization state of all DNS records, including\ncounts of synced, pending, and failed records. The ResolvedTarget field shows the\nactual CNAME target being used (either from tunnel or external target).",
+ "properties": {
+ "conditions": {
+ "description": "Conditions represent the latest available observations.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "failedRecords": {
+ "description": "FailedRecords is the number of records that failed to sync.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "lastSyncTime": {
+ "description": "LastSyncTime is the last time records were synced.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the generation observed by the controller.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "pendingRecords": {
+ "description": "PendingRecords is the number of records pending sync.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "records": {
+ "description": "Records contains the status of individual DNS records.",
+ "items": {
+ "description": "DNSRecordSyncStatus represents the synchronization status of a single DNS record.\n\nDNSRecordSyncStatus tracks individual DNS record state including the Cloudflare record ID,\ncurrent configuration, and sync status. The Status field indicates: Synced (successfully\nsynchronized), Pending (awaiting sync), or Failed (sync failed, see Error field).",
+ "properties": {
+ "error": {
+ "description": "Error contains the error message if status is Failed.",
+ "type": "string"
+ },
+ "hostname": {
+ "description": "Hostname is the DNS hostname.",
+ "type": "string"
+ },
+ "proxied": {
+ "description": "Proxied indicates if Cloudflare proxy is enabled.",
+ "type": "boolean"
+ },
+ "recordId": {
+ "description": "RecordID is the Cloudflare record ID.",
+ "type": "string"
+ },
+ "status": {
+ "description": "Status is the sync status: Synced, Pending, Failed.",
+ "type": "string"
+ },
+ "target": {
+ "description": "Target is the record target/content.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL is the record TTL.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": {
+ "description": "Type is the DNS record type (CNAME, A, AAAA).",
+ "type": "string"
+ },
+ "zoneId": {
+ "description": "ZoneID is the Cloudflare zone ID where the record was created.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "hostname",
+ "proxied",
+ "status",
+ "target",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 1000,
+ "type": "array"
+ },
+ "resolvedTarget": {
+ "description": "ResolvedTarget is the resolved CNAME target (tunnel domain or external value).",
+ "type": "string"
+ },
+ "syncedRecords": {
+ "description": "SyncedRecords is the number of successfully synced records.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/cloudflaretunnel-stable-v1alpha1.json b/crdSchemas/master-standalone/cloudflaretunnel-stable-v1alpha1.json
new file mode 100644
index 0000000..783ad2b
--- /dev/null
+++ b/crdSchemas/master-standalone/cloudflaretunnel-stable-v1alpha1.json
@@ -0,0 +1,483 @@
+{
+ "description": "CloudflareTunnel is the Schema for the cloudflaretunnels API.\n\nCloudflareTunnel manages the lifecycle of a Cloudflare Tunnel and its cloudflared daemon\ndeployment. It handles tunnel creation or adoption, credential management, and deploys\ncloudflared pods that establish secure connections to Cloudflare's edge network.\n\nCloudflareTunnel follows a composable architecture where tunnel lifecycle is separate from\nDNS management. Use CloudflareDNS with a tunnelRef to create DNS records pointing to this\ntunnel's domain.\n\nStatus conditions:\n - Ready: tunnel is fully operational\n - CredentialsValid: API credentials have been validated\n - TunnelReady: tunnel exists in Cloudflare\n - ConfigurationSynced: ingress configuration is synced\n - CloudflaredDeployed: cloudflared pods are running",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "CloudflareTunnelSpec defines the desired state of a CloudflareTunnel resource.\n\nCloudflareTunnelSpec configures the tunnel identity, Cloudflare credentials, cloudflared\ndeployment settings, and origin connection defaults. The tunnel manages lifecycle only;\nDNS records are managed separately via CloudflareDNS resources.",
+ "properties": {
+ "cloudflare": {
+ "description": "Cloudflare defines the Cloudflare API credentials.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the Cloudflare Account ID.",
+ "maxLength": 32,
+ "type": "string"
+ },
+ "accountName": {
+ "description": "AccountName is the Cloudflare Account name. Will be looked up via API.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "secretKeys": {
+ "description": "SecretKeys defines the key mappings within the secret.",
+ "properties": {
+ "apiToken": {
+ "default": "CLOUDFLARE_API_TOKEN",
+ "description": "APIToken is the key name for the Cloudflare API token.",
+ "maxLength": 253,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secretRef": {
+ "description": "SecretRef references the Secret containing Cloudflare API credentials.\nThe secret must contain an API token (not tunnel token).",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the tunnel's namespace.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "secretRef"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either accountId or accountName must be specified",
+ "rule": "has(self.accountId) || has(self.accountName)"
+ },
+ {
+ "message": "accountId must be a 32-character hex string",
+ "rule": "!has(self.accountId) || self.accountId.matches('^[a-f0-9]{32}$')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "cloudflared": {
+ "description": "Cloudflared defines the cloudflared deployment configuration.",
+ "properties": {
+ "extraArgs": {
+ "description": "ExtraArgs are additional arguments to pass to cloudflared.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 20,
+ "type": "array"
+ },
+ "image": {
+ "default": "ghcr.io/inherent-design/cloudflared:2026.5.0-h2c.1",
+ "description": "Image is the cloudflared container image.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "imagePullPolicy": {
+ "default": "IfNotPresent",
+ "description": "ImagePullPolicy is the pull policy for the cloudflared image.",
+ "enum": [
+ "Always",
+ "Never",
+ "IfNotPresent"
+ ],
+ "type": "string"
+ },
+ "metrics": {
+ "description": "Metrics configures the cloudflared metrics endpoint.",
+ "properties": {
+ "enabled": {
+ "default": true,
+ "description": "Enabled enables the metrics endpoint.",
+ "type": "boolean"
+ },
+ "port": {
+ "default": 44483,
+ "description": "Port is the port for the metrics endpoint.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "nodeSelector": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "NodeSelector is a selector for nodes to run cloudflared on.",
+ "maxProperties": 50,
+ "type": "object"
+ },
+ "podAnnotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "PodAnnotations are annotations to add to cloudflared pods.",
+ "maxProperties": 50,
+ "type": "object"
+ },
+ "protocol": {
+ "default": "auto",
+ "description": "Protocol is the tunnel transport protocol: auto, quic, http2.",
+ "enum": [
+ "auto",
+ "quic",
+ "http2"
+ ],
+ "type": "string"
+ },
+ "replicas": {
+ "default": 2,
+ "description": "Replicas is the number of cloudflared replicas.",
+ "format": "int32",
+ "maximum": 10,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "resources": {
+ "description": "Resources are the resource requirements for cloudflared containers.",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tolerations": {
+ "description": "Tolerations are tolerations for the cloudflared pods.",
+ "items": {
+ "description": "The pod this Toleration is attached to tolerates any taint that matches\nthe triple using the matching operator .",
+ "properties": {
+ "effect": {
+ "description": "Effect indicates the taint effect to match. Empty means match all taint effects.\nWhen specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.",
+ "type": "string"
+ },
+ "key": {
+ "description": "Key is the taint key that the toleration applies to. Empty means match all taint keys.\nIf the key is empty, operator must be Exists; this combination means to match all values and all keys.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Operator represents a key's relationship to the value.\nValid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.\nExists is equivalent to wildcard for value, so that a pod can\ntolerate all taints of a particular category.\nLt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).",
+ "type": "string"
+ },
+ "tolerationSeconds": {
+ "description": "TolerationSeconds represents the period of time the toleration (which must be\nof effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,\nit is not set, which means tolerate the taint forever (do not evict). Zero and\nnegative values will be treated as 0 (evict immediately) by the system.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "value": {
+ "description": "Value is the taint value the toleration matches to.\nIf the operator is Exists, the value should be empty, otherwise just a regular string.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 20,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fallbackCredentialsRef": {
+ "description": "FallbackCredentialsRef references a secret containing fallback Cloudflare API credentials.\nUsed during deletion when primary credentials (in Cloudflare.SecretRef) are unavailable.\nThis enables cleanup of Cloudflare resources even if the per-tunnel secret is deleted.\nThe secret must contain the same keys as the primary credentials secret.",
+ "properties": {
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
+ "maxLength": 63,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fallbackTarget": {
+ "default": "http_status:404",
+ "description": "FallbackTarget is the service for unmatched requests.",
+ "maxLength": 255,
+ "type": "string"
+ },
+ "originDefaults": {
+ "description": "OriginDefaults defines default settings for origin connections.",
+ "properties": {
+ "caPoolSecretRef": {
+ "description": "CAPoolSecretRef references a Secret containing CA certificates for origin verification.",
+ "properties": {
+ "key": {
+ "default": "ca.crt",
+ "description": "Key is the key within the secret data.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the secret.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connectTimeout": {
+ "default": "30s",
+ "description": "ConnectTimeout is the timeout for connecting to the origin.",
+ "pattern": "^[0-9]+(s|m|h)$",
+ "type": "string"
+ },
+ "h2cOrigin": {
+ "default": false,
+ "description": "H2cOrigin enables HTTP/2 cleartext (h2c) for origin connections.\nUse this for origins that speak HTTP/2 without TLS (e.g., gRPC services).\nMutually exclusive with http2Origin (TLS-based HTTP/2).",
+ "type": "boolean"
+ },
+ "http2Origin": {
+ "default": false,
+ "description": "HTTP2Origin enables HTTP/2 for origin connections.",
+ "type": "boolean"
+ },
+ "noTLSVerify": {
+ "default": false,
+ "description": "NoTLSVerify disables TLS verification for origin connections.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "http2Origin and h2cOrigin are mutually exclusive",
+ "rule": "!(self.http2Origin && self.h2cOrigin)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "tunnel": {
+ "description": "Tunnel defines the tunnel identity configuration.",
+ "properties": {
+ "name": {
+ "description": "Name is the tunnel name in Cloudflare. If tunnel with this name exists, adopt it.\nIf not, create it. Tunnel ID is stored in status after resolution/creation.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "cloudflare",
+ "tunnel"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "CloudflareTunnelStatus defines the observed state of a CloudflareTunnel resource.\n\nCloudflareTunnelStatus captures the tunnel's Cloudflare-assigned identifiers, deployment\nstatus, and reconciliation state. The TunnelDomain field provides the CNAME target\n({tunnelId}.cfargotunnel.com) that CloudflareDNS uses for DNS record creation.",
+ "properties": {
+ "accountId": {
+ "description": "AccountID is the resolved Cloudflare account ID.",
+ "type": "string"
+ },
+ "conditions": {
+ "description": "Conditions represent the latest available observations of the tunnel's state.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "connectedRouteCount": {
+ "description": "ConnectedRouteCount is the number of routes connected to this tunnel.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "lastSyncTime": {
+ "description": "LastSyncTime is the last time the configuration was synced to Cloudflare.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration is the generation observed by the controller.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "readyReplicas": {
+ "description": "ReadyReplicas is the number of ready cloudflared replicas.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "replicas": {
+ "description": "Replicas is the total number of cloudflared replicas.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tunnelDomain": {
+ "description": "TunnelDomain is the tunnel's CNAME target domain (e.g., {tunnelId}.cfargotunnel.com).",
+ "type": "string"
+ },
+ "tunnelId": {
+ "description": "TunnelID is the Cloudflare tunnel ID.",
+ "type": "string"
+ },
+ "tunnelName": {
+ "description": "TunnelName is the Cloudflare tunnel name.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/envoyextensionpolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/envoyextensionpolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..6834ef8
--- /dev/null
+++ b/crdSchemas/master-standalone/envoyextensionpolicy-stable-v1alpha1.json
@@ -0,0 +1,2259 @@
+{
+ "description": "EnvoyExtensionPolicy allows the user to configure various envoy extensibility options for the Gateway.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of EnvoyExtensionPolicy.",
+ "properties": {
+ "dynamicModule": {
+ "description": "DynamicModule is an ordered list of dynamic module HTTP filters\nthat should be added to the envoy filter chain.\nEach module must be registered in the EnvoyProxy resource's dynamicModules\nallowlist.\nOrder matters, as the filters will be loaded in the order they are\ndefined in this list.",
+ "items": {
+ "description": "DynamicModule defines a dynamic module HTTP filter to be loaded by Envoy.\nThe module must be registered in the EnvoyProxy resource's dynamicModules\nallowlist by the infrastructure operator.",
+ "properties": {
+ "config": {
+ "description": "Config is the configuration for the dynamic module filter.\nThis is serialized as JSON and passed to the module's initialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "filterName": {
+ "description": "FilterName identifies a specific filter implementation within the dynamic\nmodule. A single shared library can contain multiple filter implementations.\nThis value is passed to the module's HTTP filter config init function to\nselect the appropriate implementation.\nIf not specified, defaults to an empty string.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "terminalFilter": {
+ "default": false,
+ "description": "TerminalFilter indicates that this dynamic module handles requests without\nrequiring an upstream backend. The module is responsible for generating and\nsending the response to downstream directly.\nDefaults to false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "extProc": {
+ "description": "ExtProc is an ordered list of external processing filters\nthat should be added to the envoy filter chain",
+ "items": {
+ "description": "ExtProc defines the configuration for External Processing filter.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "failOpen": {
+ "default": false,
+ "description": "FailOpen is a switch used to control the behavior when failing to call the external processor.\n\nIf FailOpen is set to true, the system bypasses the ExtProc extension and\nallows the traffic to pass through. If it is set to false or\nnot set (defaulting to false), the system blocks the traffic and returns\nan HTTP 5xx error.\n\nIf set to true, the ExtProc extension will also be bypassed if the configuration is invalid.",
+ "type": "boolean"
+ },
+ "messageTimeout": {
+ "description": "MessageTimeout is the timeout for a response to be returned from the external processor\nDefault: 200ms",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "metadata": {
+ "description": "Metadata defines options related to the sending and receiving of dynamic metadata.\nThese options define which metadata namespaces would be sent to the processor and which dynamic metadata\nnamespaces the processor would be permitted to emit metadata to.\nUsers can specify custom namespaces or well-known envoy metadata namespace (such as envoy.filters.http.ext_authz)\ndocumented here: https://www.envoyproxy.io/docs/envoy/latest/configuration/advanced/well_known_dynamic_metadata#well-known-dynamic-metadata\nDefault: no metadata context is sent or received from the external processor",
+ "properties": {
+ "accessibleNamespaces": {
+ "description": "AccessibleNamespaces are metadata namespaces that are sent to the external processor as context",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "writableNamespaces": {
+ "description": "WritableNamespaces are metadata namespaces that the external processor can write to",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "writableNamespaces cannot contain well-known Envoy HTTP filter namespaces",
+ "rule": "self.all(f, !f.startsWith('envoy.filters.http'))"
+ }
+ ]
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "processingMode": {
+ "description": "ProcessingMode defines how request and response body is processed\nDefault: header and body are not sent to the external processor",
+ "properties": {
+ "allowModeOverride": {
+ "description": "AllowModeOverride allows the external processor to override the processing mode set via the\n`mode_override` field in the gRPC response message. This defaults to false.",
+ "type": "boolean"
+ },
+ "request": {
+ "description": "Defines processing mode for requests. If present, request headers are sent. Request body is processed according\nto the specified mode.",
+ "properties": {
+ "attributes": {
+ "description": "Defines which attributes are sent to the external processor. Envoy Gateway currently\nsupports only the following attribute prefixes: connection, source, destination,\nrequest, response, upstream and xds.route.\nhttps://www.envoyproxy.io/docs/envoy/latest/intro/arch_overview/advanced/attributes",
+ "items": {
+ "pattern": "^(connection\\.|source\\.|destination\\.|request\\.|response\\.|upstream\\.|xds\\.route_)[a-z_1-9]*$",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "body": {
+ "description": "Defines body processing mode",
+ "enum": [
+ "Streamed",
+ "Buffered",
+ "BufferedPartial",
+ "FullDuplexStreamed"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "response": {
+ "description": "Defines processing mode for responses. If present, response headers are sent. Response body is processed according\nto the specified mode.",
+ "properties": {
+ "attributes": {
+ "description": "Defines which attributes are sent to the external processor. Envoy Gateway currently\nsupports only the following attribute prefixes: connection, source, destination,\nrequest, response, upstream and xds.route.\nhttps://www.envoyproxy.io/docs/envoy/latest/intro/arch_overview/advanced/attributes",
+ "items": {
+ "pattern": "^(connection\\.|source\\.|destination\\.|request\\.|response\\.|upstream\\.|xds\\.route_)[a-z_1-9]*$",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "body": {
+ "description": "Defines body processing mode",
+ "enum": [
+ "Streamed",
+ "Buffered",
+ "BufferedPartial",
+ "FullDuplexStreamed"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only supports Service, ServiceImport, and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'ServiceImport' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only supports Core, multicluster.x-k8s.io, and gateway.envoyproxy.io groups.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'multicluster.x-k8s.io' || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "If FullDuplexStreamed body processing mode is used, FailOpen must be false.",
+ "rule": "!(has(self.failOpen) && self.failOpen == true && has(self.processingMode) && ((has(self.processingMode.request) && has(self.processingMode.request.body) && self.processingMode.request.body == 'FullDuplexStreamed') || (has(self.processingMode.response) && has(self.processingMode.response.body) && self.processingMode.response.body == 'FullDuplexStreamed')))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "lua": {
+ "description": "Lua is an ordered list of Lua filters\nthat should be added to the envoy filter chain",
+ "items": {
+ "description": "Lua defines a Lua extension\nOnly one of Inline or ValueRef must be set",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the source code as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the Lua value.\nValid values are Inline and ValueRef, default is Inline.",
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ],
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef has the source code specified as a local object reference.\nOnly a reference to ConfigMap is supported.\nThe value of key `lua` in the ConfigMap will be used.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Only a reference to an object of kind ConfigMap belonging to default v1 API group is supported.",
+ "rule": "self.kind == 'ConfigMap' && (self.group == 'v1' || self.group == '')"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Exactly one of inline or valueRef must be set with correct type.",
+ "rule": "(self.type == 'Inline' && has(self.inline) && !has(self.valueRef)) || (self.type == 'ValueRef' && !has(self.inline) && has(self.valueRef))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "wasm": {
+ "description": "Wasm is a list of Wasm extensions to be loaded by the Gateway.\nOrder matters, as the extensions will be loaded in the order they are\ndefined in this list.",
+ "items": {
+ "description": "Wasm defines a Wasm extension.\n\nNote: at the moment, Envoy Gateway does not support configuring Wasm runtime.\nv8 is used as the VM runtime for the Wasm extensions.",
+ "properties": {
+ "code": {
+ "description": "Code is the Wasm code for the extension.",
+ "properties": {
+ "http": {
+ "description": "HTTP is the HTTP URL containing the Wasm code.\n\nNote that the HTTP server must be accessible from the Envoy proxy.",
+ "properties": {
+ "sha256": {
+ "description": "SHA256 checksum that will be used to verify the Wasm code.\n\nIf not specified, Envoy Gateway will not verify the downloaded Wasm code.\nkubebuilder:validation:Pattern=`^[a-f0-9]{64}$`",
+ "type": "string"
+ },
+ "tls": {
+ "description": "TLS configuration when connecting to the Wasm code source.",
+ "properties": {
+ "caCertificateRef": {
+ "description": "CACertificateRef contains a reference to\nKubernetes objects that contain TLS certificates of\nthe Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the Wasm code source.\n\nKubernetes ConfigMap, Kubernetes Secret, and Kubernetes ClusterTrustBundle are supported.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "caCertificateRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "url": {
+ "description": "URL is the URL containing the Wasm code.",
+ "pattern": "^((https?:)(\\/\\/\\/?)([\\w]*(?::[\\w]*)?@)?([\\d\\w\\.-]+)(?::(\\d+))?)?([\\/\\\\\\w\\.()-]*)?(?:([?][^#]*)?(#.*)?)*",
+ "type": "string"
+ }
+ },
+ "required": [
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "image": {
+ "description": "Image is the OCI image containing the Wasm code.\n\nNote that the image must be accessible from the Envoy Gateway.",
+ "properties": {
+ "pullSecretRef": {
+ "description": "PullSecretRef is a reference to the secret containing the credentials to pull the image.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only support Secret kind.",
+ "rule": "self.kind == 'Secret'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "sha256": {
+ "description": "SHA256 checksum that will be used to verify the OCI image.\n\nIt must match the digest of the OCI image.\n\nIf not specified, Envoy Gateway will not verify the downloaded OCI image.\nkubebuilder:validation:Pattern=`^[a-f0-9]{64}$`",
+ "type": "string"
+ },
+ "tls": {
+ "description": "TLS configuration when connecting to the Wasm code source.",
+ "properties": {
+ "caCertificateRef": {
+ "description": "CACertificateRef contains a reference to\nKubernetes objects that contain TLS certificates of\nthe Certificate Authorities that can be used\nas a trust anchor to validate the certificates presented by the Wasm code source.\n\nKubernetes ConfigMap, Kubernetes Secret, and Kubernetes ClusterTrustBundle are supported.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "caCertificateRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "url": {
+ "description": "URL is the URL of the OCI image.\nURL can be in the format of `registry/image:tag` or `registry/image@sha256:digest`.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pullPolicy": {
+ "description": "PullPolicy is the policy to use when pulling the Wasm module by either the HTTP or Image source.\nThis field is only applicable when the SHA256 field is not set.\n\nIf not specified, the default policy is IfNotPresent except for OCI images whose tag is latest.\n\nNote: EG does not update the Wasm module every time an Envoy proxy requests\nthe Wasm module even if the pull policy is set to Always.\nIt only updates the Wasm module when the EnvoyExtension resource version changes.",
+ "enum": [
+ "IfNotPresent",
+ "Always"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "Image"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "Image",
+ "ConfigMap"
+ ]
+ }
+ ],
+ "description": "Type is the type of the source of the Wasm code.\nValid WasmCodeSourceType values are \"HTTP\" or \"Image\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If type is Image, image field needs to be set.",
+ "rule": "self.type == 'Image' ? has(self.image) : !has(self.image)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "config": {
+ "description": "Config is the configuration for the Wasm extension.\nThis configuration will be passed as a JSON string to the Wasm extension.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "env": {
+ "description": "Env configures the environment for the Wasm extension",
+ "properties": {
+ "hostKeys": {
+ "description": "HostKeys is a list of keys for environment variables from the host envoy process\nthat should be passed into the Wasm VM. This is useful for passing secrets to to Wasm extensions.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failOpen": {
+ "default": false,
+ "description": "FailOpen is a switch used to control the behavior when a fatal error occurs\nduring the initialization or the execution of the Wasm extension.\n\nIf FailOpen is set to true, the system bypasses the Wasm extension and\nallows the traffic to pass through. If it is set to false or\nnot set (defaulting to false), the system blocks the traffic and returns\nan HTTP 5xx error.\n\nIf set to true, the Wasm extension will also be bypassed if the configuration is invalid.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name is a unique name for this Wasm extension. It is used to identify the\nWasm extension if multiple extensions are handled by the same vm_id and root_id.\nIt's also used for logging/debugging.\nIf not specified, EG will generate a unique name for the Wasm extension.",
+ "type": "string"
+ },
+ "rootID": {
+ "description": "RootID is a unique ID for a set of extensions in a VM which will share a\nRootContext and Contexts if applicable (e.g., an Wasm HttpFilter and an Wasm AccessLog).\nIf left blank, all extensions with a blank root_id with the same vm_id will share Context(s).\n\nNote: RootID must match the root_id parameter used to register the Context in the Wasm code.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "code"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true"
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRef) ? self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute'] : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true "
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute/UDPRoute/TLSRoute",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'UDPRoute', 'TCPRoute', 'TLSRoute']) : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of EnvoyExtensionPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/envoypatchpolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/envoypatchpolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..0e87e08
--- /dev/null
+++ b/crdSchemas/master-standalone/envoypatchpolicy-stable-v1alpha1.json
@@ -0,0 +1,292 @@
+{
+ "description": "EnvoyPatchPolicy allows the user to modify the generated Envoy xDS\nresources by Envoy Gateway using this patch API",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of EnvoyPatchPolicy.",
+ "properties": {
+ "jsonPatches": {
+ "description": "JSONPatch defines the JSONPatch configuration.",
+ "items": {
+ "description": "EnvoyJSONPatchConfig defines the configuration for patching a Envoy xDS Resource\nusing JSONPatch semantic",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the resource",
+ "type": "string"
+ },
+ "operation": {
+ "description": "Patch defines the JSON Patch Operation",
+ "properties": {
+ "from": {
+ "description": "From is the source location of the value to be copied or moved. Only valid\nfor move or copy operations\nRefer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.",
+ "type": "string"
+ },
+ "jsonPath": {
+ "description": "JSONPath is a JSONPath expression. Refer to https://datatracker.ietf.org/doc/rfc9535/ for more details.\nIt produces one or more JSONPointer expressions based on the given JSON document.\nIf no JSONPointer is found, it will result in an error.\nIf the 'Path' property is also set, it will be appended to the resulting JSONPointer expressions from the JSONPath evaluation.\nThis is useful when creating a property that does not yet exist in the JSON document.\nThe final JSONPointer expressions specifies the locations in the target document/field where the operation will be applied.",
+ "type": "string"
+ },
+ "op": {
+ "description": "Op is the type of operation to perform",
+ "enum": [
+ "add",
+ "remove",
+ "replace",
+ "move",
+ "copy",
+ "test"
+ ],
+ "type": "string"
+ },
+ "path": {
+ "description": "Path is a JSONPointer expression. Refer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.\nIt specifies the location of the target document/field where the operation will be performed",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the new value of the path location. The value is only used by\nthe `add` and `replace` operations.",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "op"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type is the typed URL of the Envoy xDS Resource",
+ "enum": [
+ "type.googleapis.com/envoy.config.listener.v3.Listener",
+ "type.googleapis.com/envoy.config.route.v3.RouteConfiguration",
+ "type.googleapis.com/envoy.config.cluster.v3.Cluster",
+ "type.googleapis.com/envoy.config.endpoint.v3.ClusterLoadAssignment",
+ "type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.Secret"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "operation",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "priority": {
+ "description": "Priority of the EnvoyPatchPolicy.\nIf multiple EnvoyPatchPolicies are applied to the same\nTargetRef, they will be applied in the ascending order of\nthe priority i.e. int32.min has the highest priority and\nint32.max has the lowest priority.\nDefaults to 0.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the Gateway API resource this policy\nis being attached to.\nBy default, attaching to Gateway is supported and\nwhen mergeGateways is enabled it should attach to GatewayClass.\nThis Policy and the TargetRef MUST be in the same namespace\nfor this Policy to have effect and be applied to the Gateway\nTargetRef",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of patch.\nValid EnvoyPatchType values are \"JSONPatch\".",
+ "enum": [
+ "JSONPatch"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "targetRef",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of EnvoyPatchPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/envoyproxy-stable-v1alpha1.json b/crdSchemas/master-standalone/envoyproxy-stable-v1alpha1.json
new file mode 100644
index 0000000..891e25b
--- /dev/null
+++ b/crdSchemas/master-standalone/envoyproxy-stable-v1alpha1.json
@@ -0,0 +1,15702 @@
+{
+ "description": "EnvoyProxy is the schema for the envoyproxies API.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "EnvoyProxySpec defines the desired state of EnvoyProxy.",
+ "properties": {
+ "backendTLS": {
+ "description": "BackendTLS is the TLS configuration for the Envoy proxy to use when connecting to backends.\nThese settings are applied on backends for which TLS policies are specified.",
+ "properties": {
+ "alpnProtocols": {
+ "description": "ALPNProtocols supplies the list of ALPN protocols that should be\nexposed by the listener or used by the proxy to connect to the backend.\nDefaults:\n1. HTTPS Routes: h2 and http/1.1 are enabled in listener context.\n2. Other Routes: ALPN is disabled.\n3. Backends: proxy uses the appropriate ALPN options for the backend protocol.\nWhen an empty list is provided, the ALPN TLS extension is disabled.\n\nDefaults to [h2, http/1.1] if not specified.\n\nTypical Supported values are:\n- http/1.0\n- http/1.1\n- h2",
+ "items": {
+ "description": "ALPNProtocol specifies the protocol to be negotiated using ALPN",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "ciphers": {
+ "description": "Ciphers specifies the set of cipher suites supported when\nnegotiating TLS 1.0 - 1.2. This setting has no effect for TLS 1.3.\nFor Envoy TLS cipher suite configuration semantics and default cipher\nlists, see the Envoy documentation:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/transport_sockets/tls/v3/common.proto#extensions-transport-sockets-tls-v3-tlsparameters\nSupported cipher suite names:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\n- ECDHE-ECDSA-CHACHA20-POLY1305\n- ECDHE-RSA-CHACHA20-POLY1305\n- ECDHE-ECDSA-AES128-SHA\n- ECDHE-RSA-AES128-SHA\n- AES128-GCM-SHA256\n- AES128-SHA\n- ECDHE-ECDSA-AES256-SHA\n- ECDHE-RSA-AES256-SHA\n- AES256-GCM-SHA384\n- AES256-SHA\nSupported IANA/RFC aliases:\n- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\n- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256\n- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\n- TLS_RSA_WITH_AES_128_GCM_SHA256\n- TLS_RSA_WITH_AES_128_CBC_SHA\n- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\n- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\n- TLS_RSA_WITH_AES_256_GCM_SHA384\n- TLS_RSA_WITH_AES_256_CBC_SHA\nIn non-FIPS Envoy Proxy builds the default cipher list is:\n- [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]\n- [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384\nIn builds using BoringSSL FIPS the default cipher list is:\n- ECDHE-ECDSA-AES128-GCM-SHA256\n- ECDHE-RSA-AES128-GCM-SHA256\n- ECDHE-ECDSA-AES256-GCM-SHA384\n- ECDHE-RSA-AES256-GCM-SHA384",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef defines the reference to a Kubernetes Secret that contains\nthe client certificate and private key for Envoy to use when connecting to\nbackend services and external services, such as ExtAuth, ALS, OpenTelemetry, etc.\nThis secret should be located within the same namespace as the Envoy proxy resource that references it.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ecdhCurves": {
+ "description": "ECDHCurves specifies the set of supported ECDH curves.\nIn non-FIPS Envoy Proxy builds the default curves are:\n- X25519\n- P-256\nIn builds using BoringSSL FIPS the default curve is:\n- P-256",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "fingerprints": {
+ "description": "Fingerprints specifies TLS client fingerprinting.\nWhen specified, a JAX fingerprint derived from the client\u2019s TLS handshake\nis generated. The fingerprint can be logged in access logs or\nforwarded to upstream services using request headers.\n\nFingerprinting is disabled if not specified.\n\nSupported values are:\n- JA3\n- JA4",
+ "items": {
+ "description": "TLSFingerprintType specifies the TLS client fingerprinting mode.",
+ "enum": [
+ "JA3",
+ "JA4"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "maxVersion": {
+ "description": "Max specifies the maximal TLS protocol version to allow\nThe default is TLS 1.3 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "minVersion": {
+ "description": "Min specifies the minimal TLS protocol version to allow.\nThe default is TLS 1.2 if this is not specified.",
+ "enum": [
+ "Auto",
+ "1.0",
+ "1.1",
+ "1.2",
+ "1.3"
+ ],
+ "type": "string"
+ },
+ "signatureAlgorithms": {
+ "description": "SignatureAlgorithms specifies which signature algorithms the listener should\nsupport.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "setting ciphers has no effect if the minimum possible TLS version is 1.3",
+ "rule": "has(self.minVersion) && self.minVersion == '1.3' ? !has(self.ciphers) : true"
+ },
+ {
+ "message": "minVersion must be smaller or equal to maxVersion",
+ "rule": "has(self.minVersion) && has(self.maxVersion) ? {\"Auto\":0,\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4}[self.minVersion] <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : !has(self.minVersion) && has(self.maxVersion) ? 3 <= {\"1.0\":1,\"1.1\":2,\"1.2\":3,\"1.3\":4,\"Auto\":5}[self.maxVersion] : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "bootstrap": {
+ "description": "Bootstrap defines the Envoy Bootstrap as a YAML string.\nVisit https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/bootstrap/v3/bootstrap.proto#envoy-v3-api-msg-config-bootstrap-v3-bootstrap\nto learn more about the syntax.\nIf set, this is the Bootstrap configuration used for the managed Envoy Proxy fleet instead of the default Bootstrap configuration\nset by Envoy Gateway.\nSome fields within the Bootstrap that are required to communicate with the xDS Server (Envoy Gateway) and receive xDS resources\nfrom it are not configurable and will result in the `EnvoyProxy` resource being rejected.\nBackward compatibility across minor versions is not guaranteed.\nWe strongly recommend using `egctl x translate` to generate a `EnvoyProxy` resource with the `Bootstrap` field set to the default\nBootstrap configuration used. You can edit this configuration, and rerun `egctl x translate` to ensure there are no validation errors.",
+ "properties": {
+ "jsonPatches": {
+ "description": "JSONPatches is an array of JSONPatches to be applied to the default bootstrap. Patches are\napplied in the order in which they are defined.",
+ "items": {
+ "description": "JSONPatchOperation defines the JSON Patch Operation as defined in\nhttps://datatracker.ietf.org/doc/html/rfc6902",
+ "properties": {
+ "from": {
+ "description": "From is the source location of the value to be copied or moved. Only valid\nfor move or copy operations\nRefer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.",
+ "type": "string"
+ },
+ "jsonPath": {
+ "description": "JSONPath is a JSONPath expression. Refer to https://datatracker.ietf.org/doc/rfc9535/ for more details.\nIt produces one or more JSONPointer expressions based on the given JSON document.\nIf no JSONPointer is found, it will result in an error.\nIf the 'Path' property is also set, it will be appended to the resulting JSONPointer expressions from the JSONPath evaluation.\nThis is useful when creating a property that does not yet exist in the JSON document.\nThe final JSONPointer expressions specifies the locations in the target document/field where the operation will be applied.",
+ "type": "string"
+ },
+ "op": {
+ "description": "Op is the type of operation to perform",
+ "enum": [
+ "add",
+ "remove",
+ "replace",
+ "move",
+ "copy",
+ "test"
+ ],
+ "type": "string"
+ },
+ "path": {
+ "description": "Path is a JSONPointer expression. Refer to https://datatracker.ietf.org/doc/html/rfc6901 for more details.\nIt specifies the location of the target document/field where the operation will be performed",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the new value of the path location. The value is only used by\nthe `add` and `replace` operations.",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "op"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "type": {
+ "default": "Replace",
+ "description": "Type is the type of the bootstrap configuration, it should be either **Replace**, **Merge**, or **JSONPatch**.\nIf unspecified, it defaults to Replace.",
+ "enum": [
+ "Merge",
+ "Replace",
+ "JSONPatch"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is a YAML string of the bootstrap.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "provided bootstrap patch doesn't match the configured patch type",
+ "rule": "self.type == 'JSONPatch' ? self.jsonPatches.size() > 0 : has(self.value)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "concurrency": {
+ "description": "Concurrency defines the number of worker threads to run. If unset, it defaults to\nthe number of cpuset threads on the platform.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "dynamicModules": {
+ "description": "DynamicModules defines the set of dynamic modules that are allowed to be\nused by EnvoyExtensionPolicy resources and dynamic module load balancer\npolicies. Each entry registers a module by a logical name and specifies\nthe shared library that Envoy will load.\n\nThe EnvoyProxy owner is responsible for ensuring the module .so files are available\non the proxy container's filesystem (e.g., via init containers, custom images,\nor shared volumes).",
+ "items": {
+ "description": "DynamicModuleEntry defines a dynamic module that is registered and allowed\nfor use by EnvoyExtensionPolicy resources.",
+ "properties": {
+ "doNotClose": {
+ "default": false,
+ "description": "DoNotClose prevents the module from being unloaded with dlclose when no\nmore references exist. This is useful for modules that maintain global\nstate that should not be destroyed on configuration updates.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "loadGlobally": {
+ "default": false,
+ "description": "LoadGlobally loads the dynamic module with the RTLD_GLOBAL flag.\nBy default, modules are loaded with RTLD_LOCAL to avoid symbol conflicts.\nSet this to true when the module needs to share symbols with other\ndynamic libraries it loads.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name is the logical name for this module. EnvoyExtensionPolicy resources\nreference modules by this name.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "source": {
+ "description": "Source defines where the dynamic module code is loaded from.",
+ "properties": {
+ "local": {
+ "description": "Local specifies a module loaded from the proxy's local filesystem\nby absolute path.",
+ "properties": {
+ "path": {
+ "description": "Path is the absolute filesystem path to the dynamic module shared library (.so file).",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "remote": {
+ "description": "Remote specifies a module fetched from a remote source.\nThe module binary is downloaded and cached by Envoy.",
+ "properties": {
+ "sha256": {
+ "description": "SHA256 checksum that Envoy will use to verify the downloaded module binary.",
+ "pattern": "^[a-f0-9]{64}$",
+ "type": "string"
+ },
+ "url": {
+ "description": "URL is the HTTP or HTTPS URL of the dynamic module shared library (.so file).",
+ "maxLength": 4096,
+ "minLength": 1,
+ "pattern": "^https?://[^/?#]+(?:[/?#].*)?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "sha256",
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Local",
+ "description": "Type is the type of the source of the dynamic module code.\nDefaults to Local.",
+ "enum": [
+ "Local",
+ "Remote"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If type is Remote, remote field needs to be set.",
+ "rule": "self.type == 'Remote' ? has(self.remote) : !has(self.remote)"
+ },
+ {
+ "message": "If type is Local, local field needs to be set.",
+ "rule": "self.type != 'Local' || has(self.local)"
+ },
+ {
+ "message": "If type is Remote, local field must not be set.",
+ "rule": "self.type == 'Remote' ? !has(self.local) : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "source"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "extraArgs": {
+ "description": "ExtraArgs defines additional command line options that are provided to Envoy.\nMore info: https://www.envoyproxy.io/docs/envoy/latest/operations/cli#command-line-options\nNote: some command line options are used internally(e.g. --log-level) so they cannot be provided here.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "filterOrder": {
+ "description": "FilterOrder defines the order of filters in the Envoy proxy's HTTP filter chain.\nThe FilterPosition in the list will be applied in the order they are defined.\nIf unspecified, the default filter order is applied.\nDefault filter order is:\n\n- envoy.filters.http.custom_response\n\n- envoy.filters.http.health_check\n\n- envoy.filters.http.fault\n\n- envoy.filters.http.cors\n\n- envoy.filters.http.header_mutation\n\n- envoy.filters.http.ext_authz\n\n- envoy.filters.http.api_key_auth\n\n- envoy.filters.http.basic_auth\n\n- envoy.filters.http.oauth2\n\n- envoy.filters.http.jwt_authn\n\n- envoy.filters.http.stateful_session\n\n- envoy.filters.http.buffer\n\n- envoy.filters.http.lua\n\n- envoy.filters.http.ext_proc\n\n- envoy.filters.http.wasm\n\n- envoy.filters.http.dynamic_modules\n\n- envoy.filters.http.geoip\n\n- envoy.filters.http.rbac\n\n- envoy.filters.http.local_ratelimit\n\n- envoy.filters.http.ratelimit\n\n- envoy.filters.http.bandwidth_limit\n\n- envoy.filters.http.grpc_web\n\n- envoy.filters.http.grpc_stats\n\n- envoy.filters.http.credential_injector\n\n- envoy.filters.http.compressor\n\n- envoy.filters.http.dynamic_forward_proxy\n\n- envoy.filters.http.router\n\nNote: \"envoy.filters.http.router\" cannot be reordered, it's always the last filter in the chain.",
+ "items": {
+ "description": "FilterPosition defines the position of an Envoy HTTP filter in the filter chain.",
+ "properties": {
+ "after": {
+ "description": "After defines the filter that should come after the filter.\nOnly one of Before or After must be set.",
+ "enum": [
+ "envoy.filters.http.custom_response",
+ "envoy.filters.http.health_check",
+ "envoy.filters.http.fault",
+ "envoy.filters.http.cors",
+ "envoy.filters.http.header_mutation",
+ "envoy.filters.http.ext_authz",
+ "envoy.filters.http.api_key_auth",
+ "envoy.filters.http.basic_auth",
+ "envoy.filters.http.oauth2",
+ "envoy.filters.http.jwt_authn",
+ "envoy.filters.http.stateful_session",
+ "envoy.filters.http.buffer",
+ "envoy.filters.http.lua",
+ "envoy.filters.http.ext_proc",
+ "envoy.filters.http.wasm",
+ "envoy.filters.http.dynamic_modules",
+ "envoy.filters.http.geoip",
+ "envoy.filters.http.rbac",
+ "envoy.filters.http.local_ratelimit",
+ "envoy.filters.http.ratelimit",
+ "envoy.filters.http.bandwidth_limit",
+ "envoy.filters.http.grpc_web",
+ "envoy.filters.http.grpc_stats",
+ "envoy.filters.http.credential_injector",
+ "envoy.filters.http.compressor",
+ "envoy.filters.http.dynamic_forward_proxy"
+ ],
+ "type": "string"
+ },
+ "before": {
+ "description": "Before defines the filter that should come before the filter.\nOnly one of Before or After must be set.",
+ "enum": [
+ "envoy.filters.http.custom_response",
+ "envoy.filters.http.health_check",
+ "envoy.filters.http.fault",
+ "envoy.filters.http.cors",
+ "envoy.filters.http.header_mutation",
+ "envoy.filters.http.ext_authz",
+ "envoy.filters.http.api_key_auth",
+ "envoy.filters.http.basic_auth",
+ "envoy.filters.http.oauth2",
+ "envoy.filters.http.jwt_authn",
+ "envoy.filters.http.stateful_session",
+ "envoy.filters.http.buffer",
+ "envoy.filters.http.lua",
+ "envoy.filters.http.ext_proc",
+ "envoy.filters.http.wasm",
+ "envoy.filters.http.dynamic_modules",
+ "envoy.filters.http.geoip",
+ "envoy.filters.http.rbac",
+ "envoy.filters.http.local_ratelimit",
+ "envoy.filters.http.ratelimit",
+ "envoy.filters.http.bandwidth_limit",
+ "envoy.filters.http.grpc_web",
+ "envoy.filters.http.grpc_stats",
+ "envoy.filters.http.credential_injector",
+ "envoy.filters.http.compressor",
+ "envoy.filters.http.dynamic_forward_proxy"
+ ],
+ "type": "string"
+ },
+ "name": {
+ "description": "Name of the filter.",
+ "enum": [
+ "envoy.filters.http.custom_response",
+ "envoy.filters.http.health_check",
+ "envoy.filters.http.fault",
+ "envoy.filters.http.cors",
+ "envoy.filters.http.header_mutation",
+ "envoy.filters.http.ext_authz",
+ "envoy.filters.http.api_key_auth",
+ "envoy.filters.http.basic_auth",
+ "envoy.filters.http.oauth2",
+ "envoy.filters.http.jwt_authn",
+ "envoy.filters.http.stateful_session",
+ "envoy.filters.http.buffer",
+ "envoy.filters.http.lua",
+ "envoy.filters.http.ext_proc",
+ "envoy.filters.http.wasm",
+ "envoy.filters.http.dynamic_modules",
+ "envoy.filters.http.geoip",
+ "envoy.filters.http.rbac",
+ "envoy.filters.http.local_ratelimit",
+ "envoy.filters.http.ratelimit",
+ "envoy.filters.http.bandwidth_limit",
+ "envoy.filters.http.grpc_web",
+ "envoy.filters.http.grpc_stats",
+ "envoy.filters.http.credential_injector",
+ "envoy.filters.http.compressor",
+ "envoy.filters.http.dynamic_forward_proxy"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "one of before or after must be specified",
+ "rule": "(has(self.before) || has(self.after))"
+ },
+ {
+ "message": "only one of before or after can be specified",
+ "rule": "(has(self.before) && !has(self.after)) || (!has(self.before) && has(self.after))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "geoIP": {
+ "description": "GeoIP defines shared GeoIP provider configuration for this EnvoyProxy fleet.",
+ "properties": {
+ "provider": {
+ "description": "Provider defines the GeoIP provider configuration used by GeoIP filter instances.",
+ "properties": {
+ "maxMind": {
+ "description": "MaxMind configures the MaxMind provider.",
+ "properties": {
+ "anonymousIpDbSource": {
+ "description": "AnonymousIPDBSource configures the Anonymous IP database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "asnDbSource": {
+ "description": "ASNDBSource configures the ASN database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cityDbSource": {
+ "description": "CityDBSource configures the City database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "countryDbSource": {
+ "description": "CountryDBSource configures the Country database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ispDbSource": {
+ "description": "ISPDBSource configures the ISP database source.",
+ "properties": {
+ "local": {
+ "description": "Local is a database source from a local file.",
+ "properties": {
+ "path": {
+ "description": "Path is the path to the database file.",
+ "pattern": "^.*\\.mmdb$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "local"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one MaxMind database source must be specified",
+ "rule": "has(self.cityDbSource) || has(self.countryDbSource) || has(self.asnDbSource) || has(self.ispDbSource) || has(self.anonymousIpDbSource)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "GeoIPProviderType enumerates GeoIP providers supported by Envoy Gateway.",
+ "enum": [
+ "MaxMind"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "maxMind must be set when type is MaxMind",
+ "rule": "self.type == 'MaxMind' ? has(self.maxMind) : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ipFamily": {
+ "description": "IPFamily specifies the IP family for the EnvoyProxy fleet.\nThis setting only affects the Gateway listener port and does not impact\nother aspects of the Envoy proxy configuration.\nIf not specified, the system will operate as follows:\n- It defaults to IPv4 only.\n- IPv6 and dual-stack environments are not supported in this default configuration.\nNote: To enable IPv6 or dual-stack functionality, explicit configuration is required.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "DualStack"
+ ],
+ "type": "string"
+ },
+ "logging": {
+ "default": {
+ "level": {
+ "default": "warn"
+ }
+ },
+ "description": "Logging defines logging parameters for managed proxies.",
+ "properties": {
+ "level": {
+ "additionalProperties": {
+ "description": "LogLevel defines a log level for Envoy Gateway and EnvoyProxy system logs.",
+ "enum": [
+ "trace",
+ "debug",
+ "info",
+ "warn",
+ "error"
+ ],
+ "type": "string"
+ },
+ "default": {
+ "default": "warn"
+ },
+ "description": "Level is a map of logging level per component, where the component is the key\nand the log level is the value. If unspecified, defaults to \"default: warn\".",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "luaValidation": {
+ "description": "LuaValidation determines strictness of the Lua script validation for Lua EnvoyExtensionPolicies\nDefault: Strict",
+ "enum": [
+ "Strict",
+ "InsecureSyntax",
+ "Disabled"
+ ],
+ "type": "string"
+ },
+ "mergeGateways": {
+ "description": "MergeGateways defines if Gateway resources should be merged onto the same Envoy Proxy Infrastructure.\nSetting this field to true would merge all Gateway Listeners under the parent Gateway Class.\nThis means that the port, protocol and hostname tuple must be unique for every listener.\nIf a duplicate listener is detected, the newer listener (based on timestamp) will be rejected and its status will be updated with a \"Accepted=False\" condition.",
+ "type": "boolean"
+ },
+ "mergeType": {
+ "description": "MergeType controls how this EnvoyProxy merges with less specific configurations\nin the hierarchy (EnvoyGateway defaults < GatewayClass < Gateway).\nIf unset, this EnvoyProxy completely replaces less specific settings.\nNote: this field has no effect when set in EnvoyGateway's default EnvoyProxySpec.",
+ "enum": [
+ "Replace",
+ "StrategicMerge",
+ "JSONMerge"
+ ],
+ "type": "string"
+ },
+ "preserveRouteOrder": {
+ "description": "PreserveRouteOrder determines if the order of matching for HTTPRoutes is determined by Gateway-API\nspecification (https://gateway-api.sigs.k8s.io/reference/1.4/spec/#httprouterule)\nor preserves the order defined by users in the HTTPRoute's HTTPRouteRule list.\nDefault: False",
+ "type": "boolean"
+ },
+ "provider": {
+ "description": "Provider defines the desired resource provider and provider-specific configuration.\nIf unspecified, the \"Kubernetes\" resource provider is used with default configuration\nparameters.",
+ "properties": {
+ "host": {
+ "description": "Host provides runtime deployment of the data plane as a child process on the\nhost environment.\nIf unspecified and type is \"Host\", default settings for the custom provider\nare applied.",
+ "properties": {
+ "envoyVersion": {
+ "description": "EnvoyVersion is the version of Envoy to use. If unspecified, the version\nagainst which Envoy Gateway is built will be used.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "kubernetes": {
+ "description": "Kubernetes defines the desired state of the Kubernetes resource provider.\nKubernetes provides infrastructure resources for running the data plane,\ne.g. Envoy proxy. If unspecified and type is \"Kubernetes\", default settings\nfor managed Kubernetes resources are applied.",
+ "properties": {
+ "envoyDaemonSet": {
+ "description": "EnvoyDaemonSet defines the desired state of the Envoy daemonset resource.\nDisabled by default, a deployment resource is used instead to provision the Envoy Proxy fleet",
+ "properties": {
+ "container": {
+ "description": "Container defines the desired specification of main container.",
+ "properties": {
+ "env": {
+ "description": "List of environment variables to set in the container.",
+ "items": {
+ "description": "EnvVar represents an environment variable present in a Container.",
+ "properties": {
+ "name": {
+ "description": "Name of the environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Variable references $(VAR_NAME) are expanded\nusing the previously defined environment variables in the container and\nany service environment variables. If a variable cannot be resolved,\nthe reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.\n\"$$(VAR_NAME)\" will produce the string literal \"$(VAR_NAME)\".\nEscaped references will never be expanded, regardless of whether the variable\nexists or not.\nDefaults to \"\".",
+ "type": "string"
+ },
+ "valueFrom": {
+ "description": "Source for the environment variable's value. Cannot be used if value is not empty.",
+ "properties": {
+ "configMapKeyRef": {
+ "description": "Selects a key of a ConfigMap.",
+ "properties": {
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fieldRef": {
+ "description": "Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`,\nspec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fileKeyRef": {
+ "description": "FileKeyRef selects a key of the env file.\nRequires the EnvFiles feature gate to be enabled.",
+ "properties": {
+ "key": {
+ "description": "The key within the env file. An invalid key will prevent the pod from starting.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nDuring Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.",
+ "type": "string"
+ },
+ "optional": {
+ "default": false,
+ "description": "Specify whether the file or its key must be defined. If the file or key\ndoes not exist, then the env var is not published.\nIf optional is set to true and the specified key does not exist,\nthe environment variable will not be set in the Pod's containers.\n\nIf optional is set to false and the specified key does not exist,\nan error will be returned during Pod creation.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "The path within the volume from which to select the file.\nMust be relative and may not contain the '..' path or start with '..'.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "The name of the volume mount containing the env file.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path",
+ "volumeName"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "secretKeyRef": {
+ "description": "Selects a key of a secret in the pod's namespace",
+ "properties": {
+ "key": {
+ "description": "The key of the secret to select from. Must be a valid secret key.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "image": {
+ "description": "Image specifies the EnvoyProxy container image to be used including a tag, instead of the default image.\nThis field is mutually exclusive with ImageRepository.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Image must include a tag and allowed characters only (e.g., 'repo:tag').",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?(/[a-zA-Z0-9._/-]+)?(:[a-zA-Z0-9._-]+)?(@sha256:[a-z0-9]+)?$')"
+ }
+ ]
+ },
+ "imageRepository": {
+ "description": "ImageRepository specifies the container image repository to be used without specifying a tag.\nThe default tag will be used.\nThis field is mutually exclusive with Image.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "ImageRepository must contain only allowed characters and must not include a tag.",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?[a-zA-Z0-9._/-]+$')"
+ }
+ ]
+ },
+ "resources": {
+ "description": "Resources required by this container.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "securityContext": {
+ "description": "SecurityContext defines the security options the container should be run with.\nIf set, the fields of SecurityContext override the equivalent fields of PodSecurityContext.\nMore info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/",
+ "properties": {
+ "allowPrivilegeEscalation": {
+ "description": "AllowPrivilegeEscalation controls whether a process can gain more\nprivileges than its parent process. This bool directly controls if\nthe no_new_privs flag will be set on the container process.\nAllowPrivilegeEscalation is true always when the container is:\n1) run as Privileged\n2) has CAP_SYS_ADMIN\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by this container. If set, this profile\noverrides the pod's appArmorProfile.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "capabilities": {
+ "description": "The capabilities to add/drop when running containers.\nDefaults to the default set of capabilities granted by the container runtime.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "add": {
+ "description": "Added capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "drop": {
+ "description": "Removed capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "privileged": {
+ "description": "Run container in privileged mode.\nProcesses in privileged containers are essentially equivalent to root on the host.\nDefaults to false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "procMount": {
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "readOnlyRootFilesystem": {
+ "description": "Whether this container has a read-only root filesystem.\nDefault is false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to the container.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by this container. If seccomp options are\nprovided at both the pod & container level, the container options\noverride the pod options.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options from the PodSecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "volumeMounts": {
+ "description": "VolumeMounts are volumes to mount into the container's filesystem.\nCannot be updated.",
+ "items": {
+ "description": "VolumeMount describes a mounting of a Volume within a container.",
+ "properties": {
+ "mountPath": {
+ "description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
+ "type": "string"
+ },
+ "mountPropagation": {
+ "description": "mountPropagation determines how mounts are propagated from the host\nto container and the other way around.\nWhen not set, MountPropagationNone is used.\nThis field is beta in 1.10.\nWhen RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified\n(which defaults to None).",
+ "type": "string"
+ },
+ "name": {
+ "description": "This must match the Name of a Volume.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "Mounted read-only if true, read-write otherwise (false or unspecified).\nDefaults to false.",
+ "type": "boolean"
+ },
+ "recursiveReadOnly": {
+ "description": "RecursiveReadOnly specifies whether read-only mounts should be handled\nrecursively.\n\nIf ReadOnly is false, this field has no meaning and must be unspecified.\n\nIf ReadOnly is true, and this field is set to Disabled, the mount is not made\nrecursively read-only. If this field is set to IfPossible, the mount is made\nrecursively read-only, if it is supported by the container runtime. If this\nfield is set to Enabled, the mount is made recursively read-only if it is\nsupported by the container runtime, otherwise the pod will not be started and\nan error will be generated to indicate the reason.\n\nIf this field is set to IfPossible or Enabled, MountPropagation must be set to\nNone (or be unspecified, which defaults to None).\n\nIf this field is not specified, it is treated as an equivalent of Disabled.",
+ "type": "string"
+ },
+ "subPath": {
+ "description": "Path within the volume from which the container's volume should be mounted.\nDefaults to \"\" (volume's root).",
+ "type": "string"
+ },
+ "subPathExpr": {
+ "description": "Expanded path within the volume from which the container's volume should be mounted.\nBehaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.\nDefaults to \"\" (volume's root).\nSubPathExpr and SubPath are mutually exclusive.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "mountPath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Either image or imageRepository can be set.",
+ "rule": "!has(self.image) || !has(self.imageRepository)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Name of the daemonSet.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to daemonset",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pod": {
+ "description": "Pod defines the desired specification of pod.",
+ "properties": {
+ "affinity": {
+ "description": "If specified, the pod's scheduling constraints.",
+ "properties": {
+ "nodeAffinity": {
+ "description": "Describes node affinity scheduling rules for the pod.",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node matches the corresponding matchExpressions; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "An empty preferred scheduling term matches all objects with implicit weight 0\n(i.e. it's a no-op). A null preferred scheduling term matches no objects (i.e. is also a no-op).",
+ "properties": {
+ "preference": {
+ "description": "A node selector term, associated with the corresponding weight.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "Weight associated with matching the corresponding nodeSelectorTerm, in the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "preference",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to an update), the system\nmay or may not try to eventually evict the pod from its node.",
+ "properties": {
+ "nodeSelectorTerms": {
+ "description": "Required. A list of node selector terms. The terms are ORed.",
+ "items": {
+ "description": "A null or empty node selector term matches no objects. The requirements of\nthem are ANDed.\nThe TopologySelectorTerm type implements a subset of the NodeSelectorTerm.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "nodeSelectorTerms"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAffinity": {
+ "description": "Describes pod affinity scheduling rules (e.g. co-locate this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAntiAffinity": {
+ "description": "Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe anti-affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling anti-affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and subtracting\n\"weight\" from the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the anti-affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the anti-affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "annotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Annotations are the annotations that should be appended to the pods.\nBy default, no pod annotations are appended.",
+ "type": "object"
+ },
+ "imagePullSecrets": {
+ "description": "ImagePullSecrets is an optional list of references to secrets\nin the same namespace to use for pulling any of the images used by this PodSpec.\nIf specified, these secrets will be passed to individual puller implementations for them to use.\nMore info: https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod",
+ "items": {
+ "description": "LocalObjectReference contains enough information to let you locate the\nreferenced object inside the same namespace.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "labels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Labels are the additional labels that should be tagged to the pods.\nBy default, no additional pod labels are tagged.",
+ "type": "object"
+ },
+ "nodeSelector": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "NodeSelector is a selector which must be true for the pod to fit on a node.\nSelector which must match a node's labels for the pod to be scheduled on that node.\nMore info: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/",
+ "type": "object"
+ },
+ "priorityClassName": {
+ "description": "PriorityClassName indicates the importance of a Pod relative to other Pods.\nIf a PriorityClassName is not specified, the pod priority will be default or zero if there is no default.\nMore info: https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/",
+ "type": "string"
+ },
+ "securityContext": {
+ "description": "SecurityContext holds pod-level security attributes and common container settings.\nOptional: Defaults to empty. See type description for default values of each field.",
+ "properties": {
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fsGroup": {
+ "description": "A special supplemental group that applies to all containers in a pod.\nSome volume types allow the Kubelet to change the ownership of that volume\nto be owned by the pod:\n\n1. The owning GID will be the FSGroup\n2. The setgid bit is set (new files created in the volume will be owned by FSGroup)\n3. The permission bits are OR'd with rw-rw----\n\nIf unset, the Kubelet will not modify the ownership and permissions of any volume.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "fsGroupChangePolicy": {
+ "description": "fsGroupChangePolicy defines behavior of changing ownership and permission of the volume\nbefore being exposed inside Pod. This field will only apply to\nvolume types which support fsGroup based ownership(and permissions).\nIt will have no effect on ephemeral volume types such as: secret, configmaps\nand emptydir.\nValid values are \"OnRootMismatch\" and \"Always\". If not specified, \"Always\" is used.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxChangePolicy": {
+ "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to all containers.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in SecurityContext. If set in\nboth SecurityContext and PodSecurityContext, the value specified in SecurityContext\ntakes precedence for that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "supplementalGroups": {
+ "description": "A list of groups applied to the first process run in each container, in\naddition to the container's primary GID and fsGroup (if specified). If\nthe SupplementalGroupsPolicy feature is enabled, the\nsupplementalGroupsPolicy field determines whether these are in addition\nto or instead of any group memberships defined in the container image.\nIf unspecified, no additional groups are added, though group memberships\ndefined in the container image may still be used, depending on the\nsupplementalGroupsPolicy field.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "format": "int64",
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "supplementalGroupsPolicy": {
+ "description": "Defines how supplemental groups of the first container processes are calculated.\nValid values are \"Merge\" and \"Strict\". If not specified, \"Merge\" is used.\n(Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled\nand the container runtime must implement support for this feature.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "sysctls": {
+ "description": "Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported\nsysctls (by the container runtime) might fail to launch.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "description": "Sysctl defines a kernel parameter to be set",
+ "properties": {
+ "name": {
+ "description": "Name of a property to set",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of a property to set",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options within a container's SecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tolerations": {
+ "description": "If specified, the pod's tolerations.",
+ "items": {
+ "description": "The pod this Toleration is attached to tolerates any taint that matches\nthe triple using the matching operator .",
+ "properties": {
+ "effect": {
+ "description": "Effect indicates the taint effect to match. Empty means match all taint effects.\nWhen specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.",
+ "type": "string"
+ },
+ "key": {
+ "description": "Key is the taint key that the toleration applies to. Empty means match all taint keys.\nIf the key is empty, operator must be Exists; this combination means to match all values and all keys.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Operator represents a key's relationship to the value.\nValid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.\nExists is equivalent to wildcard for value, so that a pod can\ntolerate all taints of a particular category.\nLt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).",
+ "type": "string"
+ },
+ "tolerationSeconds": {
+ "description": "TolerationSeconds represents the period of time the toleration (which must be\nof effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,\nit is not set, which means tolerate the taint forever (do not evict). Zero and\nnegative values will be treated as 0 (evict immediately) by the system.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "value": {
+ "description": "Value is the taint value the toleration matches to.\nIf the operator is Exists, the value should be empty, otherwise just a regular string.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "topologySpreadConstraints": {
+ "description": "TopologySpreadConstraints describes how a group of pods ought to spread across topology\ndomains. Scheduler will schedule pods in a way which abides by the constraints.\nAll topologySpreadConstraints are ANDed.",
+ "items": {
+ "description": "TopologySpreadConstraint specifies how to spread matching pods among the given topology.",
+ "properties": {
+ "labelSelector": {
+ "description": "LabelSelector is used to find matching pods.\nPods that match this label selector are counted to determine the number of pods\nin their corresponding topology domain.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select the pods over which\nspreading will be calculated. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are ANDed with labelSelector\nto select the group of existing pods over which spreading will be calculated\nfor the incoming pod. The same key is forbidden to exist in both MatchLabelKeys and LabelSelector.\nMatchLabelKeys cannot be set when LabelSelector isn't set.\nKeys that don't exist in the incoming pod labels will\nbe ignored. A null or empty list means only match against labelSelector.\n\nThis is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate to be enabled (enabled by default).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "maxSkew": {
+ "description": "MaxSkew describes the degree to which pods may be unevenly distributed.\nWhen `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference\nbetween the number of matching pods in the target topology and the global minimum.\nThe global minimum is the minimum number of matching pods in an eligible domain\nor zero if the number of eligible domains is less than MinDomains.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 2/2/1:\nIn this case, the global minimum is 1.\n| zone1 | zone2 | zone3 |\n| P P | P P | P |\n- if MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2;\nscheduling it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2)\nviolate MaxSkew(1).\n- if MaxSkew is 2, incoming pod can be scheduled onto any zone.\nWhen `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence\nto topologies that satisfy it.\nIt's a required field. Default value is 1 and 0 is not allowed.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "minDomains": {
+ "description": "MinDomains indicates a minimum number of eligible domains.\nWhen the number of eligible domains with matching topology keys is less than minDomains,\nPod Topology Spread treats \"global minimum\" as 0, and then the calculation of Skew is performed.\nAnd when the number of eligible domains with matching topology keys equals or greater than minDomains,\nthis value has no effect on scheduling.\nAs a result, when the number of eligible domains is less than minDomains,\nscheduler won't schedule more than maxSkew Pods to those domains.\nIf value is nil, the constraint behaves as if MinDomains is equal to 1.\nValid values are integers greater than 0.\nWhen value is not nil, WhenUnsatisfiable must be DoNotSchedule.\n\nFor example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and pods with the same\nlabelSelector spread as 2/2/2:\n| zone1 | zone2 | zone3 |\n| P P | P P | P P |\nThe number of domains is less than 5(MinDomains), so \"global minimum\" is treated as 0.\nIn this situation, new pod with the same labelSelector cannot be scheduled,\nbecause computed skew will be 3(3 - 0) if new Pod is scheduled to any of the three zones,\nit will violate MaxSkew.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "nodeAffinityPolicy": {
+ "description": "NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector\nwhen calculating pod topology spread skew. Options are:\n- Honor: only nodes matching nodeAffinity/nodeSelector are included in the calculations.\n- Ignore: nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.\n\nIf this value is nil, the behavior is equivalent to the Honor policy.",
+ "type": "string"
+ },
+ "nodeTaintsPolicy": {
+ "description": "NodeTaintsPolicy indicates how we will treat node taints when calculating\npod topology spread skew. Options are:\n- Honor: nodes without taints, along with tainted nodes for which the incoming pod\nhas a toleration, are included.\n- Ignore: node taints are ignored. All nodes are included.\n\nIf this value is nil, the behavior is equivalent to the Ignore policy.",
+ "type": "string"
+ },
+ "topologyKey": {
+ "description": "TopologyKey is the key of node labels. Nodes that have a label with this key\nand identical values are considered to be in the same topology.\nWe consider each as a \"bucket\", and try to put balanced number\nof pods into each bucket.\nWe define a domain as a particular instance of a topology.\nAlso, we define an eligible domain as a domain whose nodes meet the requirements of\nnodeAffinityPolicy and nodeTaintsPolicy.\ne.g. If TopologyKey is \"kubernetes.io/hostname\", each Node is a domain of that topology.\nAnd, if TopologyKey is \"topology.kubernetes.io/zone\", each zone is a domain of that topology.\nIt's a required field.",
+ "type": "string"
+ },
+ "whenUnsatisfiable": {
+ "description": "WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy\nthe spread constraint.\n- DoNotSchedule (default) tells the scheduler not to schedule it.\n- ScheduleAnyway tells the scheduler to schedule the pod in any location,\n but giving higher precedence to topologies that would help reduce the\n skew.\nA constraint is considered \"Unsatisfiable\" for an incoming pod\nif and only if every possible node assignment for that pod would violate\n\"MaxSkew\" on some topology.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 3/1/1:\n| zone1 | zone2 | zone3 |\n| P P P | P | P |\nIf WhenUnsatisfiable is set to DoNotSchedule, incoming pod can only be scheduled\nto zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies\nMaxSkew(1). In other words, the cluster can still be imbalanced, but scheduler\nwon't make it *more* imbalanced.\nIt's a required field.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "maxSkew",
+ "topologyKey",
+ "whenUnsatisfiable"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "volumes": {
+ "description": "Volumes that can be mounted by containers belonging to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes",
+ "items": {
+ "description": "Volume represents a named volume in a pod that may be accessed by any container in the pod.",
+ "properties": {
+ "awsElasticBlockStore": {
+ "description": "awsElasticBlockStore represents an AWS Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: AWSElasticBlockStore is deprecated. All operations for the in-tree\nawsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly value true will force the readOnly setting in VolumeMounts.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureDisk": {
+ "description": "azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.\nDeprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type\nare redirected to the disk.csi.azure.com CSI driver.",
+ "properties": {
+ "cachingMode": {
+ "description": "cachingMode is the Host Caching mode: None, Read Only, Read Write.",
+ "type": "string"
+ },
+ "diskName": {
+ "description": "diskName is the Name of the data disk in the blob storage",
+ "type": "string"
+ },
+ "diskURI": {
+ "description": "diskURI is the URI of data disk in the blob storage",
+ "type": "string"
+ },
+ "fsType": {
+ "default": "ext4",
+ "description": "fsType is Filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "kind expected values are Shared: multiple blob disks per storage account Dedicated: single blob disk per storage account Managed: azure managed data disk (only in managed availability set). defaults to shared",
+ "type": "string"
+ },
+ "readOnly": {
+ "default": false,
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "diskName",
+ "diskURI"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureFile": {
+ "description": "azureFile represents an Azure File Service mount on the host and bind mount to the pod.\nDeprecated: AzureFile is deprecated. All operations for the in-tree azureFile type\nare redirected to the file.csi.azure.com CSI driver.",
+ "properties": {
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of secret that contains Azure Storage Account Name and Key",
+ "type": "string"
+ },
+ "shareName": {
+ "description": "shareName is the azure share Name",
+ "type": "string"
+ }
+ },
+ "required": [
+ "secretName",
+ "shareName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cephfs": {
+ "description": "cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.\nDeprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.",
+ "properties": {
+ "monitors": {
+ "description": "monitors is Required: Monitors is a collection of Ceph monitors\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretFile": {
+ "description": "secretFile is Optional: SecretFile is the path to key ring for User, default is /etc/ceph/user.secret\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: SecretRef is reference to the authentication secret for User, default is empty.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "description": "user is optional: User is the rados user name, default is admin\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cinder": {
+ "description": "cinder represents a cinder volume attached and mounted on kubelets host machine.\nDeprecated: Cinder is deprecated. All operations for the in-tree cinder type\nare redirected to the cinder.csi.openstack.org CSI driver.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is optional: points to a secret object containing parameters used to connect\nto OpenStack.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeID": {
+ "description": "volumeID used to identify the volume in cinder.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap represents a configMap that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "csi": {
+ "description": "csi (Container Storage Interface) represents ephemeral storage that is handled by certain external CSI drivers.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the CSI driver that handles this volume.\nConsult with your admin for the correct name as registered in the cluster.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType to mount. Ex. \"ext4\", \"xfs\", \"ntfs\".\nIf not provided, the empty value is passed to the associated CSI driver\nwhich will determine the default filesystem to apply.",
+ "type": "string"
+ },
+ "nodePublishSecretRef": {
+ "description": "nodePublishSecretRef is a reference to the secret object containing\nsensitive information to pass to the CSI driver to complete the CSI\nNodePublishVolume and NodeUnpublishVolume calls.\nThis field is optional, and may be empty if no secret is required. If the\nsecret object contains more than one secret, all secret references are passed.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "readOnly": {
+ "description": "readOnly specifies a read-only configuration for the volume.\nDefaults to false (read/write).",
+ "type": "boolean"
+ },
+ "volumeAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "volumeAttributes stores driver-specific properties that are passed to the CSI\ndriver. Consult your driver's documentation for supported values.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI represents downward API about the pod that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "Optional: mode bits to use on created files by default. Must be a\nOptional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "Items is a list of downward API volume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emptyDir": {
+ "description": "emptyDir represents a temporary directory that shares a pod's lifetime.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "properties": {
+ "medium": {
+ "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "type": "string"
+ },
+ "sizeLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "sizeLimit is the total amount of local storage required for this EmptyDir volume.\nThe size limit is also applicable for memory medium.\nThe maximum usage on memory medium EmptyDir would be the minimum value between\nthe SizeLimit specified here and the sum of memory limits of all containers in a pod.\nThe default is nil which means that the limit is undefined.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ephemeral": {
+ "description": "ephemeral represents a volume that is handled by a cluster storage driver.\nThe volume's lifecycle is tied to the pod that defines it - it will be created before the pod starts,\nand deleted when the pod is removed.\n\nUse this if:\na) the volume is only needed while the pod runs,\nb) features of normal volumes like restoring from snapshot or capacity\n tracking are needed,\nc) the storage driver is specified through a storage class, and\nd) the storage driver supports dynamic volume provisioning through\n a PersistentVolumeClaim (see EphemeralVolumeSource for more\n information on the connection between this volume type\n and PersistentVolumeClaim).\n\nUse PersistentVolumeClaim or one of the vendor-specific\nAPIs for volumes that persist for longer than the lifecycle\nof an individual pod.\n\nUse CSI for light-weight local ephemeral volumes if the CSI driver is meant to\nbe used that way - see the documentation of the driver for\nmore information.\n\nA pod can use both types of ephemeral volumes and\npersistent volumes at the same time.",
+ "properties": {
+ "volumeClaimTemplate": {
+ "description": "Will be used to create a stand-alone PVC to provision the volume.\nThe pod in which this EphemeralVolumeSource is embedded will be the\nowner of the PVC, i.e. the PVC will be deleted together with the\npod. The name of the PVC will be `-` where\n`` is the name from the `PodSpec.Volumes` array\nentry. Pod validation will reject the pod if the concatenated name\nis not valid for a PVC (for example, too long).\n\nAn existing PVC with that name that is not owned by the pod\nwill *not* be used for the pod to avoid using an unrelated\nvolume by mistake. Starting the pod is then blocked until\nthe unrelated PVC is removed. If such a pre-created PVC is\nmeant to be used by the pod, the PVC has to updated with an\nowner reference to the pod once the pod exists. Normally\nthis should not be necessary, but it may be useful when\nmanually reconstructing a broken cluster.\n\nThis field is read-only and no changes will be made by Kubernetes\nto the PVC after it has been created.\n\nRequired, must not be nil.",
+ "properties": {
+ "metadata": {
+ "description": "May contain labels and annotations that will be copied into the PVC\nwhen creating it. No other fields are allowed and will be rejected during\nvalidation.",
+ "type": "object"
+ },
+ "spec": {
+ "description": "The specification for the PersistentVolumeClaim. The entire content is\ncopied unchanged into the PVC that gets created from this\ntemplate. The same fields as in a PersistentVolumeClaim\nare also valid here.",
+ "properties": {
+ "accessModes": {
+ "description": "accessModes contains the desired access modes the volume should have.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "dataSource": {
+ "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "dataSourceRef": {
+ "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of resource being referenced\nNote that when a namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is required in the referent namespace to allow that namespace's owner to accept the reference. See the ReferenceGrant documentation for details.\n(Alpha) This field requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resources": {
+ "description": "resources represents the minimum resources the volume should have.\nUsers are allowed to specify resource requirements\nthat are lower than previous value but must still be higher than capacity recorded in the\nstatus field of the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources",
+ "properties": {
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "selector": {
+ "description": "selector is a label query over volumes to consider for binding.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "storageClassName": {
+ "description": "storageClassName is the name of the StorageClass required by the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1",
+ "type": "string"
+ },
+ "volumeAttributesClassName": {
+ "description": "volumeAttributesClassName may be used to set the VolumeAttributesClass used by this claim.\nIf specified, the CSI driver will create or update the volume with the attributes defined\nin the corresponding VolumeAttributesClass. This has a different purpose than storageClassName,\nit can be changed after the claim is created. An empty string or nil value indicates that no\nVolumeAttributesClass will be applied to the claim. If the claim enters an Infeasible error state,\nthis field can be reset to its previous value (including nil) to cancel the modification.\nIf the resource referred to by volumeAttributesClass does not exist, this PersistentVolumeClaim will be\nset to a Pending state, as reflected by the modifyVolumeStatus field, until such as a resource\nexists.\nMore info: https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/",
+ "type": "string"
+ },
+ "volumeMode": {
+ "description": "volumeMode defines what type of volume is required by the claim.\nValue of Filesystem is implied when not included in claim spec.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the binding reference to the PersistentVolume backing this claim.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fc": {
+ "description": "fc represents a Fibre Channel resource that is attached to a kubelet's host machine and then exposed to the pod.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun is Optional: FC target lun number",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "targetWWNs": {
+ "description": "targetWWNs is Optional: FC target worldwide names (WWNs)",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "wwids": {
+ "description": "wwids Optional: FC volume world wide identifiers (wwids)\nEither wwids or combination of targetWWNs and lun must be set, but not both simultaneously.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flexVolume": {
+ "description": "flexVolume represents a generic volume resource that is\nprovisioned/attached using an exec based plugin.\nDeprecated: FlexVolume is deprecated. Consider using a CSIDriver instead.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the driver to use for this volume.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". The default filesystem depends on FlexVolume script.",
+ "type": "string"
+ },
+ "options": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "options is Optional: this field holds extra command options if any.",
+ "type": "object"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: secretRef is reference to the secret object containing\nsensitive information to pass to the plugin scripts. This may be\nempty if no secret object is specified. If the secret object\ncontains more than one secret, all secrets are passed to the plugin\nscripts.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flocker": {
+ "description": "flocker represents a Flocker volume attached to a kubelet's host machine. This depends on the Flocker control service being running.\nDeprecated: Flocker is deprecated and the in-tree flocker type is no longer supported.",
+ "properties": {
+ "datasetName": {
+ "description": "datasetName is Name of the dataset stored as metadata -> name on the dataset for Flocker\nshould be considered as deprecated",
+ "type": "string"
+ },
+ "datasetUUID": {
+ "description": "datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker dataset",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gcePersistentDisk": {
+ "description": "gcePersistentDisk represents a GCE Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: GCEPersistentDisk is deprecated. All operations for the in-tree\ngcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "format": "int32",
+ "type": "integer"
+ },
+ "pdName": {
+ "description": "pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "pdName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gitRepo": {
+ "description": "gitRepo represents a git repository at a particular revision.\nDeprecated: GitRepo is deprecated. To provision a container with a git repo, mount an\nEmptyDir into an InitContainer that clones the repo using git, then mount the EmptyDir\ninto the Pod's container.",
+ "properties": {
+ "directory": {
+ "description": "directory is the target directory name.\nMust not contain or start with '..'. If '.' is supplied, the volume directory will be the\ngit repository. Otherwise, if specified, the volume will contain the git repository in\nthe subdirectory with the given name.",
+ "type": "string"
+ },
+ "repository": {
+ "description": "repository is the URL",
+ "type": "string"
+ },
+ "revision": {
+ "description": "revision is the commit hash for the specified revision.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "repository"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "glusterfs": {
+ "description": "glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.\nDeprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer supported.",
+ "properties": {
+ "endpoints": {
+ "description": "endpoints is the endpoint name that details Glusterfs topology.",
+ "type": "string"
+ },
+ "path": {
+ "description": "path is the Glusterfs volume path.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Glusterfs volume to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "endpoints",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostPath": {
+ "description": "hostPath represents a pre-existing file or directory on the host\nmachine that is directly exposed to the container. This is generally\nused for system agents or other privileged things that are allowed\nto see the host machine. Most containers will NOT need this.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "properties": {
+ "path": {
+ "description": "path of the directory on the host.\nIf the path is a symlink, it will follow the link to the real path.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ },
+ "type": {
+ "description": "type for HostPath Volume\nDefaults to \"\"\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "image": {
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "properties": {
+ "pullPolicy": {
+ "description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
+ "type": "string"
+ },
+ "reference": {
+ "description": "Required: Image or artifact reference to be used.\nBehaves in the same way as pod.spec.containers[*].image.\nPull secrets will be assembled in the same way as for the container image by looking up node credentials, SA image pull secrets, and pod spec image pull secrets.\nMore info: https://kubernetes.io/docs/concepts/containers/images\nThis field is optional to allow higher level config management to default or override\ncontainer images in workload controllers like Deployments and StatefulSets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "iscsi": {
+ "description": "iscsi represents an ISCSI Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes/#iscsi",
+ "properties": {
+ "chapAuthDiscovery": {
+ "description": "chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication",
+ "type": "boolean"
+ },
+ "chapAuthSession": {
+ "description": "chapAuthSession defines whether support iSCSI Session CHAP authentication",
+ "type": "boolean"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#iscsi",
+ "type": "string"
+ },
+ "initiatorName": {
+ "description": "initiatorName is the custom iSCSI Initiator Name.\nIf initiatorName is specified with iscsiInterface simultaneously, new iSCSI interface\n: will be created for the connection.",
+ "type": "string"
+ },
+ "iqn": {
+ "description": "iqn is the target iSCSI Qualified Name.",
+ "type": "string"
+ },
+ "iscsiInterface": {
+ "default": "default",
+ "description": "iscsiInterface is the interface Name that uses an iSCSI transport.\nDefaults to 'default' (tcp).",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun represents iSCSI Target Lun number.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "portals": {
+ "description": "portals is the iSCSI Target Portal List. The portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is the CHAP Secret for iSCSI target and initiator authentication",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "targetPortal": {
+ "description": "targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "iqn",
+ "lun",
+ "targetPortal"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "name of the volume.\nMust be a DNS_LABEL and unique within the pod.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "nfs": {
+ "description": "nfs represents an NFS mount on the host that shares a pod's lifetime\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "properties": {
+ "path": {
+ "description": "path that is exported by the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the NFS export to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "boolean"
+ },
+ "server": {
+ "description": "server is the hostname or IP address of the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "persistentVolumeClaim": {
+ "description": "persistentVolumeClaimVolumeSource represents a reference to a\nPersistentVolumeClaim in the same namespace.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "properties": {
+ "claimName": {
+ "description": "claimName is the name of a PersistentVolumeClaim in the same namespace as the pod using this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Will force the ReadOnly setting in VolumeMounts.\nDefault false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "claimName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "photonPersistentDisk": {
+ "description": "photonPersistentDisk represents a PhotonController persistent disk attached and mounted on kubelets host machine.\nDeprecated: PhotonPersistentDisk is deprecated and the in-tree photonPersistentDisk type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "pdID": {
+ "description": "pdID is the ID that identifies Photon Controller persistent disk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "pdID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "portworxVolume": {
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID uniquely identifies a Portworx volume",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "projected": {
+ "description": "projected items for all in one resources secrets, configmaps, and downward API",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode are the mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "sources": {
+ "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
+ "items": {
+ "description": "Projection that may be projected along with other supported volume types.\nExactly one of these fields must be set.",
+ "properties": {
+ "clusterTrustBundle": {
+ "description": "ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field\nof ClusterTrustBundle objects in an auto-updating file.\n\nAlpha, gated by the ClusterTrustBundleProjection feature gate.\n\nClusterTrustBundle objects can either be selected by name, or by the\ncombination of signer name and a label selector.\n\nKubelet performs aggressive normalization of the PEM contents written\ninto the pod filesystem. Esoteric PEM features such as inter-block\ncomments and block headers are stripped. Certificates are deduplicated.\nThe ordering of certificates within the file is arbitrary, and Kubelet\nmay change the order over time.",
+ "properties": {
+ "labelSelector": {
+ "description": "Select all ClusterTrustBundles that match this label selector. Only has\neffect if signerName is set. Mutually-exclusive with name. If unset,\ninterpreted as \"match nothing\". If set but empty, interpreted as \"match\neverything\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Select a single ClusterTrustBundle by object name. Mutually-exclusive\nwith signerName and labelSelector.",
+ "type": "string"
+ },
+ "optional": {
+ "description": "If true, don't block pod startup if the referenced ClusterTrustBundle(s)\naren't available. If using name, then the named ClusterTrustBundle is\nallowed not to exist. If using signerName, then the combination of\nsignerName and labelSelector is allowed to match zero\nClusterTrustBundles.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "Relative path from the volume root to write the bundle.",
+ "type": "string"
+ },
+ "signerName": {
+ "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap information about the configMap data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI information about the downwardAPI data to project",
+ "properties": {
+ "items": {
+ "description": "Items is a list of DownwardAPIVolume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podCertificate": {
+ "description": "Projects an auto-rotating credential bundle (private key and certificate\nchain) that the pod can use either as a TLS client or server.\n\nKubelet generates a private key and uses it to send a\nPodCertificateRequest to the named signer. Once the signer approves the\nrequest and issues a certificate chain, Kubelet writes the key and\ncertificate chain to the pod filesystem. The pod does not start until\ncertificates have been issued for each podCertificate projected volume\nsource in its spec.\n\nKubelet will begin trying to rotate the certificate at the time indicated\nby the signer using the PodCertificateRequest.Status.BeginRefreshAt\ntimestamp.\n\nKubelet can write a single file, indicated by the credentialBundlePath\nfield, or separate files, indicated by the keyPath and\ncertificateChainPath fields.\n\nThe credential bundle is a single file in PEM format. The first PEM\nentry is the private key (in PKCS#8 format), and the remaining PEM\nentries are the certificate chain issued by the signer (typically,\nsigners will return their certificate chain in leaf-to-root order).\n\nPrefer using the credential bundle format, since your application code\ncan read it atomically. If you use keyPath and certificateChainPath,\nyour application must make two separate file reads. If these coincide\nwith a certificate rotation, it is possible that the private key and leaf\ncertificate you read may not correspond to each other. Your application\nwill need to check for this condition, and re-read until they are\nconsistent.\n\nThe named signer controls chooses the format of the certificate it\nissues; consult the signer implementation's documentation to learn how to\nuse the certificates it issues.",
+ "properties": {
+ "certificateChainPath": {
+ "description": "Write the certificate chain at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "credentialBundlePath": {
+ "description": "Write the credential bundle at this path in the projected volume.\n\nThe credential bundle is a single file that contains multiple PEM blocks.\nThe first PEM block is a PRIVATE KEY block, containing a PKCS#8 private\nkey.\n\nThe remaining blocks are CERTIFICATE blocks, containing the issued\ncertificate chain from the signer (leaf and any intermediates).\n\nUsing credentialBundlePath lets your Pod's application code make a single\natomic read that retrieves a consistent key and certificate chain. If you\nproject them to separate files, your application code will need to\nadditionally check that the leaf certificate was issued to the key.",
+ "type": "string"
+ },
+ "keyPath": {
+ "description": "Write the key at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "keyType": {
+ "description": "The type of keypair Kubelet will generate for the pod.\n\nValid values are \"RSA3072\", \"RSA4096\", \"ECDSAP256\", \"ECDSAP384\",\n\"ECDSAP521\", and \"ED25519\".",
+ "type": "string"
+ },
+ "maxExpirationSeconds": {
+ "description": "maxExpirationSeconds is the maximum lifetime permitted for the\ncertificate.\n\nKubelet copies this value verbatim into the PodCertificateRequests it\ngenerates for this projection.\n\nIf omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver\nwill reject values shorter than 3600 (1 hour). The maximum allowable\nvalue is 7862400 (91 days).\n\nThe signer implementation is then free to issue a certificate with any\nlifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600\nseconds (1 hour). This constraint is enforced by kube-apiserver.\n`kubernetes.io` signers will never issue certificates with a lifetime\nlonger than 24 hours.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "signerName": {
+ "description": "Kubelet's generated CSRs will be addressed to this signer.",
+ "type": "string"
+ },
+ "userAnnotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "userAnnotations allow pod authors to pass additional information to\nthe signer implementation. Kubernetes does not restrict or validate this\nmetadata in any way.\n\nThese values are copied verbatim into the `spec.unverifiedUserAnnotations` field of\nthe PodCertificateRequest objects that Kubelet creates.\n\nEntries are subject to the same validation as object metadata annotations,\nwith the addition that all keys must be domain-prefixed. No restrictions\nare placed on values, except an overall size limitation on the entire field.\n\nSigners should document the keys and values they support. Signers should\ndeny requests that contain keys they do not recognize.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "keyType",
+ "signerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret information about the secret data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "serviceAccountToken": {
+ "description": "serviceAccountToken is information about the serviceAccountToken data to project",
+ "properties": {
+ "audience": {
+ "description": "audience is the intended audience of the token. A recipient of a token\nmust identify itself with an identifier specified in the audience of the\ntoken, and otherwise should reject the token. The audience defaults to the\nidentifier of the apiserver.",
+ "type": "string"
+ },
+ "expirationSeconds": {
+ "description": "expirationSeconds is the requested duration of validity of the service\naccount token. As the token approaches expiration, the kubelet volume\nplugin will proactively rotate the service account token. The kubelet will\nstart trying to rotate the token if the token is older than 80 percent of\nits time to live or if the token is older than 24 hours.Defaults to 1 hour\nand must be at least 10 minutes.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "quobyte": {
+ "description": "quobyte represents a Quobyte mount on the host that shares a pod's lifetime.\nDeprecated: Quobyte is deprecated and the in-tree quobyte type is no longer supported.",
+ "properties": {
+ "group": {
+ "description": "group to map volume access to\nDefault is no group",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Quobyte volume to be mounted with read-only permissions.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "registry": {
+ "description": "registry represents a single or multiple Quobyte Registry services\nspecified as a string as host:port pair (multiple entries are separated with commas)\nwhich acts as the central registry for volumes",
+ "type": "string"
+ },
+ "tenant": {
+ "description": "tenant owning the given Quobyte volume in the Backend\nUsed with dynamically provisioned Quobyte volumes, value is set by the plugin",
+ "type": "string"
+ },
+ "user": {
+ "description": "user to map volume access to\nDefaults to serivceaccount user",
+ "type": "string"
+ },
+ "volume": {
+ "description": "volume is a string that references an already created Quobyte volume by name.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "registry",
+ "volume"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "rbd": {
+ "description": "rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.\nDeprecated: RBD is deprecated and the in-tree rbd type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#rbd",
+ "type": "string"
+ },
+ "image": {
+ "description": "image is the rados image name.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "keyring": {
+ "default": "/etc/ceph/keyring",
+ "description": "keyring is the path to key ring for RBDUser.\nDefault is /etc/ceph/keyring.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "monitors": {
+ "description": "monitors is a collection of Ceph monitors.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "pool": {
+ "default": "rbd",
+ "description": "pool is the rados pool name.\nDefault is rbd.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is name of the authentication secret for RBDUser. If provided\noverrides keyring.\nDefault is nil.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "default": "admin",
+ "description": "user is the rados user name.\nDefault is admin.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "image",
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scaleIO": {
+ "description": "scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes nodes.\nDeprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "default": "xfs",
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\".\nDefault is \"xfs\".",
+ "type": "string"
+ },
+ "gateway": {
+ "description": "gateway is the host address of the ScaleIO API Gateway.",
+ "type": "string"
+ },
+ "protectionDomain": {
+ "description": "protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef references to the secret for ScaleIO user and other\nsensitive information. If this is not provided, Login operation will fail.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "sslEnabled": {
+ "description": "sslEnabled Flag enable/disable SSL communication with Gateway, default false",
+ "type": "boolean"
+ },
+ "storageMode": {
+ "default": "ThinProvisioned",
+ "description": "storageMode indicates whether the storage for a volume should be ThickProvisioned or ThinProvisioned.\nDefault is ThinProvisioned.",
+ "type": "string"
+ },
+ "storagePool": {
+ "description": "storagePool is the ScaleIO Storage Pool associated with the protection domain.",
+ "type": "string"
+ },
+ "system": {
+ "description": "system is the name of the storage system as configured in ScaleIO.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the name of a volume already created in the ScaleIO system\nthat is associated with this volume source.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "gateway",
+ "secretRef",
+ "system"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret represents a secret that should populate this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is Optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values\nfor mode bits. Defaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its keys must be defined",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of the secret in the pod's namespace to use.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "storageos": {
+ "description": "storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.\nDeprecated: StorageOS is deprecated and the in-tree storageos type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef specifies the secret to use for obtaining the StorageOS API\ncredentials. If not specified, default values will be attempted.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeName": {
+ "description": "volumeName is the human-readable name of the StorageOS volume. Volume\nnames are only unique within a namespace.",
+ "type": "string"
+ },
+ "volumeNamespace": {
+ "description": "volumeNamespace specifies the scope of the volume within StorageOS. If no\nnamespace is specified then the Pod's namespace will be used. This allows the\nKubernetes name scoping to be mirrored within StorageOS for tighter integration.\nSet VolumeName to any name to override the default behaviour.\nSet to \"default\" if you are not using namespaces within StorageOS.\nNamespaces that do not pre-exist within StorageOS will be created.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "vsphereVolume": {
+ "description": "vsphereVolume represents a vSphere volume attached and mounted on kubelets host machine.\nDeprecated: VsphereVolume is deprecated. All operations for the in-tree vsphereVolume type\nare redirected to the csi.vsphere.vmware.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "storagePolicyID": {
+ "description": "storagePolicyID is the storage Policy Based Management (SPBM) profile ID associated with the StoragePolicyName.",
+ "type": "string"
+ },
+ "storagePolicyName": {
+ "description": "storagePolicyName is the storage Policy Based Management (SPBM) profile name.",
+ "type": "string"
+ },
+ "volumePath": {
+ "description": "volumePath is the path that identifies vSphere volume vmdk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumePath"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "strategy": {
+ "description": "The daemonset strategy to use to replace existing pods with new ones.",
+ "properties": {
+ "rollingUpdate": {
+ "description": "Rolling update config params. Present only if type = \"RollingUpdate\".",
+ "properties": {
+ "maxSurge": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of nodes with an existing available DaemonSet pod that\ncan have an updated DaemonSet pod during during an update.\nValue can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%).\nThis can not be 0 if MaxUnavailable is 0.\nAbsolute number is calculated from percentage by rounding up to a minimum of 1.\nDefault value is 0.\nExample: when this is set to 30%, at most 30% of the total number of nodes\nthat should be running the daemon pod (i.e. status.desiredNumberScheduled)\ncan have their a new pod created before the old pod is marked as deleted.\nThe update starts by launching new pods on 30% of nodes. Once an updated\npod is available (Ready for at least minReadySeconds) the old DaemonSet pod\non that node is marked deleted. If the old pod becomes unavailable for any\nreason (Ready transitions to false, is evicted, or is drained) an updated\npod is immediately created on that node without considering surge limits.\nAllowing surge implies the possibility that the resources consumed by the\ndaemonset on any given node can double if the readiness check fails, and\nso resource intensive daemonsets should take into account that they may\ncause evictions during disruption.",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxUnavailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of DaemonSet pods that can be unavailable during the\nupdate. Value can be an absolute number (ex: 5) or a percentage of total\nnumber of DaemonSet pods at the start of the update (ex: 10%). Absolute\nnumber is calculated from percentage by rounding up.\nThis cannot be 0 if MaxSurge is 0\nDefault value is 1.\nExample: when this is set to 30%, at most 30% of the total number of nodes\nthat should be running the daemon pod (i.e. status.desiredNumberScheduled)\ncan have their pods stopped for an update at any given time. The update\nstarts by stopping at most 30% of those DaemonSet pods and then brings\nup new DaemonSet pods in their place. Once the new pods are available,\nit then proceeds onto other DaemonSet pods, thus ensuring that at least\n70% of original number of DaemonSet pods are available at all times during\nthe update.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type of daemon set update. Can be \"RollingUpdate\" or \"OnDelete\". Default is RollingUpdate.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "envoyDeployment": {
+ "description": "EnvoyDeployment defines the desired state of the Envoy deployment resource.\nIf unspecified, default settings for the managed Envoy deployment resource\nare applied.",
+ "properties": {
+ "container": {
+ "description": "Container defines the desired specification of main container.",
+ "properties": {
+ "env": {
+ "description": "List of environment variables to set in the container.",
+ "items": {
+ "description": "EnvVar represents an environment variable present in a Container.",
+ "properties": {
+ "name": {
+ "description": "Name of the environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Variable references $(VAR_NAME) are expanded\nusing the previously defined environment variables in the container and\nany service environment variables. If a variable cannot be resolved,\nthe reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.\n\"$$(VAR_NAME)\" will produce the string literal \"$(VAR_NAME)\".\nEscaped references will never be expanded, regardless of whether the variable\nexists or not.\nDefaults to \"\".",
+ "type": "string"
+ },
+ "valueFrom": {
+ "description": "Source for the environment variable's value. Cannot be used if value is not empty.",
+ "properties": {
+ "configMapKeyRef": {
+ "description": "Selects a key of a ConfigMap.",
+ "properties": {
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fieldRef": {
+ "description": "Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`,\nspec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fileKeyRef": {
+ "description": "FileKeyRef selects a key of the env file.\nRequires the EnvFiles feature gate to be enabled.",
+ "properties": {
+ "key": {
+ "description": "The key within the env file. An invalid key will prevent the pod from starting.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nDuring Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.",
+ "type": "string"
+ },
+ "optional": {
+ "default": false,
+ "description": "Specify whether the file or its key must be defined. If the file or key\ndoes not exist, then the env var is not published.\nIf optional is set to true and the specified key does not exist,\nthe environment variable will not be set in the Pod's containers.\n\nIf optional is set to false and the specified key does not exist,\nan error will be returned during Pod creation.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "The path within the volume from which to select the file.\nMust be relative and may not contain the '..' path or start with '..'.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "The name of the volume mount containing the env file.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path",
+ "volumeName"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "secretKeyRef": {
+ "description": "Selects a key of a secret in the pod's namespace",
+ "properties": {
+ "key": {
+ "description": "The key of the secret to select from. Must be a valid secret key.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "image": {
+ "description": "Image specifies the EnvoyProxy container image to be used including a tag, instead of the default image.\nThis field is mutually exclusive with ImageRepository.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Image must include a tag and allowed characters only (e.g., 'repo:tag').",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?(/[a-zA-Z0-9._/-]+)?(:[a-zA-Z0-9._-]+)?(@sha256:[a-z0-9]+)?$')"
+ }
+ ]
+ },
+ "imageRepository": {
+ "description": "ImageRepository specifies the container image repository to be used without specifying a tag.\nThe default tag will be used.\nThis field is mutually exclusive with Image.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "ImageRepository must contain only allowed characters and must not include a tag.",
+ "rule": "self.matches('^[a-zA-Z0-9._-]+(:[0-9]+)?[a-zA-Z0-9._/-]+$')"
+ }
+ ]
+ },
+ "resources": {
+ "description": "Resources required by this container.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "securityContext": {
+ "description": "SecurityContext defines the security options the container should be run with.\nIf set, the fields of SecurityContext override the equivalent fields of PodSecurityContext.\nMore info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/",
+ "properties": {
+ "allowPrivilegeEscalation": {
+ "description": "AllowPrivilegeEscalation controls whether a process can gain more\nprivileges than its parent process. This bool directly controls if\nthe no_new_privs flag will be set on the container process.\nAllowPrivilegeEscalation is true always when the container is:\n1) run as Privileged\n2) has CAP_SYS_ADMIN\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by this container. If set, this profile\noverrides the pod's appArmorProfile.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "capabilities": {
+ "description": "The capabilities to add/drop when running containers.\nDefaults to the default set of capabilities granted by the container runtime.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "add": {
+ "description": "Added capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "drop": {
+ "description": "Removed capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "privileged": {
+ "description": "Run container in privileged mode.\nProcesses in privileged containers are essentially equivalent to root on the host.\nDefaults to false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "procMount": {
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "readOnlyRootFilesystem": {
+ "description": "Whether this container has a read-only root filesystem.\nDefault is false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to the container.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by this container. If seccomp options are\nprovided at both the pod & container level, the container options\noverride the pod options.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options from the PodSecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "volumeMounts": {
+ "description": "VolumeMounts are volumes to mount into the container's filesystem.\nCannot be updated.",
+ "items": {
+ "description": "VolumeMount describes a mounting of a Volume within a container.",
+ "properties": {
+ "mountPath": {
+ "description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
+ "type": "string"
+ },
+ "mountPropagation": {
+ "description": "mountPropagation determines how mounts are propagated from the host\nto container and the other way around.\nWhen not set, MountPropagationNone is used.\nThis field is beta in 1.10.\nWhen RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified\n(which defaults to None).",
+ "type": "string"
+ },
+ "name": {
+ "description": "This must match the Name of a Volume.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "Mounted read-only if true, read-write otherwise (false or unspecified).\nDefaults to false.",
+ "type": "boolean"
+ },
+ "recursiveReadOnly": {
+ "description": "RecursiveReadOnly specifies whether read-only mounts should be handled\nrecursively.\n\nIf ReadOnly is false, this field has no meaning and must be unspecified.\n\nIf ReadOnly is true, and this field is set to Disabled, the mount is not made\nrecursively read-only. If this field is set to IfPossible, the mount is made\nrecursively read-only, if it is supported by the container runtime. If this\nfield is set to Enabled, the mount is made recursively read-only if it is\nsupported by the container runtime, otherwise the pod will not be started and\nan error will be generated to indicate the reason.\n\nIf this field is set to IfPossible or Enabled, MountPropagation must be set to\nNone (or be unspecified, which defaults to None).\n\nIf this field is not specified, it is treated as an equivalent of Disabled.",
+ "type": "string"
+ },
+ "subPath": {
+ "description": "Path within the volume from which the container's volume should be mounted.\nDefaults to \"\" (volume's root).",
+ "type": "string"
+ },
+ "subPathExpr": {
+ "description": "Expanded path within the volume from which the container's volume should be mounted.\nBehaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.\nDefaults to \"\" (volume's root).\nSubPathExpr and SubPath are mutually exclusive.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "mountPath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Either image or imageRepository can be set.",
+ "rule": "!has(self.image) || !has(self.imageRepository)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initContainers": {
+ "description": "List of initialization containers belonging to the pod.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/",
+ "items": {
+ "description": "A single application container that you want to run within a pod.",
+ "properties": {
+ "args": {
+ "description": "Arguments to the entrypoint.\nThe container image's CMD is used if this is not provided.\nVariable references $(VAR_NAME) are expanded using the container's environment. If a variable\ncannot be resolved, the reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e. \"$$(VAR_NAME)\" will\nproduce the string literal \"$(VAR_NAME)\". Escaped references will never be expanded, regardless\nof whether the variable exists or not. Cannot be updated.\nMore info: https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "command": {
+ "description": "Entrypoint array. Not executed within a shell.\nThe container image's ENTRYPOINT is used if this is not provided.\nVariable references $(VAR_NAME) are expanded using the container's environment. If a variable\ncannot be resolved, the reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e. \"$$(VAR_NAME)\" will\nproduce the string literal \"$(VAR_NAME)\". Escaped references will never be expanded, regardless\nof whether the variable exists or not. Cannot be updated.\nMore info: https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "env": {
+ "description": "List of environment variables to set in the container.\nCannot be updated.",
+ "items": {
+ "description": "EnvVar represents an environment variable present in a Container.",
+ "properties": {
+ "name": {
+ "description": "Name of the environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Variable references $(VAR_NAME) are expanded\nusing the previously defined environment variables in the container and\nany service environment variables. If a variable cannot be resolved,\nthe reference in the input string will be unchanged. Double $$ are reduced\nto a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.\n\"$$(VAR_NAME)\" will produce the string literal \"$(VAR_NAME)\".\nEscaped references will never be expanded, regardless of whether the variable\nexists or not.\nDefaults to \"\".",
+ "type": "string"
+ },
+ "valueFrom": {
+ "description": "Source for the environment variable's value. Cannot be used if value is not empty.",
+ "properties": {
+ "configMapKeyRef": {
+ "description": "Selects a key of a ConfigMap.",
+ "properties": {
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fieldRef": {
+ "description": "Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`,\nspec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "fileKeyRef": {
+ "description": "FileKeyRef selects a key of the env file.\nRequires the EnvFiles feature gate to be enabled.",
+ "properties": {
+ "key": {
+ "description": "The key within the env file. An invalid key will prevent the pod from starting.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nDuring Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.",
+ "type": "string"
+ },
+ "optional": {
+ "default": false,
+ "description": "Specify whether the file or its key must be defined. If the file or key\ndoes not exist, then the env var is not published.\nIf optional is set to true and the specified key does not exist,\nthe environment variable will not be set in the Pod's containers.\n\nIf optional is set to false and the specified key does not exist,\nan error will be returned during Pod creation.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "The path within the volume from which to select the file.\nMust be relative and may not contain the '..' path or start with '..'.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "The name of the volume mount containing the env file.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path",
+ "volumeName"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "secretKeyRef": {
+ "description": "Selects a key of a secret in the pod's namespace",
+ "properties": {
+ "key": {
+ "description": "The key of the secret to select from. Must be a valid secret key.",
+ "type": "string"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "key"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "envFrom": {
+ "description": "List of sources to populate environment variables in the container.\nThe keys defined within a source may consist of any printable ASCII characters except '='.\nWhen a key exists in multiple\nsources, the value associated with the last source will take precedence.\nValues defined by an Env with a duplicate key will take precedence.\nCannot be updated.",
+ "items": {
+ "description": "EnvFromSource represents the source of a set of ConfigMaps or Secrets",
+ "properties": {
+ "configMapRef": {
+ "description": "The ConfigMap to select from",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the ConfigMap must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "prefix": {
+ "description": "Optional text to prepend to the name of each environment variable.\nMay consist of any printable ASCII characters except '='.",
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "The Secret to select from",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "Specify whether the Secret must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "image": {
+ "description": "Container image name.\nMore info: https://kubernetes.io/docs/concepts/containers/images\nThis field is optional to allow higher level config management to default or override\ncontainer images in workload controllers like Deployments and StatefulSets.",
+ "type": "string"
+ },
+ "imagePullPolicy": {
+ "description": "Image pull policy.\nOne of Always, Never, IfNotPresent.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/containers/images#updating-images",
+ "type": "string"
+ },
+ "lifecycle": {
+ "description": "Actions that the management system should take in response to container lifecycle events.\nCannot be updated.",
+ "properties": {
+ "postStart": {
+ "description": "PostStart is called immediately after a container is created. If the handler fails,\nthe container is terminated and restarted according to its restart policy.\nOther management of the container blocks until the hook completes.\nMore info: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sleep": {
+ "description": "Sleep represents a duration that the container should sleep.",
+ "properties": {
+ "seconds": {
+ "description": "Seconds is the number of seconds to sleep.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "seconds"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpSocket": {
+ "description": "Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept\nfor backward compatibility. There is no validation of this field and\nlifecycle hooks will fail at runtime when it is specified.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "preStop": {
+ "description": "PreStop is called immediately before a container is terminated due to an\nAPI request or management event such as liveness/startup probe failure,\npreemption, resource contention, etc. The handler is not called if the\ncontainer crashes or exits. The Pod's termination grace period countdown begins before the\nPreStop hook is executed. Regardless of the outcome of the handler, the\ncontainer will eventually terminate within the Pod's termination grace\nperiod (unless delayed by finalizers). Other management of the container blocks until the hook completes\nor until the termination grace period is reached.\nMore info: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sleep": {
+ "description": "Sleep represents a duration that the container should sleep.",
+ "properties": {
+ "seconds": {
+ "description": "Seconds is the number of seconds to sleep.",
+ "format": "int64",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "seconds"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpSocket": {
+ "description": "Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept\nfor backward compatibility. There is no validation of this field and\nlifecycle hooks will fail at runtime when it is specified.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "stopSignal": {
+ "description": "StopSignal defines which signal will be sent to a container when it is being stopped.\nIf not specified, the default is defined by the container runtime in use.\nStopSignal can only be set for Pods with a non-empty .spec.os.name",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "livenessProbe": {
+ "description": "Periodic probe of container liveness.\nContainer will be restarted if the probe fails.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failureThreshold": {
+ "description": "Minimum consecutive failures for the probe to be considered failed after having succeeded.\nDefaults to 3. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "grpc": {
+ "description": "GRPC specifies a GRPC HealthCheckRequest.",
+ "properties": {
+ "port": {
+ "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "service": {
+ "default": "",
+ "description": "Service is the name of the service to place in the gRPC HealthCheckRequest\n(see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).\n\nIf this is not specified, the default behavior is defined by gRPC.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialDelaySeconds": {
+ "description": "Number of seconds after the container has started before liveness probes are initiated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ },
+ "periodSeconds": {
+ "description": "How often (in seconds) to perform the probe.\nDefault to 10 seconds. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "successThreshold": {
+ "description": "Minimum consecutive successes for the probe to be considered successful after having failed.\nDefaults to 1. Must be 1 for liveness and startup. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tcpSocket": {
+ "description": "TCPSocket specifies a connection to a TCP port.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "terminationGracePeriodSeconds": {
+ "description": "Optional duration in seconds the pod needs to terminate gracefully upon probe failure.\nThe grace period is the duration in seconds after the processes running in the pod are sent\na termination signal and the time when the processes are forcibly halted with a kill signal.\nSet this value longer than the expected cleanup time for your process.\nIf this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this\nvalue overrides the value provided by the pod spec.\nValue must be non-negative integer. The value zero indicates stop immediately via\nthe kill signal (no opportunity to shut down).\nThis is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.\nMinimum value is 1. spec.terminationGracePeriodSeconds is used if unset.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "description": "Number of seconds after which the probe times out.\nDefaults to 1 second. Minimum value is 1.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Name of the container specified as a DNS_LABEL.\nEach container in a pod must have a unique name (DNS_LABEL).\nCannot be updated.",
+ "type": "string"
+ },
+ "ports": {
+ "description": "List of ports to expose from the container. Not specifying a port here\nDOES NOT prevent that port from being exposed. Any port which is\nlistening on the default \"0.0.0.0\" address inside a container will be\naccessible from the network.\nModifying this array with strategic merge patch may corrupt the data.\nFor more information See https://github.com/kubernetes/kubernetes/issues/108255.\nCannot be updated.",
+ "items": {
+ "description": "ContainerPort represents a network port in a single container.",
+ "properties": {
+ "containerPort": {
+ "description": "Number of port to expose on the pod's IP address.\nThis must be a valid port number, 0 < x < 65536.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "hostIP": {
+ "description": "What host IP to bind the external port to.",
+ "type": "string"
+ },
+ "hostPort": {
+ "description": "Number of port to expose on the host.\nIf specified, this must be a valid port number, 0 < x < 65536.\nIf HostNetwork is specified, this must match ContainerPort.\nMost containers do not need this.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "name": {
+ "description": "If specified, this must be an IANA_SVC_NAME and unique within the pod. Each\nnamed port in a pod must have a unique name. Name for the port that can be\nreferred to by services.",
+ "type": "string"
+ },
+ "protocol": {
+ "default": "TCP",
+ "description": "Protocol for port. Must be UDP, TCP, or SCTP.\nDefaults to \"TCP\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "containerPort"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "containerPort",
+ "protocol"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "readinessProbe": {
+ "description": "Periodic probe of container service readiness.\nContainer will be removed from service endpoints if the probe fails.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failureThreshold": {
+ "description": "Minimum consecutive failures for the probe to be considered failed after having succeeded.\nDefaults to 3. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "grpc": {
+ "description": "GRPC specifies a GRPC HealthCheckRequest.",
+ "properties": {
+ "port": {
+ "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "service": {
+ "default": "",
+ "description": "Service is the name of the service to place in the gRPC HealthCheckRequest\n(see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).\n\nIf this is not specified, the default behavior is defined by gRPC.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialDelaySeconds": {
+ "description": "Number of seconds after the container has started before liveness probes are initiated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ },
+ "periodSeconds": {
+ "description": "How often (in seconds) to perform the probe.\nDefault to 10 seconds. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "successThreshold": {
+ "description": "Minimum consecutive successes for the probe to be considered successful after having failed.\nDefaults to 1. Must be 1 for liveness and startup. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tcpSocket": {
+ "description": "TCPSocket specifies a connection to a TCP port.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "terminationGracePeriodSeconds": {
+ "description": "Optional duration in seconds the pod needs to terminate gracefully upon probe failure.\nThe grace period is the duration in seconds after the processes running in the pod are sent\na termination signal and the time when the processes are forcibly halted with a kill signal.\nSet this value longer than the expected cleanup time for your process.\nIf this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this\nvalue overrides the value provided by the pod spec.\nValue must be non-negative integer. The value zero indicates stop immediately via\nthe kill signal (no opportunity to shut down).\nThis is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.\nMinimum value is 1. spec.terminationGracePeriodSeconds is used if unset.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "description": "Number of seconds after which the probe times out.\nDefaults to 1 second. Minimum value is 1.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resizePolicy": {
+ "description": "Resources resize policy for the container.\nThis field cannot be set on ephemeral containers.",
+ "items": {
+ "description": "ContainerResizePolicy represents resource resize policy for the container.",
+ "properties": {
+ "resourceName": {
+ "description": "Name of the resource to which this resource resize policy applies.\nSupported values: cpu, memory.",
+ "type": "string"
+ },
+ "restartPolicy": {
+ "description": "Restart policy to apply when specified resource is resized.\nIf not specified, it defaults to NotRequired.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resourceName",
+ "restartPolicy"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "resources": {
+ "description": "Compute Resources required by this container.\nCannot be updated.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "properties": {
+ "claims": {
+ "description": "Claims lists the names of resources, defined in spec.resourceClaims,\nthat are used by this container.\n\nThis field depends on the\nDynamicResourceAllocation feature gate.\n\nThis field is immutable. It can only be set for containers.",
+ "items": {
+ "description": "ResourceClaim references one entry in PodSpec.ResourceClaims.",
+ "properties": {
+ "name": {
+ "description": "Name must match the name of one entry in pod.spec.resourceClaims of\nthe Pod where this field is used. It makes that resource available\ninside a container.",
+ "type": "string"
+ },
+ "request": {
+ "description": "Request is the name chosen for a request in the referenced claim.\nIf empty, everything from the claim is made available, otherwise\nonly the result of this request.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "restartPolicy": {
+ "description": "RestartPolicy defines the restart behavior of individual containers in a pod.\nThis overrides the pod-level restart policy. When this field is not specified,\nthe restart behavior is defined by the Pod's restart policy and the container type.\nAdditionally, setting the RestartPolicy as \"Always\" for the init container will\nhave the following effect:\nthis init container will be continually restarted on\nexit until all regular containers have terminated. Once all regular\ncontainers have completed, all init containers with restartPolicy \"Always\"\nwill be shut down. This lifecycle differs from normal init containers and\nis often referred to as a \"sidecar\" container. Although this init\ncontainer still starts in the init container sequence, it does not wait\nfor the container to complete before proceeding to the next init\ncontainer. Instead, the next init container starts immediately after this\ninit container is started, or after any startupProbe has successfully\ncompleted.",
+ "type": "string"
+ },
+ "restartPolicyRules": {
+ "description": "Represents a list of rules to be checked to determine if the\ncontainer should be restarted on exit. The rules are evaluated in\norder. Once a rule matches a container exit condition, the remaining\nrules are ignored. If no rule matches the container exit condition,\nthe Container-level restart policy determines the whether the container\nis restarted or not. Constraints on the rules:\n- At most 20 rules are allowed.\n- Rules can have the same action.\n- Identical rules are not forbidden in validations.\nWhen rules are specified, container MUST set RestartPolicy explicitly\neven it if matches the Pod's RestartPolicy.",
+ "items": {
+ "description": "ContainerRestartRule describes how a container exit is handled.",
+ "properties": {
+ "action": {
+ "description": "Specifies the action taken on a container exit if the requirements\nare satisfied. The only possible value is \"Restart\" to restart the\ncontainer.",
+ "type": "string"
+ },
+ "exitCodes": {
+ "description": "Represents the exit codes to check on container exits.",
+ "properties": {
+ "operator": {
+ "description": "Represents the relationship between the container exit code(s) and the\nspecified values. Possible values are:\n- In: the requirement is satisfied if the container exit code is in the\n set of specified values.\n- NotIn: the requirement is satisfied if the container exit code is\n not in the set of specified values.",
+ "type": "string"
+ },
+ "values": {
+ "description": "Specifies the set of values to check for container exit codes.\nAt most 255 elements are allowed.",
+ "items": {
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "required": [
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "action"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "securityContext": {
+ "description": "SecurityContext defines the security options the container should be run with.\nIf set, the fields of SecurityContext override the equivalent fields of PodSecurityContext.\nMore info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/",
+ "properties": {
+ "allowPrivilegeEscalation": {
+ "description": "AllowPrivilegeEscalation controls whether a process can gain more\nprivileges than its parent process. This bool directly controls if\nthe no_new_privs flag will be set on the container process.\nAllowPrivilegeEscalation is true always when the container is:\n1) run as Privileged\n2) has CAP_SYS_ADMIN\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by this container. If set, this profile\noverrides the pod's appArmorProfile.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "capabilities": {
+ "description": "The capabilities to add/drop when running containers.\nDefaults to the default set of capabilities granted by the container runtime.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "add": {
+ "description": "Added capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "drop": {
+ "description": "Removed capabilities",
+ "items": {
+ "description": "Capability represent POSIX capabilities type",
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "privileged": {
+ "description": "Run container in privileged mode.\nProcesses in privileged containers are essentially equivalent to root on the host.\nDefaults to false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "procMount": {
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "readOnlyRootFilesystem": {
+ "description": "Whether this container has a read-only root filesystem.\nDefault is false.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "boolean"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to the container.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by this container. If seccomp options are\nprovided at both the pod & container level, the container options\noverride the pod options.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options from the PodSecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "startupProbe": {
+ "description": "StartupProbe indicates that the Pod has successfully initialized.\nIf specified, no other probes are executed until this completes successfully.\nIf this probe fails, the Pod will be restarted, just as if the livenessProbe failed.\nThis can be used to provide different probe parameters at the beginning of a Pod's lifecycle,\nwhen it might take a long time to load data or warm a cache, than during steady-state operation.\nThis cannot be updated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "properties": {
+ "exec": {
+ "description": "Exec specifies a command to execute in the container.",
+ "properties": {
+ "command": {
+ "description": "Command is the command line to execute inside the container, the working directory for the\ncommand is root ('/') in the container's filesystem. The command is simply exec'd, it is\nnot run inside a shell, so traditional shell instructions ('|', etc) won't work. To use\na shell, you need to explicitly call out to that shell.\nExit status of 0 is treated as live/healthy and non-zero is unhealthy.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "failureThreshold": {
+ "description": "Minimum consecutive failures for the probe to be considered failed after having succeeded.\nDefaults to 3. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "grpc": {
+ "description": "GRPC specifies a GRPC HealthCheckRequest.",
+ "properties": {
+ "port": {
+ "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "service": {
+ "default": "",
+ "description": "Service is the name of the service to place in the gRPC HealthCheckRequest\n(see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).\n\nIf this is not specified, the default behavior is defined by gRPC.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "httpGet": {
+ "description": "HTTPGet specifies an HTTP GET request to perform.",
+ "properties": {
+ "host": {
+ "description": "Host name to connect to, defaults to the pod IP. You probably want to set\n\"Host\" in httpHeaders instead.",
+ "type": "string"
+ },
+ "httpHeaders": {
+ "description": "Custom headers to set in the request. HTTP allows repeated headers.",
+ "items": {
+ "description": "HTTPHeader describes a custom header to be used in HTTP probes",
+ "properties": {
+ "name": {
+ "description": "The header field name.\nThis will be canonicalized upon output, so case-variant names will be understood as the same header.",
+ "type": "string"
+ },
+ "value": {
+ "description": "The header field value",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "Path to access on the HTTP server.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ },
+ "scheme": {
+ "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialDelaySeconds": {
+ "description": "Number of seconds after the container has started before liveness probes are initiated.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ },
+ "periodSeconds": {
+ "description": "How often (in seconds) to perform the probe.\nDefault to 10 seconds. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "successThreshold": {
+ "description": "Minimum consecutive successes for the probe to be considered successful after having failed.\nDefaults to 1. Must be 1 for liveness and startup. Minimum value is 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tcpSocket": {
+ "description": "TCPSocket specifies a connection to a TCP port.",
+ "properties": {
+ "host": {
+ "description": "Optional: Host name to connect to, defaults to the pod IP.",
+ "type": "string"
+ },
+ "port": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Number or name of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "port"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "terminationGracePeriodSeconds": {
+ "description": "Optional duration in seconds the pod needs to terminate gracefully upon probe failure.\nThe grace period is the duration in seconds after the processes running in the pod are sent\na termination signal and the time when the processes are forcibly halted with a kill signal.\nSet this value longer than the expected cleanup time for your process.\nIf this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this\nvalue overrides the value provided by the pod spec.\nValue must be non-negative integer. The value zero indicates stop immediately via\nthe kill signal (no opportunity to shut down).\nThis is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.\nMinimum value is 1. spec.terminationGracePeriodSeconds is used if unset.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "timeoutSeconds": {
+ "description": "Number of seconds after which the probe times out.\nDefaults to 1 second. Minimum value is 1.\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "stdin": {
+ "description": "Whether this container should allocate a buffer for stdin in the container runtime. If this\nis not set, reads from stdin in the container will always result in EOF.\nDefault is false.",
+ "type": "boolean"
+ },
+ "stdinOnce": {
+ "description": "Whether the container runtime should close the stdin channel after it has been opened by\na single attach. When stdin is true the stdin stream will remain open across multiple attach\nsessions. If stdinOnce is set to true, stdin is opened on container start, is empty until the\nfirst client attaches to stdin, and then remains open and accepts data until the client disconnects,\nat which time stdin is closed and remains closed until the container is restarted. If this\nflag is false, a container processes that reads from stdin will never receive an EOF.\nDefault is false",
+ "type": "boolean"
+ },
+ "terminationMessagePath": {
+ "description": "Optional: Path at which the file to which the container's termination message\nwill be written is mounted into the container's filesystem.\nMessage written is intended to be brief final status, such as an assertion failure message.\nWill be truncated by the node if greater than 4096 bytes. The total message length across\nall containers will be limited to 12kb.\nDefaults to /dev/termination-log.\nCannot be updated.",
+ "type": "string"
+ },
+ "terminationMessagePolicy": {
+ "description": "Indicate how the termination message should be populated. File will use the contents of\nterminationMessagePath to populate the container status message on both success and failure.\nFallbackToLogsOnError will use the last chunk of container log output if the termination\nmessage file is empty and the container exited with an error.\nThe log output is limited to 2048 bytes or 80 lines, whichever is smaller.\nDefaults to File.\nCannot be updated.",
+ "type": "string"
+ },
+ "tty": {
+ "description": "Whether this container should allocate a TTY for itself, also requires 'stdin' to be true.\nDefault is false.",
+ "type": "boolean"
+ },
+ "volumeDevices": {
+ "description": "volumeDevices is the list of block devices to be used by the container.",
+ "items": {
+ "description": "volumeDevice describes a mapping of a raw block device within a container.",
+ "properties": {
+ "devicePath": {
+ "description": "devicePath is the path inside of the container that the device will be mapped to.",
+ "type": "string"
+ },
+ "name": {
+ "description": "name must match the name of a persistentVolumeClaim in the pod",
+ "type": "string"
+ }
+ },
+ "required": [
+ "devicePath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "devicePath"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "volumeMounts": {
+ "description": "Pod volumes to mount into the container's filesystem.\nCannot be updated.",
+ "items": {
+ "description": "VolumeMount describes a mounting of a Volume within a container.",
+ "properties": {
+ "mountPath": {
+ "description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
+ "type": "string"
+ },
+ "mountPropagation": {
+ "description": "mountPropagation determines how mounts are propagated from the host\nto container and the other way around.\nWhen not set, MountPropagationNone is used.\nThis field is beta in 1.10.\nWhen RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified\n(which defaults to None).",
+ "type": "string"
+ },
+ "name": {
+ "description": "This must match the Name of a Volume.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "Mounted read-only if true, read-write otherwise (false or unspecified).\nDefaults to false.",
+ "type": "boolean"
+ },
+ "recursiveReadOnly": {
+ "description": "RecursiveReadOnly specifies whether read-only mounts should be handled\nrecursively.\n\nIf ReadOnly is false, this field has no meaning and must be unspecified.\n\nIf ReadOnly is true, and this field is set to Disabled, the mount is not made\nrecursively read-only. If this field is set to IfPossible, the mount is made\nrecursively read-only, if it is supported by the container runtime. If this\nfield is set to Enabled, the mount is made recursively read-only if it is\nsupported by the container runtime, otherwise the pod will not be started and\nan error will be generated to indicate the reason.\n\nIf this field is set to IfPossible or Enabled, MountPropagation must be set to\nNone (or be unspecified, which defaults to None).\n\nIf this field is not specified, it is treated as an equivalent of Disabled.",
+ "type": "string"
+ },
+ "subPath": {
+ "description": "Path within the volume from which the container's volume should be mounted.\nDefaults to \"\" (volume's root).",
+ "type": "string"
+ },
+ "subPathExpr": {
+ "description": "Expanded path within the volume from which the container's volume should be mounted.\nBehaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.\nDefaults to \"\" (volume's root).\nSubPathExpr and SubPath are mutually exclusive.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "mountPath",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "mountPath"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "workingDir": {
+ "description": "Container's working directory.\nIf not specified, the container runtime's default will be used, which\nmight be configured in the container image.\nCannot be updated.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "name": {
+ "description": "Name of the deployment.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to deployment",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pod": {
+ "description": "Pod defines the desired specification of pod.",
+ "properties": {
+ "affinity": {
+ "description": "If specified, the pod's scheduling constraints.",
+ "properties": {
+ "nodeAffinity": {
+ "description": "Describes node affinity scheduling rules for the pod.",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node matches the corresponding matchExpressions; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "An empty preferred scheduling term matches all objects with implicit weight 0\n(i.e. it's a no-op). A null preferred scheduling term matches no objects (i.e. is also a no-op).",
+ "properties": {
+ "preference": {
+ "description": "A node selector term, associated with the corresponding weight.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "Weight associated with matching the corresponding nodeSelectorTerm, in the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "preference",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to an update), the system\nmay or may not try to eventually evict the pod from its node.",
+ "properties": {
+ "nodeSelectorTerms": {
+ "description": "Required. A list of node selector terms. The terms are ORed.",
+ "items": {
+ "description": "A null or empty node selector term matches no objects. The requirements of\nthem are ANDed.\nThe TopologySelectorTerm type implements a subset of the NodeSelectorTerm.",
+ "properties": {
+ "matchExpressions": {
+ "description": "A list of node selector requirements by node's labels.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchFields": {
+ "description": "A list of node selector requirements by node's fields.",
+ "items": {
+ "description": "A node selector requirement is a selector that contains values, a key, and an operator\nthat relates the key and values.",
+ "properties": {
+ "key": {
+ "description": "The label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.",
+ "type": "string"
+ },
+ "values": {
+ "description": "An array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. If the operator is Gt or Lt, the values\narray must have a single element, which will be interpreted as an integer.\nThis array is replaced during a strategic merge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "nodeSelectorTerms"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAffinity": {
+ "description": "Describes pod affinity scheduling rules (e.g. co-locate this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and adding\n\"weight\" to the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podAntiAffinity": {
+ "description": "Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in the same node, zone, etc. as some other pod(s)).",
+ "properties": {
+ "preferredDuringSchedulingIgnoredDuringExecution": {
+ "description": "The scheduler will prefer to schedule pods to nodes that satisfy\nthe anti-affinity expressions specified by this field, but it may choose\na node that violates one or more of the expressions. The node that is\nmost preferred is the one with the greatest sum of weights, i.e.\nfor each node that meets all of the scheduling requirements (resource\nrequest, requiredDuringScheduling anti-affinity expressions, etc.),\ncompute a sum by iterating through the elements of this field and subtracting\n\"weight\" from the sum if the node has pods which matches the corresponding podAffinityTerm; the\nnode(s) with the highest sum are the most preferred.",
+ "items": {
+ "description": "The weights of all of the matched WeightedPodAffinityTerm fields are added per-node to find the most preferred node(s)",
+ "properties": {
+ "podAffinityTerm": {
+ "description": "Required. A pod affinity term, associated with the corresponding weight.",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weight": {
+ "description": "weight associated with matching the corresponding podAffinityTerm,\nin the range 1-100.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "podAffinityTerm",
+ "weight"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "requiredDuringSchedulingIgnoredDuringExecution": {
+ "description": "If the anti-affinity requirements specified by this field are not met at\nscheduling time, the pod will not be scheduled onto the node.\nIf the anti-affinity requirements specified by this field cease to be met\nat some point during pod execution (e.g. due to a pod label update), the\nsystem may or may not try to eventually evict the pod from its node.\nWhen there are multiple elements, the lists of nodes corresponding to each\npodAffinityTerm are intersected, i.e. all terms must be satisfied.",
+ "items": {
+ "description": "Defines a set of pods (namely those matching the labelSelector\nrelative to the given namespace(s)) that this pod should be\nco-located (affinity) or not co-located (anti-affinity) with,\nwhere co-located is defined as running on a node whose value of\nthe label with key matches that of any node on which\na pod of the set of pods is running",
+ "properties": {
+ "labelSelector": {
+ "description": "A label query over a set of resources, in this case pods.\nIf it's null, this PodAffinityTerm matches with no Pods.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both matchLabelKeys and labelSelector.\nAlso, matchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mismatchLabelKeys": {
+ "description": "MismatchLabelKeys is a set of pod label keys to select which pods will\nbe taken into consideration. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`\nto select the group of existing pods which pods will be taken into consideration\nfor the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming\npod labels will be ignored. The default value is empty.\nThe same key is forbidden to exist in both mismatchLabelKeys and labelSelector.\nAlso, mismatchLabelKeys cannot be set when labelSelector isn't set.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaceSelector": {
+ "description": "A label query over the set of namespaces that the term applies to.\nThe term is applied to the union of the namespaces selected by this field\nand the ones listed in the namespaces field.\nnull selector and null or empty namespaces list means \"this pod's namespace\".\nAn empty selector ({}) matches all namespaces.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "namespaces": {
+ "description": "namespaces specifies a static list of namespace names that the term applies to.\nThe term is applied to the union of the namespaces listed in this field\nand the ones selected by namespaceSelector.\nnull or empty namespaces list and null namespaceSelector means \"this pod's namespace\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "topologyKey": {
+ "description": "This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching\nthe labelSelector in the specified namespaces, where co-located is defined as running on a node\nwhose value of the label with key topologyKey matches that of any node on which any of the\nselected pods is running.\nEmpty topologyKey is not allowed.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "topologyKey"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "annotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Annotations are the annotations that should be appended to the pods.\nBy default, no pod annotations are appended.",
+ "type": "object"
+ },
+ "imagePullSecrets": {
+ "description": "ImagePullSecrets is an optional list of references to secrets\nin the same namespace to use for pulling any of the images used by this PodSpec.\nIf specified, these secrets will be passed to individual puller implementations for them to use.\nMore info: https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod",
+ "items": {
+ "description": "LocalObjectReference contains enough information to let you locate the\nreferenced object inside the same namespace.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "labels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Labels are the additional labels that should be tagged to the pods.\nBy default, no additional pod labels are tagged.",
+ "type": "object"
+ },
+ "nodeSelector": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "NodeSelector is a selector which must be true for the pod to fit on a node.\nSelector which must match a node's labels for the pod to be scheduled on that node.\nMore info: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/",
+ "type": "object"
+ },
+ "priorityClassName": {
+ "description": "PriorityClassName indicates the importance of a Pod relative to other Pods.\nIf a PriorityClassName is not specified, the pod priority will be default or zero if there is no default.\nMore info: https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/",
+ "type": "string"
+ },
+ "securityContext": {
+ "description": "SecurityContext holds pod-level security attributes and common container settings.\nOptional: Defaults to empty. See type description for default values of each field.",
+ "properties": {
+ "appArmorProfile": {
+ "description": "appArmorProfile is the AppArmor options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile loaded on the node that should be used.\nThe profile must be preconfigured on the node to work.\nMust match the loaded name of the profile.\nMust be set if and only if type is \"Localhost\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of AppArmor profile will be applied.\nValid options are:\n Localhost - a profile pre-loaded on the node.\n RuntimeDefault - the container runtime's default profile.\n Unconfined - no AppArmor enforcement.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fsGroup": {
+ "description": "A special supplemental group that applies to all containers in a pod.\nSome volume types allow the Kubelet to change the ownership of that volume\nto be owned by the pod:\n\n1. The owning GID will be the FSGroup\n2. The setgid bit is set (new files created in the volume will be owned by FSGroup)\n3. The permission bits are OR'd with rw-rw----\n\nIf unset, the Kubelet will not modify the ownership and permissions of any volume.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "fsGroupChangePolicy": {
+ "description": "fsGroupChangePolicy defines behavior of changing ownership and permission of the volume\nbefore being exposed inside Pod. This field will only apply to\nvolume types which support fsGroup based ownership(and permissions).\nIt will have no effect on ephemeral volume types such as: secret, configmaps\nand emptydir.\nValid values are \"OnRootMismatch\" and \"Always\". If not specified, \"Always\" is used.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "runAsGroup": {
+ "description": "The GID to run the entrypoint of the container process.\nUses runtime default if unset.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "runAsNonRoot": {
+ "description": "Indicates that the container must run as a non-root user.\nIf true, the Kubelet will validate the image at runtime to ensure that it\ndoes not run as UID 0 (root) and fail to start the container if it does.\nIf unset or false, no such validation will be performed.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "boolean"
+ },
+ "runAsUser": {
+ "description": "The UID to run the entrypoint of the container process.\nDefaults to user specified in image metadata if unspecified.\nMay also be set in SecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence\nfor that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "seLinuxChangePolicy": {
+ "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "seLinuxOptions": {
+ "description": "The SELinux context to be applied to all containers.\nIf unspecified, the container runtime will allocate a random SELinux context for each\ncontainer. May also be set in SecurityContext. If set in\nboth SecurityContext and PodSecurityContext, the value specified in SecurityContext\ntakes precedence for that container.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "level": {
+ "description": "Level is SELinux level label that applies to the container.",
+ "type": "string"
+ },
+ "role": {
+ "description": "Role is a SELinux role label that applies to the container.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type is a SELinux type label that applies to the container.",
+ "type": "string"
+ },
+ "user": {
+ "description": "User is a SELinux user label that applies to the container.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "seccompProfile": {
+ "description": "The seccomp options to use by the containers in this pod.\nNote that this field cannot be set when spec.os.name is windows.",
+ "properties": {
+ "localhostProfile": {
+ "description": "localhostProfile indicates a profile defined in a file on the node should be used.\nThe profile must be preconfigured on the node to work.\nMust be a descending path, relative to the kubelet's configured seccomp profile location.\nMust be set if type is \"Localhost\". Must NOT be set for any other type.",
+ "type": "string"
+ },
+ "type": {
+ "description": "type indicates which kind of seccomp profile will be applied.\nValid options are:\n\nLocalhost - a profile defined in a file on the node should be used.\nRuntimeDefault - the container runtime default profile should be used.\nUnconfined - no profile should be applied.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "supplementalGroups": {
+ "description": "A list of groups applied to the first process run in each container, in\naddition to the container's primary GID and fsGroup (if specified). If\nthe SupplementalGroupsPolicy feature is enabled, the\nsupplementalGroupsPolicy field determines whether these are in addition\nto or instead of any group memberships defined in the container image.\nIf unspecified, no additional groups are added, though group memberships\ndefined in the container image may still be used, depending on the\nsupplementalGroupsPolicy field.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "format": "int64",
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "supplementalGroupsPolicy": {
+ "description": "Defines how supplemental groups of the first container processes are calculated.\nValid values are \"Merge\" and \"Strict\". If not specified, \"Merge\" is used.\n(Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled\nand the container runtime must implement support for this feature.\nNote that this field cannot be set when spec.os.name is windows.",
+ "type": "string"
+ },
+ "sysctls": {
+ "description": "Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported\nsysctls (by the container runtime) might fail to launch.\nNote that this field cannot be set when spec.os.name is windows.",
+ "items": {
+ "description": "Sysctl defines a kernel parameter to be set",
+ "properties": {
+ "name": {
+ "description": "Name of a property to set",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of a property to set",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "windowsOptions": {
+ "description": "The Windows specific settings applied to all containers.\nIf unspecified, the options within a container's SecurityContext will be used.\nIf set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.\nNote that this field cannot be set when spec.os.name is linux.",
+ "properties": {
+ "gmsaCredentialSpec": {
+ "description": "GMSACredentialSpec is where the GMSA admission webhook\n(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the\nGMSA credential spec named by the GMSACredentialSpecName field.",
+ "type": "string"
+ },
+ "gmsaCredentialSpecName": {
+ "description": "GMSACredentialSpecName is the name of the GMSA credential spec to use.",
+ "type": "string"
+ },
+ "hostProcess": {
+ "description": "HostProcess determines if a container should be run as a 'Host Process' container.\nAll of a Pod's containers must have the same effective HostProcess value\n(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).\nIn addition, if HostProcess is true then HostNetwork must also be set to true.",
+ "type": "boolean"
+ },
+ "runAsUserName": {
+ "description": "The UserName in Windows to run the entrypoint of the container process.\nDefaults to the user specified in image metadata if unspecified.\nMay also be set in PodSecurityContext. If set in both SecurityContext and\nPodSecurityContext, the value specified in SecurityContext takes precedence.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tolerations": {
+ "description": "If specified, the pod's tolerations.",
+ "items": {
+ "description": "The pod this Toleration is attached to tolerates any taint that matches\nthe triple using the matching operator .",
+ "properties": {
+ "effect": {
+ "description": "Effect indicates the taint effect to match. Empty means match all taint effects.\nWhen specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.",
+ "type": "string"
+ },
+ "key": {
+ "description": "Key is the taint key that the toleration applies to. Empty means match all taint keys.\nIf the key is empty, operator must be Exists; this combination means to match all values and all keys.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "Operator represents a key's relationship to the value.\nValid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.\nExists is equivalent to wildcard for value, so that a pod can\ntolerate all taints of a particular category.\nLt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).",
+ "type": "string"
+ },
+ "tolerationSeconds": {
+ "description": "TolerationSeconds represents the period of time the toleration (which must be\nof effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,\nit is not set, which means tolerate the taint forever (do not evict). Zero and\nnegative values will be treated as 0 (evict immediately) by the system.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "value": {
+ "description": "Value is the taint value the toleration matches to.\nIf the operator is Exists, the value should be empty, otherwise just a regular string.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "topologySpreadConstraints": {
+ "description": "TopologySpreadConstraints describes how a group of pods ought to spread across topology\ndomains. Scheduler will schedule pods in a way which abides by the constraints.\nAll topologySpreadConstraints are ANDed.",
+ "items": {
+ "description": "TopologySpreadConstraint specifies how to spread matching pods among the given topology.",
+ "properties": {
+ "labelSelector": {
+ "description": "LabelSelector is used to find matching pods.\nPods that match this label selector are counted to determine the number of pods\nin their corresponding topology domain.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "matchLabelKeys": {
+ "description": "MatchLabelKeys is a set of pod label keys to select the pods over which\nspreading will be calculated. The keys are used to lookup values from the\nincoming pod labels, those key-value labels are ANDed with labelSelector\nto select the group of existing pods over which spreading will be calculated\nfor the incoming pod. The same key is forbidden to exist in both MatchLabelKeys and LabelSelector.\nMatchLabelKeys cannot be set when LabelSelector isn't set.\nKeys that don't exist in the incoming pod labels will\nbe ignored. A null or empty list means only match against labelSelector.\n\nThis is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate to be enabled (enabled by default).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "maxSkew": {
+ "description": "MaxSkew describes the degree to which pods may be unevenly distributed.\nWhen `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference\nbetween the number of matching pods in the target topology and the global minimum.\nThe global minimum is the minimum number of matching pods in an eligible domain\nor zero if the number of eligible domains is less than MinDomains.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 2/2/1:\nIn this case, the global minimum is 1.\n| zone1 | zone2 | zone3 |\n| P P | P P | P |\n- if MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2;\nscheduling it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2)\nviolate MaxSkew(1).\n- if MaxSkew is 2, incoming pod can be scheduled onto any zone.\nWhen `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence\nto topologies that satisfy it.\nIt's a required field. Default value is 1 and 0 is not allowed.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "minDomains": {
+ "description": "MinDomains indicates a minimum number of eligible domains.\nWhen the number of eligible domains with matching topology keys is less than minDomains,\nPod Topology Spread treats \"global minimum\" as 0, and then the calculation of Skew is performed.\nAnd when the number of eligible domains with matching topology keys equals or greater than minDomains,\nthis value has no effect on scheduling.\nAs a result, when the number of eligible domains is less than minDomains,\nscheduler won't schedule more than maxSkew Pods to those domains.\nIf value is nil, the constraint behaves as if MinDomains is equal to 1.\nValid values are integers greater than 0.\nWhen value is not nil, WhenUnsatisfiable must be DoNotSchedule.\n\nFor example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and pods with the same\nlabelSelector spread as 2/2/2:\n| zone1 | zone2 | zone3 |\n| P P | P P | P P |\nThe number of domains is less than 5(MinDomains), so \"global minimum\" is treated as 0.\nIn this situation, new pod with the same labelSelector cannot be scheduled,\nbecause computed skew will be 3(3 - 0) if new Pod is scheduled to any of the three zones,\nit will violate MaxSkew.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "nodeAffinityPolicy": {
+ "description": "NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector\nwhen calculating pod topology spread skew. Options are:\n- Honor: only nodes matching nodeAffinity/nodeSelector are included in the calculations.\n- Ignore: nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.\n\nIf this value is nil, the behavior is equivalent to the Honor policy.",
+ "type": "string"
+ },
+ "nodeTaintsPolicy": {
+ "description": "NodeTaintsPolicy indicates how we will treat node taints when calculating\npod topology spread skew. Options are:\n- Honor: nodes without taints, along with tainted nodes for which the incoming pod\nhas a toleration, are included.\n- Ignore: node taints are ignored. All nodes are included.\n\nIf this value is nil, the behavior is equivalent to the Ignore policy.",
+ "type": "string"
+ },
+ "topologyKey": {
+ "description": "TopologyKey is the key of node labels. Nodes that have a label with this key\nand identical values are considered to be in the same topology.\nWe consider each as a \"bucket\", and try to put balanced number\nof pods into each bucket.\nWe define a domain as a particular instance of a topology.\nAlso, we define an eligible domain as a domain whose nodes meet the requirements of\nnodeAffinityPolicy and nodeTaintsPolicy.\ne.g. If TopologyKey is \"kubernetes.io/hostname\", each Node is a domain of that topology.\nAnd, if TopologyKey is \"topology.kubernetes.io/zone\", each zone is a domain of that topology.\nIt's a required field.",
+ "type": "string"
+ },
+ "whenUnsatisfiable": {
+ "description": "WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy\nthe spread constraint.\n- DoNotSchedule (default) tells the scheduler not to schedule it.\n- ScheduleAnyway tells the scheduler to schedule the pod in any location,\n but giving higher precedence to topologies that would help reduce the\n skew.\nA constraint is considered \"Unsatisfiable\" for an incoming pod\nif and only if every possible node assignment for that pod would violate\n\"MaxSkew\" on some topology.\nFor example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same\nlabelSelector spread as 3/1/1:\n| zone1 | zone2 | zone3 |\n| P P P | P | P |\nIf WhenUnsatisfiable is set to DoNotSchedule, incoming pod can only be scheduled\nto zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies\nMaxSkew(1). In other words, the cluster can still be imbalanced, but scheduler\nwon't make it *more* imbalanced.\nIt's a required field.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "maxSkew",
+ "topologyKey",
+ "whenUnsatisfiable"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "volumes": {
+ "description": "Volumes that can be mounted by containers belonging to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes",
+ "items": {
+ "description": "Volume represents a named volume in a pod that may be accessed by any container in the pod.",
+ "properties": {
+ "awsElasticBlockStore": {
+ "description": "awsElasticBlockStore represents an AWS Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: AWSElasticBlockStore is deprecated. All operations for the in-tree\nawsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly value true will force the readOnly setting in VolumeMounts.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureDisk": {
+ "description": "azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.\nDeprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type\nare redirected to the disk.csi.azure.com CSI driver.",
+ "properties": {
+ "cachingMode": {
+ "description": "cachingMode is the Host Caching mode: None, Read Only, Read Write.",
+ "type": "string"
+ },
+ "diskName": {
+ "description": "diskName is the Name of the data disk in the blob storage",
+ "type": "string"
+ },
+ "diskURI": {
+ "description": "diskURI is the URI of data disk in the blob storage",
+ "type": "string"
+ },
+ "fsType": {
+ "default": "ext4",
+ "description": "fsType is Filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "kind expected values are Shared: multiple blob disks per storage account Dedicated: single blob disk per storage account Managed: azure managed data disk (only in managed availability set). defaults to shared",
+ "type": "string"
+ },
+ "readOnly": {
+ "default": false,
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "diskName",
+ "diskURI"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "azureFile": {
+ "description": "azureFile represents an Azure File Service mount on the host and bind mount to the pod.\nDeprecated: AzureFile is deprecated. All operations for the in-tree azureFile type\nare redirected to the file.csi.azure.com CSI driver.",
+ "properties": {
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of secret that contains Azure Storage Account Name and Key",
+ "type": "string"
+ },
+ "shareName": {
+ "description": "shareName is the azure share Name",
+ "type": "string"
+ }
+ },
+ "required": [
+ "secretName",
+ "shareName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cephfs": {
+ "description": "cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.\nDeprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.",
+ "properties": {
+ "monitors": {
+ "description": "monitors is Required: Monitors is a collection of Ceph monitors\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "path": {
+ "description": "path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretFile": {
+ "description": "secretFile is Optional: SecretFile is the path to key ring for User, default is /etc/ceph/user.secret\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: SecretRef is reference to the authentication secret for User, default is empty.\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "description": "user is optional: User is the rados user name, default is admin\nMore info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cinder": {
+ "description": "cinder represents a cinder volume attached and mounted on kubelets host machine.\nDeprecated: Cinder is deprecated. All operations for the in-tree cinder type\nare redirected to the cinder.csi.openstack.org CSI driver.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is optional: points to a secret object containing parameters used to connect\nto OpenStack.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeID": {
+ "description": "volumeID used to identify the volume in cinder.\nMore info: https://examples.k8s.io/mysql-cinder-pd/README.md",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap represents a configMap that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "csi": {
+ "description": "csi (Container Storage Interface) represents ephemeral storage that is handled by certain external CSI drivers.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the CSI driver that handles this volume.\nConsult with your admin for the correct name as registered in the cluster.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType to mount. Ex. \"ext4\", \"xfs\", \"ntfs\".\nIf not provided, the empty value is passed to the associated CSI driver\nwhich will determine the default filesystem to apply.",
+ "type": "string"
+ },
+ "nodePublishSecretRef": {
+ "description": "nodePublishSecretRef is a reference to the secret object containing\nsensitive information to pass to the CSI driver to complete the CSI\nNodePublishVolume and NodeUnpublishVolume calls.\nThis field is optional, and may be empty if no secret is required. If the\nsecret object contains more than one secret, all secret references are passed.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "readOnly": {
+ "description": "readOnly specifies a read-only configuration for the volume.\nDefaults to false (read/write).",
+ "type": "boolean"
+ },
+ "volumeAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "volumeAttributes stores driver-specific properties that are passed to the CSI\ndriver. Consult your driver's documentation for supported values.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI represents downward API about the pod that should populate this volume",
+ "properties": {
+ "defaultMode": {
+ "description": "Optional: mode bits to use on created files by default. Must be a\nOptional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDefaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "Items is a list of downward API volume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "emptyDir": {
+ "description": "emptyDir represents a temporary directory that shares a pod's lifetime.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "properties": {
+ "medium": {
+ "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "type": "string"
+ },
+ "sizeLimit": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "sizeLimit is the total amount of local storage required for this EmptyDir volume.\nThe size limit is also applicable for memory medium.\nThe maximum usage on memory medium EmptyDir would be the minimum value between\nthe SizeLimit specified here and the sum of memory limits of all containers in a pod.\nThe default is nil which means that the limit is undefined.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ephemeral": {
+ "description": "ephemeral represents a volume that is handled by a cluster storage driver.\nThe volume's lifecycle is tied to the pod that defines it - it will be created before the pod starts,\nand deleted when the pod is removed.\n\nUse this if:\na) the volume is only needed while the pod runs,\nb) features of normal volumes like restoring from snapshot or capacity\n tracking are needed,\nc) the storage driver is specified through a storage class, and\nd) the storage driver supports dynamic volume provisioning through\n a PersistentVolumeClaim (see EphemeralVolumeSource for more\n information on the connection between this volume type\n and PersistentVolumeClaim).\n\nUse PersistentVolumeClaim or one of the vendor-specific\nAPIs for volumes that persist for longer than the lifecycle\nof an individual pod.\n\nUse CSI for light-weight local ephemeral volumes if the CSI driver is meant to\nbe used that way - see the documentation of the driver for\nmore information.\n\nA pod can use both types of ephemeral volumes and\npersistent volumes at the same time.",
+ "properties": {
+ "volumeClaimTemplate": {
+ "description": "Will be used to create a stand-alone PVC to provision the volume.\nThe pod in which this EphemeralVolumeSource is embedded will be the\nowner of the PVC, i.e. the PVC will be deleted together with the\npod. The name of the PVC will be `-` where\n`` is the name from the `PodSpec.Volumes` array\nentry. Pod validation will reject the pod if the concatenated name\nis not valid for a PVC (for example, too long).\n\nAn existing PVC with that name that is not owned by the pod\nwill *not* be used for the pod to avoid using an unrelated\nvolume by mistake. Starting the pod is then blocked until\nthe unrelated PVC is removed. If such a pre-created PVC is\nmeant to be used by the pod, the PVC has to updated with an\nowner reference to the pod once the pod exists. Normally\nthis should not be necessary, but it may be useful when\nmanually reconstructing a broken cluster.\n\nThis field is read-only and no changes will be made by Kubernetes\nto the PVC after it has been created.\n\nRequired, must not be nil.",
+ "properties": {
+ "metadata": {
+ "description": "May contain labels and annotations that will be copied into the PVC\nwhen creating it. No other fields are allowed and will be rejected during\nvalidation.",
+ "type": "object"
+ },
+ "spec": {
+ "description": "The specification for the PersistentVolumeClaim. The entire content is\ncopied unchanged into the PVC that gets created from this\ntemplate. The same fields as in a PersistentVolumeClaim\nare also valid here.",
+ "properties": {
+ "accessModes": {
+ "description": "accessModes contains the desired access modes the volume should have.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "dataSource": {
+ "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "dataSourceRef": {
+ "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "properties": {
+ "apiGroup": {
+ "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the type of resource being referenced",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of resource being referenced",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of resource being referenced\nNote that when a namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is required in the referent namespace to allow that namespace's owner to accept the reference. See the ReferenceGrant documentation for details.\n(Alpha) This field requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resources": {
+ "description": "resources represents the minimum resources the volume should have.\nUsers are allowed to specify resource requirements\nthat are lower than previous value but must still be higher than capacity recorded in the\nstatus field of the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources",
+ "properties": {
+ "limits": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Limits describes the maximum amount of compute resources allowed.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ },
+ "requests": {
+ "additionalProperties": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "description": "Requests describes the minimum amount of compute resources required.\nIf Requests is omitted for a container, it defaults to Limits if that is explicitly specified,\notherwise to an implementation-defined value. Requests cannot exceed Limits.\nMore info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "selector": {
+ "description": "selector is a label query over volumes to consider for binding.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "storageClassName": {
+ "description": "storageClassName is the name of the StorageClass required by the claim.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1",
+ "type": "string"
+ },
+ "volumeAttributesClassName": {
+ "description": "volumeAttributesClassName may be used to set the VolumeAttributesClass used by this claim.\nIf specified, the CSI driver will create or update the volume with the attributes defined\nin the corresponding VolumeAttributesClass. This has a different purpose than storageClassName,\nit can be changed after the claim is created. An empty string or nil value indicates that no\nVolumeAttributesClass will be applied to the claim. If the claim enters an Infeasible error state,\nthis field can be reset to its previous value (including nil) to cancel the modification.\nIf the resource referred to by volumeAttributesClass does not exist, this PersistentVolumeClaim will be\nset to a Pending state, as reflected by the modifyVolumeStatus field, until such as a resource\nexists.\nMore info: https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/",
+ "type": "string"
+ },
+ "volumeMode": {
+ "description": "volumeMode defines what type of volume is required by the claim.\nValue of Filesystem is implied when not included in claim spec.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the binding reference to the PersistentVolume backing this claim.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "fc": {
+ "description": "fc represents a Fibre Channel resource that is attached to a kubelet's host machine and then exposed to the pod.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun is Optional: FC target lun number",
+ "format": "int32",
+ "type": "integer"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "targetWWNs": {
+ "description": "targetWWNs is Optional: FC target worldwide names (WWNs)",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "wwids": {
+ "description": "wwids Optional: FC volume world wide identifiers (wwids)\nEither wwids or combination of targetWWNs and lun must be set, but not both simultaneously.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flexVolume": {
+ "description": "flexVolume represents a generic volume resource that is\nprovisioned/attached using an exec based plugin.\nDeprecated: FlexVolume is deprecated. Consider using a CSIDriver instead.",
+ "properties": {
+ "driver": {
+ "description": "driver is the name of the driver to use for this volume.",
+ "type": "string"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". The default filesystem depends on FlexVolume script.",
+ "type": "string"
+ },
+ "options": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "options is Optional: this field holds extra command options if any.",
+ "type": "object"
+ },
+ "readOnly": {
+ "description": "readOnly is Optional: defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is Optional: secretRef is reference to the secret object containing\nsensitive information to pass to the plugin scripts. This may be\nempty if no secret object is specified. If the secret object\ncontains more than one secret, all secrets are passed to the plugin\nscripts.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "driver"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "flocker": {
+ "description": "flocker represents a Flocker volume attached to a kubelet's host machine. This depends on the Flocker control service being running.\nDeprecated: Flocker is deprecated and the in-tree flocker type is no longer supported.",
+ "properties": {
+ "datasetName": {
+ "description": "datasetName is Name of the dataset stored as metadata -> name on the dataset for Flocker\nshould be considered as deprecated",
+ "type": "string"
+ },
+ "datasetUUID": {
+ "description": "datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker dataset",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gcePersistentDisk": {
+ "description": "gcePersistentDisk represents a GCE Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nDeprecated: GCEPersistentDisk is deprecated. All operations for the in-tree\ngcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI driver.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "partition": {
+ "description": "partition is the partition in the volume that you want to mount.\nIf omitted, the default is to mount by volume name.\nExamples: For volume /dev/sda1, you specify the partition as \"1\".\nSimilarly, the volume partition for /dev/sda is \"0\" (or you can leave the property empty).\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "format": "int32",
+ "type": "integer"
+ },
+ "pdName": {
+ "description": "pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "pdName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "gitRepo": {
+ "description": "gitRepo represents a git repository at a particular revision.\nDeprecated: GitRepo is deprecated. To provision a container with a git repo, mount an\nEmptyDir into an InitContainer that clones the repo using git, then mount the EmptyDir\ninto the Pod's container.",
+ "properties": {
+ "directory": {
+ "description": "directory is the target directory name.\nMust not contain or start with '..'. If '.' is supplied, the volume directory will be the\ngit repository. Otherwise, if specified, the volume will contain the git repository in\nthe subdirectory with the given name.",
+ "type": "string"
+ },
+ "repository": {
+ "description": "repository is the URL",
+ "type": "string"
+ },
+ "revision": {
+ "description": "revision is the commit hash for the specified revision.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "repository"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "glusterfs": {
+ "description": "glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.\nDeprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer supported.",
+ "properties": {
+ "endpoints": {
+ "description": "endpoints is the endpoint name that details Glusterfs topology.",
+ "type": "string"
+ },
+ "path": {
+ "description": "path is the Glusterfs volume path.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Glusterfs volume to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "endpoints",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostPath": {
+ "description": "hostPath represents a pre-existing file or directory on the host\nmachine that is directly exposed to the container. This is generally\nused for system agents or other privileged things that are allowed\nto see the host machine. Most containers will NOT need this.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "properties": {
+ "path": {
+ "description": "path of the directory on the host.\nIf the path is a symlink, it will follow the link to the real path.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ },
+ "type": {
+ "description": "type for HostPath Volume\nDefaults to \"\"\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "image": {
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "properties": {
+ "pullPolicy": {
+ "description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
+ "type": "string"
+ },
+ "reference": {
+ "description": "Required: Image or artifact reference to be used.\nBehaves in the same way as pod.spec.containers[*].image.\nPull secrets will be assembled in the same way as for the container image by looking up node credentials, SA image pull secrets, and pod spec image pull secrets.\nMore info: https://kubernetes.io/docs/concepts/containers/images\nThis field is optional to allow higher level config management to default or override\ncontainer images in workload controllers like Deployments and StatefulSets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "iscsi": {
+ "description": "iscsi represents an ISCSI Disk resource that is attached to a\nkubelet's host machine and then exposed to the pod.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes/#iscsi",
+ "properties": {
+ "chapAuthDiscovery": {
+ "description": "chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication",
+ "type": "boolean"
+ },
+ "chapAuthSession": {
+ "description": "chapAuthSession defines whether support iSCSI Session CHAP authentication",
+ "type": "boolean"
+ },
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#iscsi",
+ "type": "string"
+ },
+ "initiatorName": {
+ "description": "initiatorName is the custom iSCSI Initiator Name.\nIf initiatorName is specified with iscsiInterface simultaneously, new iSCSI interface\n: will be created for the connection.",
+ "type": "string"
+ },
+ "iqn": {
+ "description": "iqn is the target iSCSI Qualified Name.",
+ "type": "string"
+ },
+ "iscsiInterface": {
+ "default": "default",
+ "description": "iscsiInterface is the interface Name that uses an iSCSI transport.\nDefaults to 'default' (tcp).",
+ "type": "string"
+ },
+ "lun": {
+ "description": "lun represents iSCSI Target Lun number.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "portals": {
+ "description": "portals is the iSCSI Target Portal List. The portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is the CHAP Secret for iSCSI target and initiator authentication",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "targetPortal": {
+ "description": "targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if the port\nis other than default (typically TCP ports 860 and 3260).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "iqn",
+ "lun",
+ "targetPortal"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "name of the volume.\nMust be a DNS_LABEL and unique within the pod.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "nfs": {
+ "description": "nfs represents an NFS mount on the host that shares a pod's lifetime\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "properties": {
+ "path": {
+ "description": "path that is exported by the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the NFS export to be mounted with read-only permissions.\nDefaults to false.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "boolean"
+ },
+ "server": {
+ "description": "server is the hostname or IP address of the NFS server.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#nfs",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "persistentVolumeClaim": {
+ "description": "persistentVolumeClaimVolumeSource represents a reference to a\nPersistentVolumeClaim in the same namespace.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "properties": {
+ "claimName": {
+ "description": "claimName is the name of a PersistentVolumeClaim in the same namespace as the pod using this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Will force the ReadOnly setting in VolumeMounts.\nDefault false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "claimName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "photonPersistentDisk": {
+ "description": "photonPersistentDisk represents a PhotonController persistent disk attached and mounted on kubelets host machine.\nDeprecated: PhotonPersistentDisk is deprecated and the in-tree photonPersistentDisk type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "pdID": {
+ "description": "pdID is the ID that identifies Photon Controller persistent disk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "pdID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "portworxVolume": {
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "volumeID": {
+ "description": "volumeID uniquely identifies a Portworx volume",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumeID"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "projected": {
+ "description": "projected items for all in one resources secrets, configmaps, and downward API",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode are the mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "sources": {
+ "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
+ "items": {
+ "description": "Projection that may be projected along with other supported volume types.\nExactly one of these fields must be set.",
+ "properties": {
+ "clusterTrustBundle": {
+ "description": "ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field\nof ClusterTrustBundle objects in an auto-updating file.\n\nAlpha, gated by the ClusterTrustBundleProjection feature gate.\n\nClusterTrustBundle objects can either be selected by name, or by the\ncombination of signer name and a label selector.\n\nKubelet performs aggressive normalization of the PEM contents written\ninto the pod filesystem. Esoteric PEM features such as inter-block\ncomments and block headers are stripped. Certificates are deduplicated.\nThe ordering of certificates within the file is arbitrary, and Kubelet\nmay change the order over time.",
+ "properties": {
+ "labelSelector": {
+ "description": "Select all ClusterTrustBundles that match this label selector. Only has\neffect if signerName is set. Mutually-exclusive with name. If unset,\ninterpreted as \"match nothing\". If set but empty, interpreted as \"match\neverything\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Select a single ClusterTrustBundle by object name. Mutually-exclusive\nwith signerName and labelSelector.",
+ "type": "string"
+ },
+ "optional": {
+ "description": "If true, don't block pod startup if the referenced ClusterTrustBundle(s)\naren't available. If using name, then the named ClusterTrustBundle is\nallowed not to exist. If using signerName, then the combination of\nsignerName and labelSelector is allowed to match zero\nClusterTrustBundles.",
+ "type": "boolean"
+ },
+ "path": {
+ "description": "Relative path from the volume root to write the bundle.",
+ "type": "string"
+ },
+ "signerName": {
+ "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "configMap": {
+ "description": "configMap information about the configMap data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional specify whether the ConfigMap or its keys must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "downwardAPI": {
+ "description": "downwardAPI information about the downwardAPI data to project",
+ "properties": {
+ "items": {
+ "description": "Items is a list of DownwardAPIVolume file",
+ "items": {
+ "description": "DownwardAPIVolumeFile represents information to create the file containing the pod field",
+ "properties": {
+ "fieldRef": {
+ "description": "Required: Selects a field of the pod: only annotations, labels, name, namespace and uid are supported.",
+ "properties": {
+ "apiVersion": {
+ "description": "Version of the schema the FieldPath is written in terms of, defaults to \"v1\".",
+ "type": "string"
+ },
+ "fieldPath": {
+ "description": "Path of the field to select in the specified API version.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "fieldPath"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "mode": {
+ "description": "Optional: mode bits used to set permissions on this file, must be an octal value\nbetween 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "Required: Path is the relative path name of the file to be created. Must not be absolute or contain the '..' path. Must be utf-8 encoded. The first item of the relative path must not start with '..'",
+ "type": "string"
+ },
+ "resourceFieldRef": {
+ "description": "Selects a resource of the container: only resources limits and requests\n(limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.",
+ "properties": {
+ "containerName": {
+ "description": "Container name: required for volumes, optional for env vars",
+ "type": "string"
+ },
+ "divisor": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "Specifies the output format of the exposed resources, defaults to \"1\"",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "resource": {
+ "description": "Required: resource to select",
+ "type": "string"
+ }
+ },
+ "required": [
+ "resource"
+ ],
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "podCertificate": {
+ "description": "Projects an auto-rotating credential bundle (private key and certificate\nchain) that the pod can use either as a TLS client or server.\n\nKubelet generates a private key and uses it to send a\nPodCertificateRequest to the named signer. Once the signer approves the\nrequest and issues a certificate chain, Kubelet writes the key and\ncertificate chain to the pod filesystem. The pod does not start until\ncertificates have been issued for each podCertificate projected volume\nsource in its spec.\n\nKubelet will begin trying to rotate the certificate at the time indicated\nby the signer using the PodCertificateRequest.Status.BeginRefreshAt\ntimestamp.\n\nKubelet can write a single file, indicated by the credentialBundlePath\nfield, or separate files, indicated by the keyPath and\ncertificateChainPath fields.\n\nThe credential bundle is a single file in PEM format. The first PEM\nentry is the private key (in PKCS#8 format), and the remaining PEM\nentries are the certificate chain issued by the signer (typically,\nsigners will return their certificate chain in leaf-to-root order).\n\nPrefer using the credential bundle format, since your application code\ncan read it atomically. If you use keyPath and certificateChainPath,\nyour application must make two separate file reads. If these coincide\nwith a certificate rotation, it is possible that the private key and leaf\ncertificate you read may not correspond to each other. Your application\nwill need to check for this condition, and re-read until they are\nconsistent.\n\nThe named signer controls chooses the format of the certificate it\nissues; consult the signer implementation's documentation to learn how to\nuse the certificates it issues.",
+ "properties": {
+ "certificateChainPath": {
+ "description": "Write the certificate chain at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "credentialBundlePath": {
+ "description": "Write the credential bundle at this path in the projected volume.\n\nThe credential bundle is a single file that contains multiple PEM blocks.\nThe first PEM block is a PRIVATE KEY block, containing a PKCS#8 private\nkey.\n\nThe remaining blocks are CERTIFICATE blocks, containing the issued\ncertificate chain from the signer (leaf and any intermediates).\n\nUsing credentialBundlePath lets your Pod's application code make a single\natomic read that retrieves a consistent key and certificate chain. If you\nproject them to separate files, your application code will need to\nadditionally check that the leaf certificate was issued to the key.",
+ "type": "string"
+ },
+ "keyPath": {
+ "description": "Write the key at this path in the projected volume.\n\nMost applications should use credentialBundlePath. When using keyPath\nand certificateChainPath, your application needs to check that the key\nand leaf certificate are consistent, because it is possible to read the\nfiles mid-rotation.",
+ "type": "string"
+ },
+ "keyType": {
+ "description": "The type of keypair Kubelet will generate for the pod.\n\nValid values are \"RSA3072\", \"RSA4096\", \"ECDSAP256\", \"ECDSAP384\",\n\"ECDSAP521\", and \"ED25519\".",
+ "type": "string"
+ },
+ "maxExpirationSeconds": {
+ "description": "maxExpirationSeconds is the maximum lifetime permitted for the\ncertificate.\n\nKubelet copies this value verbatim into the PodCertificateRequests it\ngenerates for this projection.\n\nIf omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver\nwill reject values shorter than 3600 (1 hour). The maximum allowable\nvalue is 7862400 (91 days).\n\nThe signer implementation is then free to issue a certificate with any\nlifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600\nseconds (1 hour). This constraint is enforced by kube-apiserver.\n`kubernetes.io` signers will never issue certificates with a lifetime\nlonger than 24 hours.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "signerName": {
+ "description": "Kubelet's generated CSRs will be addressed to this signer.",
+ "type": "string"
+ },
+ "userAnnotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "userAnnotations allow pod authors to pass additional information to\nthe signer implementation. Kubernetes does not restrict or validate this\nmetadata in any way.\n\nThese values are copied verbatim into the `spec.unverifiedUserAnnotations` field of\nthe PodCertificateRequest objects that Kubelet creates.\n\nEntries are subject to the same validation as object metadata annotations,\nwith the addition that all keys must be domain-prefixed. No restrictions\nare placed on values, except an overall size limitation on the entire field.\n\nSigners should document the keys and values they support. Signers should\ndeny requests that contain keys they do not recognize.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "keyType",
+ "signerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret information about the secret data to project",
+ "properties": {
+ "items": {
+ "description": "items if unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its key must be defined",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "serviceAccountToken": {
+ "description": "serviceAccountToken is information about the serviceAccountToken data to project",
+ "properties": {
+ "audience": {
+ "description": "audience is the intended audience of the token. A recipient of a token\nmust identify itself with an identifier specified in the audience of the\ntoken, and otherwise should reject the token. The audience defaults to the\nidentifier of the apiserver.",
+ "type": "string"
+ },
+ "expirationSeconds": {
+ "description": "expirationSeconds is the requested duration of validity of the service\naccount token. As the token approaches expiration, the kubelet volume\nplugin will proactively rotate the service account token. The kubelet will\nstart trying to rotate the token if the token is older than 80 percent of\nits time to live or if the token is older than 24 hours.Defaults to 1 hour\nand must be at least 10 minutes.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "quobyte": {
+ "description": "quobyte represents a Quobyte mount on the host that shares a pod's lifetime.\nDeprecated: Quobyte is deprecated and the in-tree quobyte type is no longer supported.",
+ "properties": {
+ "group": {
+ "description": "group to map volume access to\nDefault is no group",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the Quobyte volume to be mounted with read-only permissions.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "registry": {
+ "description": "registry represents a single or multiple Quobyte Registry services\nspecified as a string as host:port pair (multiple entries are separated with commas)\nwhich acts as the central registry for volumes",
+ "type": "string"
+ },
+ "tenant": {
+ "description": "tenant owning the given Quobyte volume in the Backend\nUsed with dynamically provisioned Quobyte volumes, value is set by the plugin",
+ "type": "string"
+ },
+ "user": {
+ "description": "user to map volume access to\nDefaults to serivceaccount user",
+ "type": "string"
+ },
+ "volume": {
+ "description": "volume is a string that references an already created Quobyte volume by name.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "registry",
+ "volume"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "rbd": {
+ "description": "rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.\nDeprecated: RBD is deprecated and the in-tree rbd type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type of the volume that you want to mount.\nTip: Ensure that the filesystem type is supported by the host operating system.\nExamples: \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#rbd",
+ "type": "string"
+ },
+ "image": {
+ "description": "image is the rados image name.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "keyring": {
+ "default": "/etc/ceph/keyring",
+ "description": "keyring is the path to key ring for RBDUser.\nDefault is /etc/ceph/keyring.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "monitors": {
+ "description": "monitors is a collection of Ceph monitors.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "pool": {
+ "default": "rbd",
+ "description": "pool is the rados pool name.\nDefault is rbd.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly here will force the ReadOnly setting in VolumeMounts.\nDefaults to false.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef is name of the authentication secret for RBDUser. If provided\noverrides keyring.\nDefault is nil.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "user": {
+ "default": "admin",
+ "description": "user is the rados user name.\nDefault is admin.\nMore info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it",
+ "type": "string"
+ }
+ },
+ "required": [
+ "image",
+ "monitors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scaleIO": {
+ "description": "scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes nodes.\nDeprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "default": "xfs",
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\".\nDefault is \"xfs\".",
+ "type": "string"
+ },
+ "gateway": {
+ "description": "gateway is the host address of the ScaleIO API Gateway.",
+ "type": "string"
+ },
+ "protectionDomain": {
+ "description": "protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly Defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef references to the secret for ScaleIO user and other\nsensitive information. If this is not provided, Login operation will fail.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "sslEnabled": {
+ "description": "sslEnabled Flag enable/disable SSL communication with Gateway, default false",
+ "type": "boolean"
+ },
+ "storageMode": {
+ "default": "ThinProvisioned",
+ "description": "storageMode indicates whether the storage for a volume should be ThickProvisioned or ThinProvisioned.\nDefault is ThinProvisioned.",
+ "type": "string"
+ },
+ "storagePool": {
+ "description": "storagePool is the ScaleIO Storage Pool associated with the protection domain.",
+ "type": "string"
+ },
+ "system": {
+ "description": "system is the name of the storage system as configured in ScaleIO.",
+ "type": "string"
+ },
+ "volumeName": {
+ "description": "volumeName is the name of a volume already created in the ScaleIO system\nthat is associated with this volume source.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "gateway",
+ "secretRef",
+ "system"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "secret": {
+ "description": "secret represents a secret that should populate this volume.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "properties": {
+ "defaultMode": {
+ "description": "defaultMode is Optional: mode bits used to set permissions on created files by default.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values\nfor mode bits. Defaults to 0644.\nDirectories within the path are not affected by this setting.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "items": {
+ "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
+ "items": {
+ "description": "Maps a string key to a path within a volume.",
+ "properties": {
+ "key": {
+ "description": "key is the key to project.",
+ "type": "string"
+ },
+ "mode": {
+ "description": "mode is Optional: mode bits used to set permissions on this file.\nMust be an octal value between 0000 and 0777 or a decimal value between 0 and 511.\nYAML accepts both octal and decimal values, JSON requires decimal values for mode bits.\nIf not specified, the volume defaultMode will be used.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup, and the result can be other mode bits set.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "path": {
+ "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "key",
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "optional": {
+ "description": "optional field specify whether the Secret or its keys must be defined",
+ "type": "boolean"
+ },
+ "secretName": {
+ "description": "secretName is the name of the secret in the pod's namespace to use.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#secret",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "storageos": {
+ "description": "storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.\nDeprecated: StorageOS is deprecated and the in-tree storageos type is no longer supported.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is the filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "readOnly": {
+ "description": "readOnly defaults to false (read/write). ReadOnly here will force\nthe ReadOnly setting in VolumeMounts.",
+ "type": "boolean"
+ },
+ "secretRef": {
+ "description": "secretRef specifies the secret to use for obtaining the StorageOS API\ncredentials. If not specified, default values will be attempted.",
+ "properties": {
+ "name": {
+ "default": "",
+ "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ },
+ "volumeName": {
+ "description": "volumeName is the human-readable name of the StorageOS volume. Volume\nnames are only unique within a namespace.",
+ "type": "string"
+ },
+ "volumeNamespace": {
+ "description": "volumeNamespace specifies the scope of the volume within StorageOS. If no\nnamespace is specified then the Pod's namespace will be used. This allows the\nKubernetes name scoping to be mirrored within StorageOS for tighter integration.\nSet VolumeName to any name to override the default behaviour.\nSet to \"default\" if you are not using namespaces within StorageOS.\nNamespaces that do not pre-exist within StorageOS will be created.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "vsphereVolume": {
+ "description": "vsphereVolume represents a vSphere volume attached and mounted on kubelets host machine.\nDeprecated: VsphereVolume is deprecated. All operations for the in-tree vsphereVolume type\nare redirected to the csi.vsphere.vmware.com CSI driver.",
+ "properties": {
+ "fsType": {
+ "description": "fsType is filesystem type to mount.\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\", \"ntfs\". Implicitly inferred to be \"ext4\" if unspecified.",
+ "type": "string"
+ },
+ "storagePolicyID": {
+ "description": "storagePolicyID is the storage Policy Based Management (SPBM) profile ID associated with the StoragePolicyName.",
+ "type": "string"
+ },
+ "storagePolicyName": {
+ "description": "storagePolicyName is the storage Policy Based Management (SPBM) profile name.",
+ "type": "string"
+ },
+ "volumePath": {
+ "description": "volumePath is the path that identifies vSphere volume vmdk",
+ "type": "string"
+ }
+ },
+ "required": [
+ "volumePath"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "replicas": {
+ "description": "Replicas is the number of desired pods. Defaults to 1.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "strategy": {
+ "description": "The deployment strategy to use to replace existing pods with new ones.",
+ "properties": {
+ "rollingUpdate": {
+ "description": "Rolling update config params. Present only if DeploymentStrategyType =\nRollingUpdate.",
+ "properties": {
+ "maxSurge": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of pods that can be scheduled above the desired number of\npods.\nValue can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%).\nThis can not be 0 if MaxUnavailable is 0.\nAbsolute number is calculated from percentage by rounding up.\nDefaults to 25%.\nExample: when this is set to 30%, the new ReplicaSet can be scaled up immediately when\nthe rolling update starts, such that the total number of old and new pods do not exceed\n130% of desired pods. Once old pods have been killed,\nnew ReplicaSet can be scaled up further, ensuring that total number of pods running\nat any time during the update is at most 130% of desired pods.",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxUnavailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "The maximum number of pods that can be unavailable during the update.\nValue can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%).\nAbsolute number is calculated from percentage by rounding down.\nThis can not be 0 if MaxSurge is 0.\nDefaults to 25%.\nExample: when this is set to 30%, the old ReplicaSet can be scaled down to 70% of desired pods\nimmediately when the rolling update starts. Once new pods are ready, old ReplicaSet\ncan be scaled down further, followed by scaling up the new ReplicaSet, ensuring\nthat the total number of pods available at all times during the update is at\nleast 70% of desired pods.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type of deployment. Can be \"Recreate\" or \"RollingUpdate\". Default is RollingUpdate.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "envoyHpa": {
+ "description": "EnvoyHpa defines the Horizontal Pod Autoscaler settings for Envoy Proxy Deployment.",
+ "properties": {
+ "behavior": {
+ "description": "behavior configures the scaling behavior of the target\nin both Up and Down directions (scaleUp and scaleDown fields respectively).\nIf not set, the default HPAScalingRules for scale up and scale down are used.\nSee k8s.io.autoscaling.v2.HorizontalPodAutoScalerBehavior.",
+ "properties": {
+ "scaleDown": {
+ "description": "scaleDown is scaling policy for scaling Down.\nIf not set, the default value is to allow to scale down to minReplicas pods, with a\n300 second stabilization window (i.e., the highest recommendation for\nthe last 300sec is used).",
+ "properties": {
+ "policies": {
+ "description": "policies is a list of potential scaling polices which can be used during scaling.\nIf not set, use the default values:\n- For scale up: allow doubling the number of pods, or an absolute change of 4 pods in a 15s window.\n- For scale down: allow all pods to be removed in a 15s window.",
+ "items": {
+ "description": "HPAScalingPolicy is a single policy which must hold true for a specified past interval.",
+ "properties": {
+ "periodSeconds": {
+ "description": "periodSeconds specifies the window of time for which the policy should hold true.\nPeriodSeconds must be greater than zero and less than or equal to 1800 (30 min).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": {
+ "description": "type is used to specify the scaling policy.",
+ "type": "string"
+ },
+ "value": {
+ "description": "value contains the amount of change which is permitted by the policy.\nIt must be greater than zero",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "periodSeconds",
+ "type",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "selectPolicy": {
+ "description": "selectPolicy is used to specify which policy should be used.\nIf not set, the default value Max is used.",
+ "type": "string"
+ },
+ "stabilizationWindowSeconds": {
+ "description": "stabilizationWindowSeconds is the number of seconds for which past recommendations should be\nconsidered while scaling up or scaling down.\nStabilizationWindowSeconds must be greater than or equal to zero and less than or equal to 3600 (one hour).\nIf not set, use the default values:\n- For scale up: 0 (i.e. no stabilization is done).\n- For scale down: 300 (i.e. the stabilization window is 300 seconds long).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tolerance": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "tolerance is the tolerance on the ratio between the current and desired\nmetric value under which no updates are made to the desired number of\nreplicas (e.g. 0.01 for 1%). Must be greater than or equal to zero. If not\nset, the default cluster-wide tolerance is applied (by default 10%).\n\nFor example, if autoscaling is configured with a memory consumption target of 100Mi,\nand scale-down and scale-up tolerances of 5% and 1% respectively, scaling will be\ntriggered when the actual consumption falls below 95Mi or exceeds 101Mi.\n\nThis is an beta field and requires the HPAConfigurableTolerance feature\ngate to be enabled.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "scaleUp": {
+ "description": "scaleUp is scaling policy for scaling Up.\nIf not set, the default value is the higher of:\n * increase no more than 4 pods per 60 seconds\n * double the number of pods per 60 seconds\nNo stabilization is used.",
+ "properties": {
+ "policies": {
+ "description": "policies is a list of potential scaling polices which can be used during scaling.\nIf not set, use the default values:\n- For scale up: allow doubling the number of pods, or an absolute change of 4 pods in a 15s window.\n- For scale down: allow all pods to be removed in a 15s window.",
+ "items": {
+ "description": "HPAScalingPolicy is a single policy which must hold true for a specified past interval.",
+ "properties": {
+ "periodSeconds": {
+ "description": "periodSeconds specifies the window of time for which the policy should hold true.\nPeriodSeconds must be greater than zero and less than or equal to 1800 (30 min).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "type": {
+ "description": "type is used to specify the scaling policy.",
+ "type": "string"
+ },
+ "value": {
+ "description": "value contains the amount of change which is permitted by the policy.\nIt must be greater than zero",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "required": [
+ "periodSeconds",
+ "type",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "selectPolicy": {
+ "description": "selectPolicy is used to specify which policy should be used.\nIf not set, the default value Max is used.",
+ "type": "string"
+ },
+ "stabilizationWindowSeconds": {
+ "description": "stabilizationWindowSeconds is the number of seconds for which past recommendations should be\nconsidered while scaling up or scaling down.\nStabilizationWindowSeconds must be greater than or equal to zero and less than or equal to 3600 (one hour).\nIf not set, use the default values:\n- For scale up: 0 (i.e. no stabilization is done).\n- For scale down: 300 (i.e. the stabilization window is 300 seconds long).",
+ "format": "int32",
+ "type": "integer"
+ },
+ "tolerance": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "tolerance is the tolerance on the ratio between the current and desired\nmetric value under which no updates are made to the desired number of\nreplicas (e.g. 0.01 for 1%). Must be greater than or equal to zero. If not\nset, the default cluster-wide tolerance is applied (by default 10%).\n\nFor example, if autoscaling is configured with a memory consumption target of 100Mi,\nand scale-down and scale-up tolerances of 5% and 1% respectively, scaling will be\ntriggered when the actual consumption falls below 95Mi or exceeds 101Mi.\n\nThis is an beta field and requires the HPAConfigurableTolerance feature\ngate to be enabled.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxReplicas": {
+ "description": "maxReplicas is the upper limit for the number of replicas to which the autoscaler can scale up.\nIt cannot be less that minReplicas.",
+ "format": "int32",
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "maxReplicas must be greater than 0",
+ "rule": "self > 0"
+ }
+ ]
+ },
+ "metrics": {
+ "description": "metrics contains the specifications for which to use to calculate the\ndesired replica count (the maximum replica count across all metrics will\nbe used).\nIf left empty, it defaults to being based on CPU utilization with average on 80% usage.",
+ "items": {
+ "description": "MetricSpec specifies how to scale based on a single metric\n(only `type` and one other matching field should be set at once).",
+ "properties": {
+ "containerResource": {
+ "description": "containerResource refers to a resource metric (such as those specified in\nrequests and limits) known to Kubernetes describing a single container in\neach pod of the current scale target (e.g. CPU or memory). Such metrics are\nbuilt in to Kubernetes, and have special scaling options on top of those\navailable to normal per-pod metrics using the \"pods\" source.",
+ "properties": {
+ "container": {
+ "description": "container is the name of the container in the pods of the scaling target",
+ "type": "string"
+ },
+ "name": {
+ "description": "name is the name of the resource in question.",
+ "type": "string"
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "container",
+ "name",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "external": {
+ "description": "external refers to a global metric that is not associated\nwith any Kubernetes object. It allows autoscaling based on information\ncoming from components running outside of cluster\n(for example length of queue in cloud messaging service, or\nQPS from loadbalancer running outside of cluster).",
+ "properties": {
+ "metric": {
+ "description": "metric identifies the target metric by name and selector",
+ "properties": {
+ "name": {
+ "description": "name is the name of the given metric",
+ "type": "string"
+ },
+ "selector": {
+ "description": "selector is the string-encoded form of a standard kubernetes label selector for the given metric\nWhen set, it is passed as an additional parameter to the metrics server for more specific metrics scoping.\nWhen unset, just the metricName will be used to gather metrics.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "metric",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "object": {
+ "description": "object refers to a metric describing a single kubernetes object\n(for example, hits-per-second on an Ingress object).",
+ "properties": {
+ "describedObject": {
+ "description": "describedObject specifies the descriptions of a object,such as kind,name apiVersion",
+ "properties": {
+ "apiVersion": {
+ "description": "apiVersion is the API version of the referent",
+ "type": "string"
+ },
+ "kind": {
+ "description": "kind is the kind of the referent; More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "name": {
+ "description": "name is the name of the referent; More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metric": {
+ "description": "metric identifies the target metric by name and selector",
+ "properties": {
+ "name": {
+ "description": "name is the name of the given metric",
+ "type": "string"
+ },
+ "selector": {
+ "description": "selector is the string-encoded form of a standard kubernetes label selector for the given metric\nWhen set, it is passed as an additional parameter to the metrics server for more specific metrics scoping.\nWhen unset, just the metricName will be used to gather metrics.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "describedObject",
+ "metric",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "pods": {
+ "description": "pods refers to a metric describing each pod in the current scale target\n(for example, transactions-processed-per-second). The values will be\naveraged together before being compared to the target value.",
+ "properties": {
+ "metric": {
+ "description": "metric identifies the target metric by name and selector",
+ "properties": {
+ "name": {
+ "description": "name is the name of the given metric",
+ "type": "string"
+ },
+ "selector": {
+ "description": "selector is the string-encoded form of a standard kubernetes label selector for the given metric\nWhen set, it is passed as an additional parameter to the metrics server for more specific metrics scoping.\nWhen unset, just the metricName will be used to gather metrics.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "metric",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "resource": {
+ "description": "resource refers to a resource metric (such as those specified in\nrequests and limits) known to Kubernetes describing each pod in the\ncurrent scale target (e.g. CPU or memory). Such metrics are built in to\nKubernetes, and have special scaling options on top of those available\nto normal per-pod metrics using the \"pods\" source.",
+ "properties": {
+ "name": {
+ "description": "name is the name of the resource in question.",
+ "type": "string"
+ },
+ "target": {
+ "description": "target specifies the target value for the given metric",
+ "properties": {
+ "averageUtilization": {
+ "description": "averageUtilization is the target value of the average of the\nresource metric across all relevant pods, represented as a percentage of\nthe requested value of the resource for the pods.\nCurrently only valid for Resource metric source type",
+ "format": "int32",
+ "type": "integer"
+ },
+ "averageValue": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "averageValue is the target value of the average of the\nmetric across all relevant pods (as a quantity)",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "type represents whether the metric type is Utilization, Value, or AverageValue",
+ "type": "string"
+ },
+ "value": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "value is the target value of the metric (as a quantity).",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "target"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "type is the type of metric source. It should be one of \"ContainerResource\", \"External\",\n\"Object\", \"Pods\" or \"Resource\", each mapping to a matching field in the object.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "minReplicas": {
+ "description": "minReplicas is the lower limit for the number of replicas to which the autoscaler\ncan scale down. It defaults to 1 replica.",
+ "format": "int32",
+ "type": "integer",
+ "x-kubernetes-validations": [
+ {
+ "message": "minReplicas must be greater than 0",
+ "rule": "self > 0"
+ }
+ ]
+ },
+ "name": {
+ "description": "Name of the horizontalPodAutoScaler.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to the HorizontalPodAutoscaler",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "maxReplicas"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "maxReplicas cannot be less than minReplicas",
+ "rule": "!has(self.minReplicas) || self.maxReplicas >= self.minReplicas"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "envoyPDB": {
+ "description": "EnvoyPDB allows to control the pod disruption budget of an Envoy Proxy.",
+ "properties": {
+ "maxUnavailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MaxUnavailable specifies the maximum amount of pods (can be expressed as integers or as a percentage) that can be unavailable at all times during voluntary disruptions,\nsuch as node drains or updates. This setting ensures that your envoy proxy maintains a certain level of availability\nand resilience during maintenance operations. Cannot be combined with minAvailable.",
+ "x-kubernetes-int-or-string": true
+ },
+ "minAvailable": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinAvailable specifies the minimum amount of pods (can be expressed as integers or as a percentage) that must be available at all times during voluntary disruptions,\nsuch as node drains or updates. This setting ensures that your envoy proxy maintains a certain level of availability\nand resilience during maintenance operations. Cannot be combined with maxUnavailable.",
+ "x-kubernetes-int-or-string": true
+ },
+ "name": {
+ "description": "Name of the podDisruptionBudget.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to the PodDisruptionBudget",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of minAvailable or maxUnavailable can be specified",
+ "rule": "(has(self.minAvailable) && !has(self.maxUnavailable)) || (!has(self.minAvailable) && has(self.maxUnavailable))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "envoyService": {
+ "description": "EnvoyService defines the desired state of the Envoy service resource.\nIf unspecified, default settings for the managed Envoy service resource\nare applied.",
+ "properties": {
+ "allocateLoadBalancerNodePorts": {
+ "description": "AllocateLoadBalancerNodePorts defines if NodePorts will be automatically allocated for\nservices with type LoadBalancer. Default is \"true\". It may be set to \"false\" if the cluster\nload-balancer does not rely on NodePorts. If the caller requests specific NodePorts (by specifying a\nvalue), those requests will be respected, regardless of this field. This field may only be set for\nservices with type LoadBalancer and will be cleared if the type is changed to any other type.",
+ "type": "boolean"
+ },
+ "annotations": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Annotations that should be appended to the service.\nBy default, no annotations are appended.",
+ "type": "object"
+ },
+ "externalTrafficPolicy": {
+ "default": "Local",
+ "description": "ExternalTrafficPolicy determines the externalTrafficPolicy for the Envoy Service. Valid options\nare Local and Cluster. Default is \"Local\". \"Local\" means traffic will only go to pods on the node\nreceiving the traffic. \"Cluster\" means connections are loadbalanced to all pods in the cluster.",
+ "enum": [
+ "Local",
+ "Cluster"
+ ],
+ "type": "string"
+ },
+ "labels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Labels that should be appended to the service.\nBy default, no labels are appended.",
+ "type": "object"
+ },
+ "loadBalancerClass": {
+ "description": "LoadBalancerClass, when specified, allows for choosing the LoadBalancer provider\nimplementation if more than one are available or is otherwise expected to be specified",
+ "type": "string"
+ },
+ "loadBalancerIP": {
+ "description": "LoadBalancerIP defines the IP Address of the underlying load balancer service. This field\nmay be ignored if the load balancer provider does not support this feature.\nThis field has been deprecated in Kubernetes, but it is still used for setting the IP Address in some cloud\nproviders such as GCP.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "loadBalancerIP must be a valid IPv4 address",
+ "rule": "self.matches(r\"^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$\")"
+ }
+ ]
+ },
+ "loadBalancerSourceRanges": {
+ "description": "LoadBalancerSourceRanges defines a list of allowed IP addresses which will be configured as\nfirewall rules on the platform providers load balancer. This is not guaranteed to be working as\nit happens outside of kubernetes and has to be supported and handled by the platform provider.\nThis field may only be set for services with type LoadBalancer and will be cleared if the type\nis changed to any other type.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "name": {
+ "description": "Name of the service.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ },
+ "patch": {
+ "description": "Patch defines how to perform the patch operation to the service",
+ "properties": {
+ "type": {
+ "description": "Type is the type of merge operation to perform\n\nBy default, StrategicMerge is used as the patch type.",
+ "type": "string"
+ },
+ "value": {
+ "description": "Object contains the raw configuration for merged object",
+ "x-kubernetes-preserve-unknown-fields": true
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "LoadBalancer",
+ "description": "Type determines how the Service is exposed. Defaults to LoadBalancer.\nValid options are ClusterIP, LoadBalancer and NodePort.\n\"LoadBalancer\" means a service will be exposed via an external load balancer (if the cloud provider supports it).\n\"ClusterIP\" means a service will only be accessible inside the cluster, via the cluster IP.\n\"NodePort\" means a service will be exposed on a static Port on all Nodes of the cluster.",
+ "enum": [
+ "ClusterIP",
+ "LoadBalancer",
+ "NodePort"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "allocateLoadBalancerNodePorts can only be set for LoadBalancer type",
+ "rule": "!has(self.allocateLoadBalancerNodePorts) || self.type == 'LoadBalancer'"
+ },
+ {
+ "message": "loadBalancerSourceRanges can only be set for LoadBalancer type",
+ "rule": "!has(self.loadBalancerSourceRanges) || self.type == 'LoadBalancer'"
+ },
+ {
+ "message": "loadBalancerIP can only be set for LoadBalancer type",
+ "rule": "!has(self.loadBalancerIP) || self.type == 'LoadBalancer'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "envoyServiceAccount": {
+ "description": "EnvoyServiceAccount defines the desired state of the Envoy service account resource.",
+ "properties": {
+ "name": {
+ "description": "Name of the Service Account.\nWhen unset, this defaults to an autogenerated name.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "useListenerPortAsContainerPort": {
+ "description": "UseListenerPortAsContainerPort disables the port shifting feature in the Envoy Proxy.\nWhen set to false (default value), if the service port is a privileged port (1-1023), add a constant to the value converting it into an ephemeral port.\nThis allows the container to bind to the port without needing a CAP_NET_BIND_SERVICE capability.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of envoyDeployment or envoyDaemonSet can be specified",
+ "rule": "((has(self.envoyDeployment) && !has(self.envoyDaemonSet)) || (!has(self.envoyDeployment) && has(self.envoyDaemonSet))) || (!has(self.envoyDeployment) && !has(self.envoyDaemonSet))"
+ },
+ {
+ "message": "cannot use envoyHpa if envoyDaemonSet is used",
+ "rule": "((has(self.envoyHpa) && !has(self.envoyDaemonSet)) || (!has(self.envoyHpa) && has(self.envoyDaemonSet))) || (!has(self.envoyHpa) && !has(self.envoyDaemonSet))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type is the type of resource provider to use. A resource provider provides\ninfrastructure resources for running the data plane, e.g. Envoy proxy, and\noptional auxiliary control planes. Supported types are \"Kubernetes\"and \"Host\".",
+ "enum": [
+ "Kubernetes",
+ "Host"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "routingType": {
+ "description": "RoutingType can be set to \"Service\" to use the Service Cluster IP for routing to the backend,\nor it can be set to \"Endpoint\" to use Endpoint routing. The default is \"Endpoint\".",
+ "type": "string"
+ },
+ "shutdown": {
+ "description": "Shutdown defines configuration for graceful envoy shutdown process.",
+ "properties": {
+ "drainTimeout": {
+ "description": "DrainTimeout defines the graceful drain timeout. This should be less than the pod's terminationGracePeriodSeconds.\nIf unspecified, defaults to 60 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "minDrainDuration": {
+ "description": "MinDrainDuration defines the minimum drain duration allowing time for endpoint deprogramming to complete.\nIf unspecified, defaults to 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "telemetry": {
+ "description": "Telemetry defines telemetry parameters for managed proxies.",
+ "properties": {
+ "accessLog": {
+ "description": "AccessLogs defines accesslog parameters for managed proxies.\nIf unspecified, will send default format to stdout.",
+ "properties": {
+ "disable": {
+ "description": "Disable disables access logging for managed proxies if set to true.",
+ "type": "boolean"
+ },
+ "settings": {
+ "description": "Settings defines accesslog settings for managed proxies.\nIf unspecified, will send default format to stdout.",
+ "items": {
+ "properties": {
+ "format": {
+ "description": "Format defines the format of accesslog.\nThis will be ignored if sink type is ALS.",
+ "properties": {
+ "json": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "JSON is additional attributes that describe the specific event occurrence.\nStructured format for the envoy access logs. Envoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators)\ncan be used as values for fields within the Struct.\nIt's required when the format type is \"JSON\".",
+ "type": "object"
+ },
+ "text": {
+ "description": "Text defines the text accesslog format, following Envoy accesslog formatting,\nIt's required when the format type is \"Text\".\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the format.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Type defines the type of accesslog format.\nWhen unset, both text and json can be specified.",
+ "enum": [
+ "Text",
+ "JSON"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If AccessLogFormat type is Text, text field needs to be set.",
+ "rule": "has(self.type) && self.type == 'Text' ? has(self.text) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is Text, json field must not be set.",
+ "rule": "has(self.type) && self.type == 'Text' ? !has(self.json) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is JSON, json field needs to be set.",
+ "rule": "has(self.type) && self.type == 'JSON' ? has(self.json) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is JSON, text field must not be set.",
+ "rule": "has(self.type) && self.type == 'JSON' ? !has(self.text) : true"
+ },
+ {
+ "message": "If AccessLogFormat type is unset, at least one of text or json must be set.",
+ "rule": "!has(self.type) ? (has(self.text) || has(self.json)) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "matches": {
+ "description": "Matches defines the match conditions for accesslog in CEL expression.\nAn accesslog will be emitted only when one or more match conditions are evaluated to true.\nInvalid [CEL](https://www.envoyproxy.io/docs/envoy/latest/xds/type/v3/cel.proto.html#common-expression-language-cel-proto) expressions will be ignored.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 10,
+ "type": "array"
+ },
+ "sinks": {
+ "description": "Sinks defines the sinks of accesslog.",
+ "items": {
+ "description": "ProxyAccessLogSink defines the sink of accesslog.",
+ "properties": {
+ "als": {
+ "description": "ALS defines the gRPC Access Log Service (ALS) sink.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTP defines additional configuration specific to HTTP access logs.",
+ "properties": {
+ "requestHeaders": {
+ "description": "RequestHeaders defines request headers to include in log entries sent to the access log service.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "responseHeaders": {
+ "description": "ResponseHeaders defines response headers to include in log entries sent to the access log service.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "responseTrailers": {
+ "description": "ResponseTrailers defines response trailers to include in log entries sent to the access log service.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "logName": {
+ "description": "LogName defines the friendly name of the access log to be returned in\nStreamAccessLogsMessage.Identifier. This allows the access log server\nto differentiate between different access logs coming from the same Envoy.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "description": "Type defines the type of accesslog. Supported types are \"HTTP\" and \"TCP\".",
+ "enum": [
+ "HTTP",
+ "TCP"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "The http field may only be set when type is HTTP.",
+ "rule": "self.type == 'HTTP' || !has(self.http)"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "must have at least one backend in backendRefs",
+ "rule": "has(self.backendRefs) && self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "file": {
+ "description": "File defines the file accesslog sink.",
+ "properties": {
+ "path": {
+ "description": "Path defines the file path used to expose envoy access log(e.g. /dev/stdout).",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "openTelemetry": {
+ "description": "OpenTelemetry defines the OpenTelemetry accesslog sink.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers is a list of additional headers to send with OTLP export requests.\nThese headers are added as gRPC initial metadata for the OTLP gRPC service.",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "host": {
+ "description": "Host define the extension service hostname.\n\nDeprecated: Use BackendRefs instead.",
+ "type": "string"
+ },
+ "port": {
+ "default": 4317,
+ "description": "Port defines the port the extension service is exposed on.\n\nDeprecated: Use BackendRefs instead.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes is a set of labels that describe the source of a log entry, including envoy node info.\nIt's recommended to follow [semantic conventions](https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/).",
+ "type": "object"
+ },
+ "resources": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Resources is a set of labels that describe the source of a log entry, including envoy node info.\nIt's recommended to follow [semantic conventions](https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/).\n\nDeprecated: Use ResourceAttributes instead.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "host or backendRefs needs to be set",
+ "rule": "has(self.host) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "either resources or resourceAttributes can be set, not both",
+ "rule": "!has(self.resources) || !has(self.resourceAttributes)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type defines the type of accesslog sink.",
+ "enum": [
+ "ALS",
+ "File",
+ "OpenTelemetry"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If AccessLogSink type is ALS, als field needs to be set.",
+ "rule": "self.type == 'ALS' ? has(self.als) : !has(self.als)"
+ },
+ {
+ "message": "If AccessLogSink type is File, file field needs to be set.",
+ "rule": "self.type == 'File' ? has(self.file) : !has(self.file)"
+ },
+ {
+ "message": "If AccessLogSink type is OpenTelemetry, openTelemetry field needs to be set.",
+ "rule": "self.type == 'OpenTelemetry' ? has(self.openTelemetry) : !has(self.openTelemetry)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ },
+ "type": {
+ "description": "Type defines the component emitting the accesslog, such as Listener and Route.\nIf type not defined, the setting would apply to:\n(1) All Routes.\n(2) Listeners if and only if Envoy does not find a matching route for a request.\nIf type is defined, the accesslog settings would apply to the relevant component (as-is).",
+ "enum": [
+ "Listener",
+ "Route",
+ "Upstream"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "sinks"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 50,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "metrics": {
+ "description": "Metrics defines metrics configuration for managed proxies.",
+ "properties": {
+ "clusterStatName": {
+ "description": "ClusterStatName defines the value of cluster alt_stat_name, determining how cluster stats are named.\nFor more details, see envoy docs: https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto.html\nThe supported operators for this pattern are:\n`%ROUTE_NAME%`: name of Gateway API xRoute resource\n`%ROUTE_NAMESPACE%`: namespace of Gateway API xRoute resource\n`%ROUTE_KIND%`: kind of Gateway API xRoute resource\n`%ROUTE_RULE_NAME%`: name of the Gateway API xRoute section\n`%ROUTE_RULE_NUMBER%`: name of the Gateway API xRoute section\n`%BACKEND_REFS%`: names of all backends referenced in `/|/|...` format\nOnly xDS Clusters created for HTTPRoute and GRPCRoute are currently supported.\nDefault: `%ROUTE_KIND%/%ROUTE_NAMESPACE%/%ROUTE_NAME%/rule/%ROUTE_RULE_NUMBER%`\nExample: `httproute/my-ns/my-route/rule/0`",
+ "type": "string"
+ },
+ "enableGRPCStats": {
+ "description": "EnableGRPCStats enables the gRPC stats filter on listeners.\nThis is enabled by default for GRPCRoute and opt-in for HTTPRoute.\nIn general, gRPC traffic should be handled via GRPCRoute, but there are cases where\nusers want to route gRPC using HTTPRoute for its richer matching capabilities.\nTherefore, we enable this behavior only when it is explicitly opted in.",
+ "type": "boolean"
+ },
+ "enablePerEndpointStats": {
+ "description": "EnablePerEndpointStats enables per endpoint envoy stats metrics.\nPlease use with caution.",
+ "type": "boolean"
+ },
+ "enableRequestResponseSizesStats": {
+ "description": "EnableRequestResponseSizesStats enables publishing of histograms tracking header and body sizes of requests and responses.",
+ "type": "boolean"
+ },
+ "enableVirtualHostStats": {
+ "description": "EnableVirtualHostStats enables envoy stat metrics for virtual hosts.",
+ "type": "boolean"
+ },
+ "matches": {
+ "description": "Matches defines configuration for selecting specific metrics instead of generating all metrics stats\nthat are enabled by default. This helps reduce CPU and memory overhead in Envoy, but eliminating some stats\nmay after critical functionality. Here are the stats that we strongly recommend not disabling:\n`cluster_manager.warming_clusters`, `cluster..membership_total`,`cluster..membership_healthy`,\n`cluster..membership_degraded`\uff0creference https://github.com/envoyproxy/envoy/issues/9856,\nhttps://github.com/envoyproxy/envoy/issues/14610",
+ "items": {
+ "description": "StringMatch defines how to match any strings.\nThis is a general purpose match condition that can be used by other EG APIs\nthat need to match against a string.",
+ "properties": {
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "prometheus": {
+ "description": "Prometheus defines the configuration for Admin endpoint `/stats/prometheus`.",
+ "properties": {
+ "compression": {
+ "description": "Configure the compression on Prometheus endpoint. Compression is useful in situations when bandwidth is scarce and large payloads can be effectively compressed at the expense of higher CPU load.",
+ "properties": {
+ "brotli": {
+ "description": "The configuration for Brotli compressor.",
+ "type": "object"
+ },
+ "gzip": {
+ "description": "The configuration for GZIP compressor.",
+ "type": "object"
+ },
+ "minContentLength": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "MinContentLength defines the minimum response size in bytes to apply compression.\nResponses smaller than this threshold will not be compressed.\nMust be at least 30 bytes as enforced by Envoy Proxy.\nNote that when the suffix is not provided, the value is interpreted as bytes.\nDefault: 30 bytes",
+ "x-kubernetes-int-or-string": true
+ },
+ "type": {
+ "description": "CompressorType defines the compressor type to use for compression.",
+ "enum": [
+ "Gzip",
+ "Brotli",
+ "Zstd"
+ ],
+ "type": "string"
+ },
+ "zstd": {
+ "description": "The configuration for Zstd compressor.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "disable": {
+ "description": "Disable the Prometheus endpoint.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sinks": {
+ "description": "Sinks defines the metric sinks where metrics are sent to.",
+ "items": {
+ "description": "ProxyMetricSink defines the sink of metrics.\nDefault metrics sink is OpenTelemetry.",
+ "properties": {
+ "openTelemetry": {
+ "description": "OpenTelemetry defines the configuration for OpenTelemetry sink.\nIt's required if the sink type is OpenTelemetry.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers is a list of additional headers to send with OTLP export requests.\nThese headers are added as gRPC initial metadata for the OTLP gRPC service.",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "host": {
+ "description": "Host define the service hostname.\n\nDeprecated: Use BackendRefs instead.",
+ "type": "string"
+ },
+ "port": {
+ "default": 4317,
+ "description": "Port defines the port the service is exposed on.\n\nDeprecated: Use BackendRefs instead.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reportCountersAsDeltas": {
+ "description": "ReportCountersAsDeltas configures the OpenTelemetry sink to report\ncounters as delta temporality instead of cumulative.",
+ "type": "boolean"
+ },
+ "reportHistogramsAsDeltas": {
+ "description": "ReportHistogramsAsDeltas configures the OpenTelemetry sink to report\nhistograms as delta temporality instead of cumulative.\nRequired for backends like Elastic that drop cumulative histograms.",
+ "type": "boolean"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes is a set of labels that describe the source of metrics.\nIt's recommended to follow semantic conventions: https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "host or backendRefs needs to be set",
+ "rule": "has(self.host) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "OpenTelemetry",
+ "description": "Type defines the metric sink type.\nEG currently only supports OpenTelemetry.",
+ "enum": [
+ "OpenTelemetry"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If MetricSink type is OpenTelemetry, openTelemetry field needs to be set.",
+ "rule": "self.type == 'OpenTelemetry' ? has(self.openTelemetry) : !has(self.openTelemetry)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestID": {
+ "description": "RequestID configures Envoy request ID behavior.",
+ "properties": {
+ "tracing": {
+ "description": "Tracing configures Envoy's behavior for the UUID request ID extension,\nincluding whether the trace sampling decision is packed into the UUID and\nwhether `X-Request-ID` is used for trace sampling decisions.\n\nWhen omitted, the default behavior is `PackAndSample`, which alters the UUID\nto contain the trace sampling decision and uses `X-Request-ID` for stable\ntrace sampling.",
+ "enum": [
+ "PackAndSample",
+ "Sample",
+ "Pack",
+ "Disable"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tracing": {
+ "description": "Tracing defines tracing configuration for managed proxies.\nIf unspecified, will not send tracing data.",
+ "properties": {
+ "customTags": {
+ "additionalProperties": {
+ "properties": {
+ "environment": {
+ "description": "Environment adds value from environment variable to each span.\nIt's required when the type is \"Environment\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the environment variable is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the environment variable which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "literal": {
+ "description": "Literal adds hard-coded value to each span.\nIt's required when the type is \"Literal\".",
+ "properties": {
+ "value": {
+ "description": "Value defines the hard-coded value to add to each span.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestHeader": {
+ "description": "RequestHeader adds value from request header to each span.\nIt's required when the type is \"RequestHeader\".",
+ "properties": {
+ "defaultValue": {
+ "description": "DefaultValue defines the default value to use if the request header is not set.",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name defines the name of the request header which to extract the value from.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "Literal",
+ "description": "Type defines the type of custom tag.",
+ "enum": [
+ "Literal",
+ "Environment",
+ "RequestHeader"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "description": "CustomTags defines the custom tags to add to each span.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nDeprecated: Use Tags instead.",
+ "type": "object"
+ },
+ "provider": {
+ "description": "Provider defines the tracing provider.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "host": {
+ "description": "Host define the provider service hostname.\n\nDeprecated: Use BackendRefs instead.",
+ "type": "string"
+ },
+ "openTelemetry": {
+ "description": "OpenTelemetry defines the OpenTelemetry tracing provider configuration",
+ "properties": {
+ "headers": {
+ "description": "Headers is a list of additional headers to send with OTLP export requests.\nThese headers are added as gRPC initial metadata for the OTLP gRPC service.",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "minItems": 1,
+ "type": "array"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes is a set of labels that describe the source of traces.\nIt's recommended to follow semantic conventions: https://opentelemetry.io/docs/reference/specification/resource/semantic_conventions/",
+ "type": "object"
+ },
+ "sampler": {
+ "description": "Sampler controls whether spans are exported.",
+ "properties": {
+ "samplingPercentage": {
+ "description": "SamplingPercentage controls the percentage of traces to sample.\nDefaults to 100% when not set.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": {
+ "default": "AlwaysOn",
+ "description": "Type is the sampler type.",
+ "enum": [
+ "AlwaysOn",
+ "AlwaysOff",
+ "TraceIdRatio",
+ "ParentBasedAlwaysOn",
+ "ParentBasedAlwaysOff",
+ "ParentBasedTraceIdRatio"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "samplingPercentage can only be set with TraceIdRatio or ParentBasedTraceIdRatio",
+ "rule": "has(self.samplingPercentage) ? (self.type == 'TraceIdRatio' || self.type == 'ParentBasedTraceIdRatio') : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "port": {
+ "default": 4317,
+ "description": "Port defines the port the provider service is exposed on.\n\nDeprecated: Use BackendRefs instead.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "serviceName": {
+ "description": "ServiceName defines the service name to use in tracing configuration.\nIf not set, Envoy Gateway will use a default service name set as\n\"name.namespace\" (e.g., \"my-gateway.default\").\nNote: This field is only supported for OpenTelemetry and Datadog tracing providers.\nFor Zipkin, the service name in traces is always derived from the Envoy --service-cluster flag\n(typically \"namespace/name\" format). Setting this field has no effect for Zipkin.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "serviceName cannot be empty if provided",
+ "rule": "self != \"\""
+ }
+ ]
+ },
+ "type": {
+ "default": "OpenTelemetry",
+ "description": "Type defines the tracing provider type.",
+ "enum": [
+ "OpenTelemetry",
+ "Zipkin",
+ "Datadog"
+ ],
+ "type": "string"
+ },
+ "zipkin": {
+ "description": "Zipkin defines the Zipkin tracing provider configuration",
+ "properties": {
+ "disableSharedSpanContext": {
+ "description": "DisableSharedSpanContext determines whether the default Envoy behaviour of\nclient and server spans sharing the same span context should be disabled.",
+ "type": "boolean"
+ },
+ "enable128BitTraceId": {
+ "description": "Enable128BitTraceID determines whether a 128bit trace id will be used\nwhen creating a new trace instance. If set to false, a 64bit trace\nid will be used.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "host or backendRefs needs to be set",
+ "rule": "has(self.host) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "BackendRefs only support Service and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only support Core and gateway.envoyproxy.io group.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "openTelemetry can only be used with type OpenTelemetry",
+ "rule": "has(self.openTelemetry) ? self.type == 'OpenTelemetry' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "samplingFraction": {
+ "description": "SamplingFraction represents the fraction of requests that should be\nselected for tracing if no prior sampling decision has been made.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "samplingRate": {
+ "description": "SamplingRate controls the rate at which traffic will be\nselected for tracing if no prior sampling decision has been made.\nDefaults to 100, valid values [0-100]. 100 indicates 100% sampling.\n\nOnly one of SamplingRate or SamplingFraction may be specified.\nIf neither field is specified, all requests will be sampled.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "spanName": {
+ "description": "SpanName defines the name of the span which will be used for tracing.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\n\nIf not set, the span name is provider specific.\ne.g. Datadog use `ingress` as the default client span name,\nand `router egress` as the server span name.",
+ "properties": {
+ "client": {
+ "description": "Client defines operation name of the span which will be used for tracing.",
+ "type": "string"
+ },
+ "server": {
+ "description": "Server defines the operation name of the upstream span which will be used for tracing.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "client",
+ "server"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tags": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Tags defines the custom tags to add to each span.\nEnvoy [command operators](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators) may be used in the value.\nThe [format string documentation](https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#config-access-log-format-strings) provides more information.\nIf provider is kubernetes, pod name and namespace are added by default.\n\nSame keys take precedence over CustomTags.",
+ "type": "object"
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of SamplingRate or SamplingFraction can be specified",
+ "rule": "!(has(self.samplingRate) && has(self.samplingFraction))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "EnvoyProxyStatus defines the actual state of EnvoyProxy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors represent the status information for all the GatewayClass or Gateway\nreference this EnvoyProxy with ParametersReference.",
+ "items": {
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds a GatewayClass or Gateway use this EnvoyProxy with ParametersReference.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "ancestorRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/fluxinstance-stable-v1.json b/crdSchemas/master-standalone/fluxinstance-stable-v1.json
index 2d8a094..939e9e5 100644
--- a/crdSchemas/master-standalone/fluxinstance-stable-v1.json
+++ b/crdSchemas/master-standalone/fluxinstance-stable-v1.json
@@ -247,7 +247,7 @@
"type": "array"
},
"storage": {
- "description": "Storage defines if the source-controller shards\nshould use an emptyDir or a persistent volume claim for storage.\nAccepted values are 'ephemeral' or 'persistent', defaults to 'ephemeral'.\nFor 'persistent' to take effect, the '.spec.storage' field must be set.",
+ "description": "Storage defines if the source-controller shards\nshould use an emptyDir or a persistent volume claim for storage.\nAccepted values are 'ephemeral' or 'persistent', defaults to 'ephemeral'.\nWhen set to 'persistent', the '.spec.storage' field must be set.",
"enum": [
"ephemeral",
"persistent"
@@ -314,7 +314,7 @@
"type": "string"
},
"provider": {
- "description": "Provider specifies OIDC provider for source authentication.\nFor OCIRepository and Bucket the provider can be set to 'aws', 'azure' or 'gcp'.\nfor GitRepository the accepted value can be set to 'azure' or 'github'.\nTo disable OIDC authentication the provider can be set to 'generic' or left empty.",
+ "description": "Provider specifies OIDC provider for source authentication.\nFor OCIRepository and Bucket the provider can be set to 'aws', 'azure' or 'gcp'.\nFor GitRepository the provider can be set to 'aws' (requires Flux 2.9 or later),\n'azure' or 'github'.\nTo disable OIDC authentication the provider can be set to 'generic' or left empty.",
"enum": [
"generic",
"aws",
@@ -344,6 +344,16 @@
"url"
],
"type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "sync.provider 'gcp' is only supported for OCIRepository and Bucket",
+ "rule": "!has(self.provider) || self.provider != 'gcp' || self.kind == 'OCIRepository' || self.kind == 'Bucket'"
+ },
+ {
+ "message": "sync.provider 'github' is only supported for GitRepository",
+ "rule": "!has(self.provider) || self.provider != 'github' || self.kind == 'GitRepository'"
+ }
+ ],
"additionalProperties": false
},
"wait": {
@@ -356,6 +366,12 @@
"distribution"
],
"type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": ".spec.storage must be set when .spec.sharding.storage is 'persistent'",
+ "rule": "!has(self.sharding) || !has(self.sharding.storage) || self.sharding.storage != 'persistent' || has(self.storage)"
+ }
+ ],
"additionalProperties": false
},
"status": {
diff --git a/crdSchemas/master-standalone/gateway-stable-v1.json b/crdSchemas/master-standalone/gateway-stable-v1.json
index 7ed11b5..0722a8f 100644
--- a/crdSchemas/master-standalone/gateway-stable-v1.json
+++ b/crdSchemas/master-standalone/gateway-stable-v1.json
@@ -89,6 +89,89 @@
}
]
},
+ "allowedListeners": {
+ "description": "AllowedListeners defines which ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "namespaces": {
+ "default": {
+ "from": "None"
+ },
+ "description": "Namespaces defines which namespaces ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "from": {
+ "default": "None",
+ "description": "From indicates where ListenerSets can attach to this Gateway. Possible\nvalues are:\n\n* Same: Only ListenerSets in the same namespace may be attached to this Gateway.\n* Selector: ListenerSets in namespaces selected by the selector may be attached to this Gateway.\n* All: ListenerSets in all namespaces may be attached to this Gateway.\n* None: Only listeners defined in the Gateway's spec are allowed\n\nThe default value None",
+ "enum": [
+ "All",
+ "Selector",
+ "Same",
+ "None"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector must be specified when From is set to \"Selector\". In that case,\nonly ListenerSets in Namespaces matching this Selector will be selected by this\nGateway. This field is ignored for other values of \"From\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "defaultScope": {
+ "description": "DefaultScope, when set, configures the Gateway as a default Gateway,\nmeaning it will dynamically and implicitly have Routes (e.g. HTTPRoute)\nattached to it, according to the scope configured here.\n\nIf unset (the default) or set to None, the Gateway will not act as a\ndefault Gateway; if set, the Gateway will claim any Route with a\nmatching scope set in its UseDefaultGateway field, subject to the usual\nrules about which routes the Gateway can attach to.\n\nThink carefully before using this functionality! While the normal rules\nabout which Route can apply are still enforced, it is simply easier for\nthe wrong Route to be accidentally attached to this Gateway in this\nconfiguration. If the Gateway operator is not also the operator in\ncontrol of the scope (e.g. namespace) with tight controls and checks on\nwhat kind of workloads and Routes get added in that scope, we strongly\nrecommend not using this just because it seems convenient, and instead\nstick to direct Route attachment.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ },
"gatewayClassName": {
"description": "GatewayClassName used for this Gateway. This is the name of a\nGatewayClass resource.",
"maxLength": 253,
@@ -291,7 +374,7 @@
"additionalProperties": false
},
"hostname": {
- "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
+ "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host, the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
"maxLength": 253,
"minLength": 1,
"pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
@@ -420,6 +503,10 @@
"message": "tls mode must be Terminate for protocol HTTPS",
"rule": "self.all(l, (l.protocol == 'HTTPS' && has(l.tls)) ? (l.tls.mode == '' || l.tls.mode == 'Terminate') : true)"
},
+ {
+ "message": "tls mode must be set for protocol TLS",
+ "rule": "self.all(l, (l.protocol == 'TLS' ? has(l.tls) && has(l.tls.mode) && l.tls.mode != '' : true))"
+ },
{
"message": "hostname must not be specified for protocols ['TCP', 'UDP']",
"rule": "self.all(l, l.protocol in ['TCP', 'UDP'] ? (!has(l.hostname) || l.hostname == '') : true)"
@@ -433,6 +520,242 @@
"rule": "self.all(l1, self.exists_one(l2, l1.port == l2.port && l1.protocol == l2.protocol && (has(l1.hostname) && has(l2.hostname) ? l1.hostname == l2.hostname : !has(l1.hostname) && !has(l2.hostname))))"
}
]
+ },
+ "tls": {
+ "description": "TLS specifies frontend and backend tls configuration for entire gateway.\n\nSupport: Extended",
+ "properties": {
+ "backend": {
+ "description": "Backend describes TLS configuration for gateway when connecting\nto backends.\n\nNote that this contains only details for the Gateway as a TLS client,\nand does _not_ imply behavior about how to choose which backend should\nget a TLS connection. That is determined by the presence of a BackendTLSPolicy.\n\nSupport: Core",
+ "properties": {
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef references an object that contains a client certificate\nand its associated private key. It can reference standard Kubernetes resources,\ni.e., Secret, or implementation-specific custom resources.\n\nA ClientCertificateRef is considered invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the referenced resource\n does not exist) or is misconfigured (e.g., a Secret does not contain the keys\n named `tls.crt` and `tls.key`). In this case, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `InvalidClientCertificateRef`\n and the Message of the Condition MUST indicate why the reference is invalid.\n\n* It refers to a resource in another namespace UNLESS there is a ReferenceGrant\n in the target namespace that allows the certificate to be attached.\n If a ReferenceGrant does not allow this reference, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the certificate\ncontent (e.g., checking expiry or enforcing specific formats). In such cases,\nan implementation-specific Reason and Message MUST be set.\n\nSupport: Core - Reference to a Kubernetes TLS Secret (with the type `kubernetes.io/tls`).\nSupport: Implementation-specific - Other resource kinds or Secrets with a\ndifferent type (e.g., `Opaque`).",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "frontend": {
+ "description": "Frontend describes TLS config when client connects to Gateway.\nSupport: Core",
+ "properties": {
+ "default": {
+ "description": "Default specifies the default client certificate validation configuration\nfor all Listeners handling HTTPS traffic, unless a per-port configuration\nis defined.\n\nsupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "perPort": {
+ "description": "PerPort specifies tls configuration assigned per port.\nPer port configuration is optional. Once set this configuration overrides\nthe default configuration for all Listeners handling HTTPS traffic\nthat match this port.\nEach override port requires a unique TLS configuration.\n\nsupport: Core",
+ "items": {
+ "properties": {
+ "port": {
+ "description": "The Port indicates the Port Number to which the TLS configuration will be\napplied. This configuration will be applied to all Listeners handling HTTPS\ntraffic that match this port.\n\nSupport: Core",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS store the configuration that will be applied to all Listeners handling\nHTTPS traffic and matching given port.\n\nSupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "port",
+ "tls"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "port"
+ ],
+ "x-kubernetes-list-type": "map",
+ "x-kubernetes-validations": [
+ {
+ "message": "Port for TLS configuration must be unique within the Gateway",
+ "rule": "self.all(t1, self.exists_one(t2, t1.port == t2.port))"
+ }
+ ]
+ }
+ },
+ "required": [
+ "default"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
}
},
"required": [
@@ -531,6 +854,11 @@
"type": "array",
"x-kubernetes-list-type": "atomic"
},
+ "attachedListenerSets": {
+ "description": "AttachedListenerSets represents the total number of ListenerSets that have been\nsuccessfully attached to this Gateway.\n\nA ListenerSet is successfully attached to a Gateway when all the following conditions are met:\n- The ListenerSet is selected by the Gateway's AllowedListeners field\n- The ListenerSet has a valid ParentRef selecting the Gateway\n- The ListenerSet's status has the condition \"Accepted: true\"\n\nUses for this field include troubleshooting AttachedListenerSets attachment and\nmeasuring blast radius/impact of changes to a Gateway.",
+ "format": "int32",
+ "type": "integer"
+ },
"conditions": {
"default": [
{
@@ -614,7 +942,7 @@
"description": "ListenerStatus is the status associated with a Listener.",
"properties": {
"attachedRoutes": {
- "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners with condition Accepted: false and MUST count successfully\nattached Routes that may themselves have Accepted: false conditions.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
+ "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners, even if the Accepted condition of an individual Listener is set\nto \"False\". The AttachedRoutes number represents the number of Routes with\nthe Accepted condition set to \"True\" that have been attached to this Listener.\nRoutes with any other value for the Accepted condition MUST NOT be included\nin this count.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
"format": "int32",
"type": "integer"
},
@@ -687,7 +1015,7 @@
"type": "string"
},
"supportedKinds": {
- "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds an implementation supports for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
+ "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds supported by an implementation for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
"items": {
"description": "RouteGroupKind indicates the group and kind of a Route resource.",
"properties": {
@@ -720,8 +1048,7 @@
"required": [
"attachedRoutes",
"conditions",
- "name",
- "supportedKinds"
+ "name"
],
"type": "object",
"additionalProperties": false
diff --git a/crdSchemas/master-standalone/gateway-stable-v1beta1.json b/crdSchemas/master-standalone/gateway-stable-v1beta1.json
index 7ed11b5..0722a8f 100644
--- a/crdSchemas/master-standalone/gateway-stable-v1beta1.json
+++ b/crdSchemas/master-standalone/gateway-stable-v1beta1.json
@@ -89,6 +89,89 @@
}
]
},
+ "allowedListeners": {
+ "description": "AllowedListeners defines which ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "namespaces": {
+ "default": {
+ "from": "None"
+ },
+ "description": "Namespaces defines which namespaces ListenerSets can be attached to this Gateway.\nThe default value is to allow no ListenerSets.",
+ "properties": {
+ "from": {
+ "default": "None",
+ "description": "From indicates where ListenerSets can attach to this Gateway. Possible\nvalues are:\n\n* Same: Only ListenerSets in the same namespace may be attached to this Gateway.\n* Selector: ListenerSets in namespaces selected by the selector may be attached to this Gateway.\n* All: ListenerSets in all namespaces may be attached to this Gateway.\n* None: Only listeners defined in the Gateway's spec are allowed\n\nThe default value None",
+ "enum": [
+ "All",
+ "Selector",
+ "Same",
+ "None"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector must be specified when From is set to \"Selector\". In that case,\nonly ListenerSets in Namespaces matching this Selector will be selected by this\nGateway. This field is ignored for other values of \"From\".",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "defaultScope": {
+ "description": "DefaultScope, when set, configures the Gateway as a default Gateway,\nmeaning it will dynamically and implicitly have Routes (e.g. HTTPRoute)\nattached to it, according to the scope configured here.\n\nIf unset (the default) or set to None, the Gateway will not act as a\ndefault Gateway; if set, the Gateway will claim any Route with a\nmatching scope set in its UseDefaultGateway field, subject to the usual\nrules about which routes the Gateway can attach to.\n\nThink carefully before using this functionality! While the normal rules\nabout which Route can apply are still enforced, it is simply easier for\nthe wrong Route to be accidentally attached to this Gateway in this\nconfiguration. If the Gateway operator is not also the operator in\ncontrol of the scope (e.g. namespace) with tight controls and checks on\nwhat kind of workloads and Routes get added in that scope, we strongly\nrecommend not using this just because it seems convenient, and instead\nstick to direct Route attachment.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ },
"gatewayClassName": {
"description": "GatewayClassName used for this Gateway. This is the name of a\nGatewayClass resource.",
"maxLength": 253,
@@ -291,7 +374,7 @@
"additionalProperties": false
},
"hostname": {
- "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
+ "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match both the SNI and Host header.\n Note that this does not require the SNI and Host header to be the same.\n The semantics of this are described in more detail below.\n\nTo ensure security, Section 11.1 of RFC-6066 emphasizes that server\nimplementations that rely on SNI hostname matching MUST also verify\nhostnames within the application protocol.\n\nSection 9.1.2 of RFC-7540 provides a mechanism for servers to reject the\nreuse of a connection by responding with the HTTP 421 Misdirected Request\nstatus code. This indicates that the origin server has rejected the\nrequest because it appears to have been misdirected.\n\nTo detect misdirected requests, Gateways SHOULD match the authority of\nthe requests with all the SNI hostname(s) configured across all the\nGateway Listeners on the same port and protocol:\n\n* If another Listener has an exact match or more specific wildcard entry,\n the Gateway SHOULD return a 421.\n* If the current Listener (selected by SNI matching during ClientHello)\n does not match the Host:\n * If another Listener does match the Host, the Gateway SHOULD return a\n 421.\n * If no other Listener matches the Host, the Gateway MUST return a\n 404.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.\n\nSupport: Core",
"maxLength": 253,
"minLength": 1,
"pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
@@ -420,6 +503,10 @@
"message": "tls mode must be Terminate for protocol HTTPS",
"rule": "self.all(l, (l.protocol == 'HTTPS' && has(l.tls)) ? (l.tls.mode == '' || l.tls.mode == 'Terminate') : true)"
},
+ {
+ "message": "tls mode must be set for protocol TLS",
+ "rule": "self.all(l, (l.protocol == 'TLS' ? has(l.tls) && has(l.tls.mode) && l.tls.mode != '' : true))"
+ },
{
"message": "hostname must not be specified for protocols ['TCP', 'UDP']",
"rule": "self.all(l, l.protocol in ['TCP', 'UDP'] ? (!has(l.hostname) || l.hostname == '') : true)"
@@ -433,6 +520,242 @@
"rule": "self.all(l1, self.exists_one(l2, l1.port == l2.port && l1.protocol == l2.protocol && (has(l1.hostname) && has(l2.hostname) ? l1.hostname == l2.hostname : !has(l1.hostname) && !has(l2.hostname))))"
}
]
+ },
+ "tls": {
+ "description": "TLS specifies frontend and backend tls configuration for entire gateway.\n\nSupport: Extended",
+ "properties": {
+ "backend": {
+ "description": "Backend describes TLS configuration for gateway when connecting\nto backends.\n\nNote that this contains only details for the Gateway as a TLS client,\nand does _not_ imply behavior about how to choose which backend should\nget a TLS connection. That is determined by the presence of a BackendTLSPolicy.\n\nSupport: Core",
+ "properties": {
+ "clientCertificateRef": {
+ "description": "ClientCertificateRef references an object that contains a client certificate\nand its associated private key. It can reference standard Kubernetes resources,\ni.e., Secret, or implementation-specific custom resources.\n\nA ClientCertificateRef is considered invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the referenced resource\n does not exist) or is misconfigured (e.g., a Secret does not contain the keys\n named `tls.crt` and `tls.key`). In this case, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `InvalidClientCertificateRef`\n and the Message of the Condition MUST indicate why the reference is invalid.\n\n* It refers to a resource in another namespace UNLESS there is a ReferenceGrant\n in the target namespace that allows the certificate to be attached.\n If a ReferenceGrant does not allow this reference, the `ResolvedRefs` condition\n on the Gateway MUST be set to False with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the certificate\ncontent (e.g., checking expiry or enforcing specific formats). In such cases,\nan implementation-specific Reason and Message MUST be set.\n\nSupport: Core - Reference to a Kubernetes TLS Secret (with the type `kubernetes.io/tls`).\nSupport: Implementation-specific - Other resource kinds or Secrets with a\ndifferent type (e.g., `Opaque`).",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "frontend": {
+ "description": "Frontend describes TLS config when client connects to Gateway.\nSupport: Core",
+ "properties": {
+ "default": {
+ "description": "Default specifies the default client certificate validation configuration\nfor all Listeners handling HTTPS traffic, unless a per-port configuration\nis defined.\n\nsupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "perPort": {
+ "description": "PerPort specifies tls configuration assigned per port.\nPer port configuration is optional. Once set this configuration overrides\nthe default configuration for all Listeners handling HTTPS traffic\nthat match this port.\nEach override port requires a unique TLS configuration.\n\nsupport: Core",
+ "items": {
+ "properties": {
+ "port": {
+ "description": "The Port indicates the Port Number to which the TLS configuration will be\napplied. This configuration will be applied to all Listeners handling HTTPS\ntraffic that match this port.\n\nSupport: Core",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "tls": {
+ "description": "TLS store the configuration that will be applied to all Listeners handling\nHTTPS traffic and matching given port.\n\nSupport: Core",
+ "properties": {
+ "validation": {
+ "description": "Validation holds configuration information for validating the frontend (client).\nSetting this field will result in mutual authentication when connecting to the gateway.\nIn browsers this may result in a dialog appearing\nthat requests a user to specify the client certificate.\nThe maximum depth of a certificate chain accepted in verification is Implementation specific.\n\nSupport: Core",
+ "properties": {
+ "caCertificateRefs": {
+ "description": "CACertificateRefs contains one or more references to Kubernetes\nobjects that contain a PEM-encoded TLS CA certificate bundle, which\nis used as a trust anchor to validate the certificates presented by\nthe client.\n\nA CACertificateRef is invalid if:\n\n* It refers to a resource that cannot be resolved (e.g., the\n referenced resource does not exist) or is misconfigured (e.g., a\n ConfigMap does not contain a key named `ca.crt`). In this case, the\n Reason on all matching HTTPS listeners must be set to `InvalidCACertificateRef`\n and the Message of the Condition must indicate which reference is invalid and why.\n\n* It refers to an unknown or unsupported kind of resource. In this\n case, the Reason on all matching HTTPS listeners must be set to\n `InvalidCACertificateKind` and the Message of the Condition must explain\n which kind of resource is unknown or unsupported.\n\n* It refers to a resource in another namespace UNLESS there is a\n ReferenceGrant in the target namespace that allows the CA\n certificate to be attached. If a ReferenceGrant does not allow this\n reference, the `ResolvedRefs` on all matching HTTPS listeners condition\n MUST be set with the Reason `RefNotPermitted`.\n\nImplementations MAY choose to perform further validation of the\ncertificate content (e.g., checking expiry or enforcing specific formats).\nIn such cases, an implementation-specific Reason and Message MUST be set.\n\nIn all cases, the implementation MUST ensure that the `ResolvedRefs`\ncondition is set to `status: False` on all targeted listeners (i.e.,\nlisteners serving HTTPS on a matching port). The condition MUST\ninclude a Reason and Message that indicate the cause of the error. If\nALL CACertificateRefs are invalid, the implementation MUST also ensure\nthe `Accepted` condition on the listener is set to `status: False`, with\nthe Reason `NoValidCACertificate`.\nImplementations MAY choose to support attaching multiple CA certificates\nto a listener, but this behavior is implementation-specific.\n\nSupport: Core - A single reference to a Kubernetes ConfigMap, with the\nCA certificate in a key named `ca.crt`.\n\nSupport: Implementation-specific - More than one reference, other kinds\nof resources, or a single reference that includes multiple certificates.",
+ "items": {
+ "description": "ObjectReference identifies an API object including its namespace.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen set to the empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"ConfigMap\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "AllowValidOnly",
+ "description": "FrontendValidationMode defines the mode for validating the client certificate.\nThere are two possible modes:\n\n- AllowValidOnly: In this mode, the gateway will accept connections only if\n the client presents a valid certificate. This certificate must successfully\n pass validation against the CA certificates specified in `CACertificateRefs`.\n- AllowInsecureFallback: In this mode, the gateway will accept connections\n even if the client certificate is not presented or fails verification.\n\n This approach delegates client authorization to the backend and introduce\n a significant security risk. It should be used in testing environments or\n on a temporary basis in non-testing environments.\n\nDefaults to AllowValidOnly.\n\nSupport: Core",
+ "enum": [
+ "AllowValidOnly",
+ "AllowInsecureFallback"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "caCertificateRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "port",
+ "tls"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "port"
+ ],
+ "x-kubernetes-list-type": "map",
+ "x-kubernetes-validations": [
+ {
+ "message": "Port for TLS configuration must be unique within the Gateway",
+ "rule": "self.all(t1, self.exists_one(t2, t1.port == t2.port))"
+ }
+ ]
+ }
+ },
+ "required": [
+ "default"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
}
},
"required": [
@@ -531,6 +854,11 @@
"type": "array",
"x-kubernetes-list-type": "atomic"
},
+ "attachedListenerSets": {
+ "description": "AttachedListenerSets represents the total number of ListenerSets that have been\nsuccessfully attached to this Gateway.\n\nA ListenerSet is successfully attached to a Gateway when all the following conditions are met:\n- The ListenerSet is selected by the Gateway's AllowedListeners field\n- The ListenerSet has a valid ParentRef selecting the Gateway\n- The ListenerSet's status has the condition \"Accepted: true\"\n\nUses for this field include troubleshooting AttachedListenerSets attachment and\nmeasuring blast radius/impact of changes to a Gateway.",
+ "format": "int32",
+ "type": "integer"
+ },
"conditions": {
"default": [
{
@@ -614,7 +942,7 @@
"description": "ListenerStatus is the status associated with a Listener.",
"properties": {
"attachedRoutes": {
- "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners with condition Accepted: false and MUST count successfully\nattached Routes that may themselves have Accepted: false conditions.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
+ "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener or Route status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners, even if the Accepted condition of an individual Listener is set\nto \"False\". The AttachedRoutes number represents the number of Routes with\nthe Accepted condition set to \"True\" that have been attached to this Listener.\nRoutes with any other value for the Accepted condition MUST NOT be included\nin this count.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
"format": "int32",
"type": "integer"
},
@@ -687,7 +1015,7 @@
"type": "string"
},
"supportedKinds": {
- "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds an implementation supports for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
+ "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds supported by an implementation for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
"items": {
"description": "RouteGroupKind indicates the group and kind of a Route resource.",
"properties": {
@@ -720,8 +1048,7 @@
"required": [
"attachedRoutes",
"conditions",
- "name",
- "supportedKinds"
+ "name"
],
"type": "object",
"additionalProperties": false
diff --git a/crdSchemas/master-standalone/grpcroute-stable-v1.json b/crdSchemas/master-standalone/grpcroute-stable-v1.json
index 8f24a6b..57ea300 100644
--- a/crdSchemas/master-standalone/grpcroute-stable-v1.json
+++ b/crdSchemas/master-standalone/grpcroute-stable-v1.json
@@ -29,7 +29,7 @@
"x-kubernetes-list-type": "atomic"
},
"parentRefs": {
- "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.",
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
"items": {
"description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
"properties": {
@@ -55,14 +55,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
@@ -87,12 +87,12 @@
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
- "message": "sectionName must be specified when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))"
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
},
{
- "message": "sectionName must be unique when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))"
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
}
]
},
@@ -104,7 +104,7 @@
"backendRefs": {
"description": "BackendRefs defines the backend(s) where matching requests should be\nsent.\n\nFailure behavior here depends on how many BackendRefs are specified and\nhow many are invalid.\n\nIf *all* entries in BackendRefs are invalid, and there are also no filters\nspecified in this route rule, *all* traffic which matches this rule MUST\nreceive an `UNAVAILABLE` status.\n\nSee the GRPCBackendRef definition for the rules about what makes a single\nGRPCBackendRef invalid.\n\nWhen a GRPCBackendRef is invalid, `UNAVAILABLE` statuses MUST be returned for\nrequests that would have otherwise been routed to an invalid backend. If\nmultiple backends are specified, and some are invalid, the proportion of\nrequests that would otherwise have been routed to an invalid backend\nMUST receive an `UNAVAILABLE` status.\n\nFor example, if two backends are specified with equal weights, and one is\ninvalid, 50 percent of traffic MUST receive an `UNAVAILABLE` status.\nImplementations may choose how that 50 percent is determined.\n\nSupport: Core for Kubernetes Service\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Core",
"items": {
- "description": "GRPCBackendRef defines how a GRPCRoute forwards a gRPC request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.",
+ "description": "GRPCBackendRef defines how a GRPCRoute forwards a gRPC request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.",
"properties": {
"filters": {
"description": "Filters defined at this level MUST be executed if and only if the\nrequest is being forwarded to the backend defined here.\n\nSupport: Implementation-specific (For broader support of filters, use the\nFilters field in GRPCRouteRule.)",
@@ -158,9 +158,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -200,9 +201,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -341,9 +343,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -383,9 +386,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -584,9 +588,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -626,9 +631,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -767,9 +773,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -809,9 +816,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -901,7 +909,7 @@
"matches": {
"description": "Matches define conditions used for matching the rule against incoming\ngRPC requests. Each match is independent, i.e. this rule will be matched\nif **any** one of the matches is satisfied.\n\nFor example, take the following matches configuration:\n\n```\nmatches:\n- method:\n service: foo.bar\n headers:\n values:\n version: 2\n- method:\n service: foo.bar.v2\n```\n\nFor a request to match against this rule, it MUST satisfy\nEITHER of the two conditions:\n\n- service of foo.bar AND contains the header `version: 2`\n- service of foo.bar.v2\n\nSee the documentation for GRPCRouteMatch on how to specify multiple\nmatch conditions to be ANDed together.\n\nIf no matches are specified, the implementation MUST match every gRPC request.\n\nProxy or Load Balancer routing configuration generated from GRPCRoutes\nMUST prioritize rules based on the following criteria, continuing on\nties. Merging MUST not be done between GRPCRoutes and HTTPRoutes.\nPrecedence MUST be given to the rule with the largest number of:\n\n* Characters in a matching non-wildcard hostname.\n* Characters in a matching hostname.\n* Characters in a matching service.\n* Characters in a matching method.\n* Header matches.\n\nIf ties still exist across multiple Routes, matching precedence MUST be\ndetermined in order of the following criteria, continuing on ties:\n\n* The oldest Route based on creation timestamp.\n* The Route appearing first in alphabetical order by\n \"{namespace}/{name}\".\n\nIf ties still exist within the Route that has been given precedence,\nmatching precedence MUST be granted to the first matching rule meeting\nthe above criteria.",
"items": {
- "description": "GRPCRouteMatch defines the predicate used to match requests to a given\naction. Multiple match types are ANDed together, i.e. the match will\nevaluate to true only if all conditions are satisfied.\n\nFor example, the match below will match a gRPC request only if its service\nis `foo` AND it contains the `version: v1` header:\n\n```\nmatches:\n - method:\n type: Exact\n service: \"foo\"\n headers:\n - name: \"version\"\n value \"v1\"\n\n```",
+ "description": "GRPCRouteMatch defines the predicate used to match requests to a given\naction. Multiple match types are ANDed together, i.e. the match will\nevaluate to true only if all conditions are satisfied.\n\nFor example, the match below will match a gRPC request only if its service\nis `foo` AND it contains the `version: v1` header:\n\n```\nmatches:\n - method:\n type: Exact\n service: \"foo\"\n - headers:\n name: \"version\"\n value \"v1\"\n\n```",
"properties": {
"headers": {
"description": "Headers specifies gRPC request header matchers. Multiple match values are\nANDed together, meaning, a request MUST match all the specified headers\nto select the route.",
@@ -999,6 +1007,63 @@
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
"type": "string"
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the route rule.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
}
},
"type": "object",
@@ -1011,8 +1076,20 @@
{
"message": "While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",
"rule": "(self.size() > 0 ? (has(self[0].matches) ? self[0].matches.size() : 0) : 0) + (self.size() > 1 ? (has(self[1].matches) ? self[1].matches.size() : 0) : 0) + (self.size() > 2 ? (has(self[2].matches) ? self[2].matches.size() : 0) : 0) + (self.size() > 3 ? (has(self[3].matches) ? self[3].matches.size() : 0) : 0) + (self.size() > 4 ? (has(self[4].matches) ? self[4].matches.size() : 0) : 0) + (self.size() > 5 ? (has(self[5].matches) ? self[5].matches.size() : 0) : 0) + (self.size() > 6 ? (has(self[6].matches) ? self[6].matches.size() : 0) : 0) + (self.size() > 7 ? (has(self[7].matches) ? self[7].matches.size() : 0) : 0) + (self.size() > 8 ? (has(self[8].matches) ? self[8].matches.size() : 0) : 0) + (self.size() > 9 ? (has(self[9].matches) ? self[9].matches.size() : 0) : 0) + (self.size() > 10 ? (has(self[10].matches) ? self[10].matches.size() : 0) : 0) + (self.size() > 11 ? (has(self[11].matches) ? self[11].matches.size() : 0) : 0) + (self.size() > 12 ? (has(self[12].matches) ? self[12].matches.size() : 0) : 0) + (self.size() > 13 ? (has(self[13].matches) ? self[13].matches.size() : 0) : 0) + (self.size() > 14 ? (has(self[14].matches) ? self[14].matches.size() : 0) : 0) + (self.size() > 15 ? (has(self[15].matches) ? self[15].matches.size() : 0) : 0) <= 128"
+ },
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
}
]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
}
},
"type": "object",
@@ -1027,7 +1104,7 @@
"description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
"properties": {
"conditions": {
- "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace the controller does not have access to.",
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
@@ -1120,14 +1197,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/master-standalone/httproute-stable-v1.json b/crdSchemas/master-standalone/httproute-stable-v1.json
index 774f9fa..cb8bca6 100644
--- a/crdSchemas/master-standalone/httproute-stable-v1.json
+++ b/crdSchemas/master-standalone/httproute-stable-v1.json
@@ -29,7 +29,7 @@
"x-kubernetes-list-type": "atomic"
},
"parentRefs": {
- "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.",
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
"items": {
"description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
"properties": {
@@ -55,14 +55,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
@@ -87,12 +87,12 @@
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
- "message": "sectionName must be specified when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))"
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
},
{
- "message": "sectionName must be unique when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))"
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
}
]
},
@@ -116,13 +116,109 @@
"backendRefs": {
"description": "BackendRefs defines the backend(s) where matching requests should be\nsent.\n\nFailure behavior here depends on how many BackendRefs are specified and\nhow many are invalid.\n\nIf *all* entries in BackendRefs are invalid, and there are also no filters\nspecified in this route rule, *all* traffic which matches this rule MUST\nreceive a 500 status code.\n\nSee the HTTPBackendRef definition for the rules about what makes a single\nHTTPBackendRef invalid.\n\nWhen a HTTPBackendRef is invalid, 500 status codes MUST be returned for\nrequests that would have otherwise been routed to an invalid backend. If\nmultiple backends are specified, and some are invalid, the proportion of\nrequests that would otherwise have been routed to an invalid backend\nMUST receive a 500 status code.\n\nFor example, if two backends are specified with equal weights, and one is\ninvalid, 50 percent of traffic must receive a 500. Implementations may\nchoose how that 50 percent is determined.\n\nWhen a HTTPBackendRef refers to a Service that has no ready endpoints,\nimplementations SHOULD return a 503 for requests to that backend instead.\nIf an implementation chooses to do this, all of the above rules for 500 responses\nMUST also apply for responses that return a 503.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Core",
"items": {
- "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.",
+ "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.",
"properties": {
"filters": {
"description": "Filters defined at this level should be executed if and only if the\nrequest is being forwarded to the backend defined here.\n\nSupport: Implementation-specific (For broader support of filters, use the\nFilters field in HTTPRouteRule.)",
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -154,6 +250,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -170,9 +412,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -212,9 +455,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -413,7 +657,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -437,9 +684,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -479,9 +727,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -511,7 +760,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -581,6 +832,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -628,6 +887,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -640,6 +907,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -723,6 +994,102 @@
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -754,6 +1121,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -770,9 +1283,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -812,9 +1326,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1013,7 +1528,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -1037,9 +1555,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1079,9 +1598,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1111,7 +1631,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -1181,6 +1703,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -1228,6 +1758,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -1240,6 +1778,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -1293,9 +1835,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1458,6 +2001,90 @@
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
"type": "string"
},
+ "retry": {
+ "description": "Retry defines the configuration for when to retry an HTTP request.\n\nSupport: Extended",
+ "properties": {
+ "attempts": {
+ "description": "Attempts specifies the maximum number of times an individual request\nfrom the gateway to a backend should be retried.\n\nIf the maximum number of retries has been attempted without a successful\nresponse from the backend, the Gateway MUST return an error.\n\nWhen this field is unspecified, the number of times to attempt to retry\na backend request is implementation-specific.\n\nSupport: Extended",
+ "type": "integer"
+ },
+ "backoff": {
+ "description": "Backoff specifies the minimum duration a Gateway should wait between\nretry attempts and is represented in Gateway API Duration formatting.\n\nFor example, setting the `rules[].retry.backoff` field to the value\n`100ms` will cause a backend request to first be retried approximately\n100 milliseconds after timing out or receiving a response code configured\nto be retriable.\n\nAn implementation MAY use an exponential or alternative backoff strategy\nfor subsequent retry attempts, MAY cap the maximum backoff duration to\nsome amount greater than the specified minimum, and MAY add arbitrary\njitter to stagger requests, as long as unsuccessful backend requests are\nnot retried before the configured minimum duration.\n\nIf a Request timeout (`rules[].timeouts.request`) is configured on the\nroute, the entire duration of the initial request and any retry attempts\nMUST not exceed the Request timeout duration. If any retry attempts are\nstill in progress when the Request timeout duration has been reached,\nthese SHOULD be canceled if possible and the Gateway MUST immediately\nreturn a timeout error.\n\nIf a BackendRequest timeout (`rules[].timeouts.backendRequest`) is\nconfigured on the route, any retry attempts which reach the configured\nBackendRequest timeout duration without a response SHOULD be canceled if\npossible and the Gateway should wait for at least the specified backoff\nduration before attempting to retry the backend request again.\n\nIf a BackendRequest timeout is _not_ configured on the route, retry\nattempts MAY time out after an implementation default duration, or MAY\nremain pending until a configured Request timeout or implementation\ndefault duration for total request time is reached.\n\nWhen this field is unspecified, the time to wait between retry attempts\nis implementation-specific.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "codes": {
+ "description": "Codes defines the HTTP response status codes for which a backend request\nshould be retried.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPRouteRetryStatusCode defines an HTTP response status code for\nwhich a backend request should be retried.\n\nImplementations MUST support the following status codes as retriable:\n\n* 500\n* 502\n* 503\n* 504\n\nImplementations MAY support specifying additional discrete values in the\n500-599 range.\n\nImplementations MAY support specifying discrete values in the 400-499 range,\nwhich are often inadvisable to retry.",
+ "maximum": 599,
+ "minimum": 400,
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the route rule.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
+ },
"timeouts": {
"description": "Timeouts defines the timeouts that can be configured for an HTTP request.\n\nSupport: Extended",
"properties": {
@@ -1508,14 +2135,27 @@
"additionalProperties": false
},
"maxItems": 16,
+ "minItems": 1,
"type": "array",
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
"message": "While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",
"rule": "(self.size() > 0 ? self[0].matches.size() : 0) + (self.size() > 1 ? self[1].matches.size() : 0) + (self.size() > 2 ? self[2].matches.size() : 0) + (self.size() > 3 ? self[3].matches.size() : 0) + (self.size() > 4 ? self[4].matches.size() : 0) + (self.size() > 5 ? self[5].matches.size() : 0) + (self.size() > 6 ? self[6].matches.size() : 0) + (self.size() > 7 ? self[7].matches.size() : 0) + (self.size() > 8 ? self[8].matches.size() : 0) + (self.size() > 9 ? self[9].matches.size() : 0) + (self.size() > 10 ? self[10].matches.size() : 0) + (self.size() > 11 ? self[11].matches.size() : 0) + (self.size() > 12 ? self[12].matches.size() : 0) + (self.size() > 13 ? self[13].matches.size() : 0) + (self.size() > 14 ? self[14].matches.size() : 0) + (self.size() > 15 ? self[15].matches.size() : 0) <= 128"
+ },
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
}
]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
}
},
"type": "object",
@@ -1530,7 +2170,7 @@
"description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
"properties": {
"conditions": {
- "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace the controller does not have access to.",
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
@@ -1623,14 +2263,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/master-standalone/httproute-stable-v1beta1.json b/crdSchemas/master-standalone/httproute-stable-v1beta1.json
index 774f9fa..cb8bca6 100644
--- a/crdSchemas/master-standalone/httproute-stable-v1beta1.json
+++ b/crdSchemas/master-standalone/httproute-stable-v1beta1.json
@@ -29,7 +29,7 @@
"x-kubernetes-list-type": "atomic"
},
"parentRefs": {
- "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.",
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
"items": {
"description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
"properties": {
@@ -55,14 +55,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
@@ -87,12 +87,12 @@
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
- "message": "sectionName must be specified when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))"
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
},
{
- "message": "sectionName must be unique when parentRefs includes 2 or more references to the same parent",
- "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))"
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
}
]
},
@@ -116,13 +116,109 @@
"backendRefs": {
"description": "BackendRefs defines the backend(s) where matching requests should be\nsent.\n\nFailure behavior here depends on how many BackendRefs are specified and\nhow many are invalid.\n\nIf *all* entries in BackendRefs are invalid, and there are also no filters\nspecified in this route rule, *all* traffic which matches this rule MUST\nreceive a 500 status code.\n\nSee the HTTPBackendRef definition for the rules about what makes a single\nHTTPBackendRef invalid.\n\nWhen a HTTPBackendRef is invalid, 500 status codes MUST be returned for\nrequests that would have otherwise been routed to an invalid backend. If\nmultiple backends are specified, and some are invalid, the proportion of\nrequests that would otherwise have been routed to an invalid backend\nMUST receive a 500 status code.\n\nFor example, if two backends are specified with equal weights, and one is\ninvalid, 50 percent of traffic must receive a 500. Implementations may\nchoose how that 50 percent is determined.\n\nWhen a HTTPBackendRef refers to a Service that has no ready endpoints,\nimplementations SHOULD return a 503 for requests to that backend instead.\nIf an implementation chooses to do this, all of the above rules for 500 responses\nMUST also apply for responses that return a 503.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Core",
"items": {
- "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.",
+ "description": "HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.",
"properties": {
"filters": {
"description": "Filters defined at this level should be executed if and only if the\nrequest is being forwarded to the backend defined here.\n\nSupport: Implementation-specific (For broader support of filters, use the\nFilters field in HTTPRouteRule.)",
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -154,6 +250,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -170,9 +412,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -212,9 +455,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -413,7 +657,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -437,9 +684,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -479,9 +727,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -511,7 +760,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -581,6 +832,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -628,6 +887,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -640,6 +907,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -723,6 +994,102 @@
"items": {
"description": "HTTPRouteFilter defines processing steps that must be completed during the\nrequest or response lifecycle. HTTPRouteFilters are meant as an extension\npoint to express processing that may be done in Gateway implementations. Some\nexamples include request or response modification, implementing\nauthentication strategies, rate-limiting, and traffic shaping. API\nguarantee/conformance is defined based on the type of the filter.",
"properties": {
+ "cors": {
+ "description": "CORS defines a schema for a filter that responds to the\ncross-origin request based on HTTP response header.\n\nSupport: Extended",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether the actual cross-origin request allows\nto include credentials.\n\nWhen set to true, the gateway will include the `Access-Control-Allow-Credentials`\nresponse header with value true (case-sensitive).\n\nWhen set to false or omitted the gateway will omit the header\n`Access-Control-Allow-Credentials` entirely (this is the standard CORS\nbehavior).\n\nSupport: Extended",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders indicates which HTTP request headers are supported for\naccessing the requested resource.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Allow-Headers`\nresponse header are separated by a comma (\",\").\n\nWhen the `AllowHeaders` field is configured with one or more headers, the\ngateway must return the `Access-Control-Allow-Headers` response header\nwhich value is present in the `AllowHeaders` field.\n\nIf any header name in the `Access-Control-Request-Headers` request header\nis not included in the list of header names specified by the response\nheader `Access-Control-Allow-Headers`, it will present an error on the\nclient side.\n\nIf any header name in the `Access-Control-Allow-Headers` response header\ndoes not recognize by the client, it will also occur an error on the\nclient side.\n\nA wildcard indicates that the requests with all HTTP headers are allowed.\nIf config contains the wildcard \"*\" in allowHeaders and the request is\nnot credentialed, the `Access-Control-Allow-Headers` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Headers from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Headers` response header. When\nalso the `AllowCredentials` field is true and `AllowHeaders` field\nis specified with the `*` wildcard, the gateway must specify one or more\nHTTP headers in the value of the `Access-Control-Allow-Headers` response\nheader. The value of the header `Access-Control-Allow-Headers` is same as\nthe `Access-Control-Request-Headers` header provided by the client. If\nthe header `Access-Control-Request-Headers` is not included in the\nrequest, the gateway will omit the `Access-Control-Allow-Headers`\nresponse header, instead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowHeaders cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowMethods": {
+ "description": "AllowMethods indicates which HTTP methods are supported for accessing the\nrequested resource.\n\nValid values are any method defined by RFC9110, along with the special\nvalue `*`, which represents all HTTP methods are allowed.\n\nMethod names are case-sensitive, so these values are also case-sensitive.\n(See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)\n\nMultiple method names in the value of the `Access-Control-Allow-Methods`\nresponse header are separated by a comma (\",\").\n\nA CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.\n(See https://fetch.spec.whatwg.org/#cors-safelisted-method) The\nCORS-safelisted methods are always allowed, regardless of whether they\nare specified in the `AllowMethods` field.\n\nWhen the `AllowMethods` field is configured with one or more methods, the\ngateway must return the `Access-Control-Allow-Methods` response header\nwhich value is present in the `AllowMethods` field.\n\nIf the HTTP method of the `Access-Control-Request-Method` request header\nis not included in the list of methods specified by the response header\n`Access-Control-Allow-Methods`, it will present an error on the client\nside.\n\nIf config contains the wildcard \"*\" in allowMethods and the request is\nnot credentialed, the `Access-Control-Allow-Methods` response header\ncan either use the `*` wildcard or the value of\nAccess-Control-Request-Method from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Methods` response header. When\nalso the `AllowCredentials` field is true and `AllowMethods` field\nspecified with the `*` wildcard, the gateway must specify one HTTP method\nin the value of the Access-Control-Allow-Methods response header. The\nvalue of the header `Access-Control-Allow-Methods` is same as the\n`Access-Control-Request-Method` header provided by the client. If the\nheader `Access-Control-Request-Method` is not included in the request,\nthe gateway will omit the `Access-Control-Allow-Methods` response header,\ninstead of specifying the `*` wildcard.\n\nSupport: Extended",
+ "items": {
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH",
+ "*"
+ ],
+ "type": "string"
+ },
+ "maxItems": 9,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowMethods cannot contain '*' alongside other methods",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins indicates whether the response can be shared with requested\nresource from the given `Origin`.\n\nThe `Origin` consists of a scheme and a host, with an optional port, and\ntakes the form `://(:)`.\n\nValid values for scheme are: `http` and `https`.\n\nValid values for port are any integer between 1 and 65535 (the list of\navailable TCP/UDP ports). Note that, if not included, port `80` is\nassumed for `http` scheme origins, and port `443` is assumed for `https`\norigins. This may affect origin matching.\n\nThe host part of the origin may contain the wildcard character `*`. These\nwildcard characters behave as follows:\n\n* `*` is a greedy match to the _left_, including any number of\n DNS labels to the left of its position. This also means that\n `*` will include any number of period `.` characters to the\n left of its position.\n* A wildcard by itself matches all hosts.\n\nAn origin value that includes _only_ the `*` character indicates requests\nfrom all `Origin`s are allowed.\n\nWhen the `AllowOrigins` field is configured with multiple origins, it\nmeans the server supports clients from multiple origins. If the request\n`Origin` matches the configured allowed origins, the gateway must return\nthe given `Origin` and sets value of the header\n`Access-Control-Allow-Origin` same as the `Origin` header provided by the\nclient.\n\nThe status code of a successful response to a \"preflight\" request is\nalways an OK status (i.e., 204 or 200).\n\nIf the request `Origin` does not match the configured allowed origins,\nthe gateway returns 204/200 response but doesn't set the relevant\ncross-origin response headers. Alternatively, the gateway responds with\n403 status to the \"preflight\" request is denied, coupled with omitting\nthe CORS headers. The cross-origin request fails on the client side.\nTherefore, the client doesn't attempt the actual cross-origin request.\n\nConversely, if the request `Origin` matches one of the configured\nallowed origins, the gateway sets the response header\n`Access-Control-Allow-Origin` to the same value as the `Origin`\nheader provided by the client.\n\nWhen config has the wildcard (\"*\") in allowOrigins, and the request\nis not credentialed (e.g., it is a preflight request), the\n`Access-Control-Allow-Origin` response header either contains the\nwildcard as well or the Origin from the request.\n\nWhen the request is credentialed, the gateway must not specify the `*`\nwildcard in the `Access-Control-Allow-Origin` response header. When\nalso the `AllowCredentials` field is true and `AllowOrigins` field\nspecified with the `*` wildcard, the gateway must return a single origin\nin the value of the `Access-Control-Allow-Origin` response header,\ninstead of specifying the `*` wildcard. The value of the header\n`Access-Control-Allow-Origin` is same as the `Origin` header provided by\nthe client.\n\nSupport: Extended",
+ "items": {
+ "description": "The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and\nencoding rules specified in RFC3986. The CORSOrigin MUST include both a\nscheme (\"http\" or \"https\") and a scheme-specific-part, or it should be a single '*' character.\nURIs that include an authority MUST include a fully qualified domain name or\nIP address as the host.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "(^\\*$)|(^(http(s)?):\\/\\/(((\\*\\.)?([a-zA-Z0-9\\-]+\\.)*[a-zA-Z0-9-]+|\\*)(:([0-9]{1,5}))?)$)",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set",
+ "x-kubernetes-validations": [
+ {
+ "message": "AllowOrigins cannot contain '*' alongside other origins",
+ "rule": "!('*' in self && self.size() > 1)"
+ }
+ ]
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders indicates which HTTP response headers can be exposed\nto client-side scripts in response to a cross-origin request.\n\nA CORS-safelisted response header is an HTTP header in a CORS response\nthat it is considered safe to expose to the client scripts.\nThe CORS-safelisted response headers include the following headers:\n`Cache-Control`\n`Content-Language`\n`Content-Length`\n`Content-Type`\n`Expires`\n`Last-Modified`\n`Pragma`\n(See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)\nThe CORS-safelisted response headers are exposed to client by default.\n\nWhen an HTTP header name is specified using the `ExposeHeaders` field,\nthis additional header will be exposed as part of the response to the\nclient.\n\nHeader names are not case-sensitive.\n\nMultiple header names in the value of the `Access-Control-Expose-Headers`\nresponse header are separated by a comma (\",\").\n\nA wildcard indicates that the responses with all HTTP headers are exposed\nto clients. The `Access-Control-Expose-Headers` response header can only\nuse `*` wildcard as value when the request is not credentialed.\n\nWhen the `exposeHeaders` config field contains the \"*\" wildcard and\nthe request is credentialed, the gateway cannot use the `*` wildcard in\nthe `Access-Control-Expose-Headers` response header.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPHeaderName is the name of an HTTP header.\n\nValid values include:\n\n* \"Authorization\"\n* \"Set-Cookie\"\n\nInvalid values include:\n\n - \":method\" - \":\" is an invalid character. This means that HTTP/2 pseudo\n headers are not currently supported by this type.\n - \"/invalid\" - \"/ \" is an invalid character",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "maxAge": {
+ "default": 5,
+ "description": "MaxAge indicates the duration (in seconds) for the client to cache the\nresults of a \"preflight\" request.\n\nThe information provided by the `Access-Control-Allow-Methods` and\n`Access-Control-Allow-Headers` response headers can be cached by the\nclient until the time specified by `Access-Control-Max-Age` elapses.\n\nThe default value of `Access-Control-Max-Age` response header is 5\n(seconds).\n\nWhen the `MaxAge` field is unspecified, the gateway sets the response\nheader \"Access-Control-Max-Age: 5\" by default.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"extensionRef": {
"description": "ExtensionRef is an optional, implementation-specific extension to the\n\"filter\" behavior. For example, resource \"myroutefilter\" in group\n\"networking.example.net\"). ExtensionRef MUST NOT be used for core and\nextended filters.\n\nThis filter can be used multiple times within the same rule.\n\nSupport: Implementation-specific",
"properties": {
@@ -754,6 +1121,152 @@
"type": "object",
"additionalProperties": false
},
+ "externalAuth": {
+ "description": "ExternalAuth configures settings related to sending request details\nto an external auth service. The external service MUST authenticate\nthe request, and MAY authorize the request as well.\n\nIf there is any problem communicating with the external service,\nthis filter MUST fail closed.\n\nSupport: Extended",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef is a reference to a backend to send authorization\nrequests to.\n\nThe backend must speak the selected protocol (GRPC or HTTP) on the\nreferenced port.\n\nIf the backend service requires TLS, use BackendTLSPolicy to tell the\nimplementation to supply the TLS details to be used to connect to that\nbackend.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "forwardBody": {
+ "description": "ForwardBody controls if requests to the authorization server should include\nthe body of the client request; and if so, how big that body is allowed\nto be.\n\nIt is expected that implementations will buffer the request body up to\n`forwardBody.maxSize` bytes. Bodies over that size must be rejected with a\n4xx series error (413 or 403 are common examples), and fail processing\nof the filter.\n\nIf unset, or `forwardBody.maxSize` is set to `0`, then the body will not\nbe forwarded.\n\nFeature Name: HTTPRouteExternalAuthForwardBody",
+ "properties": {
+ "maxSize": {
+ "description": "MaxSize specifies how large in bytes the largest body that will be buffered\nand sent to the authorization server. If the body size is larger than\n`maxSize`, then the body sent to the authorization server must be\ntruncated to `maxSize` bytes.\n\nExperimental note: This behavior needs to be checked against\nvarious dataplanes; it may need to be changed.\nSee https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746\nfor more.\n\nIf 0, the body will not be sent to the authorization server.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "grpc": {
+ "description": "GRPCAuthConfig contains configuration for communication with ext_authz\nprotocol-speaking backends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what headers from the client request\nwill be sent to the authorization server.\n\nIf this list is empty, then all headers must be sent.\n\nIf the list has entries, only those entries must be sent.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http": {
+ "description": "HTTPAuthConfig contains configuration for communication with HTTP-speaking\nbackends.\n\nIf unset, implementations must assume the default behavior for each\nincluded field is intended.",
+ "properties": {
+ "allowedHeaders": {
+ "description": "AllowedRequestHeaders specifies what additional headers from the client request\nwill be sent to the authorization server.\n\nThe following headers must always be sent to the authorization server,\nregardless of this setting:\n\n* `Host`\n* `Method`\n* `Path`\n* `Content-Length`\n* `Authorization`\n\nIf this list is empty, then only those headers must be sent.\n\nNote that `Content-Length` has a special behavior, in that the length\nsent must be correct for the actual request to the external authorization\nserver - that is, it must reflect the actual number of bytes sent in the\nbody of the request to the authorization server.\n\nSo if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set\nto `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set\nto anything other than `0`, then the `Content-Length` of the authorization\nrequest must be set to the actual number of bytes forwarded.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "allowedResponseHeaders": {
+ "description": "AllowedResponseHeaders specifies what headers from the authorization response\nwill be copied into the request to the backend.\n\nIf this list is empty, then all headers from the authorization server\nexcept Authority or Host must be copied.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "path": {
+ "description": "Path sets the prefix that paths from the client request will have added\nwhen forwarded to the authorization server.\n\nWhen empty or unspecified, no prefix is added.\n\nValid values are the same as the \"value\" regex for path values in the `match`\nstanza, and the validation regex will screen out invalid paths in the same way.\nEven with the validation, implementations MUST sanitize this input before using it\ndirectly.",
+ "maxLength": 1024,
+ "pattern": "^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "protocol": {
+ "description": "ExternalAuthProtocol describes which protocol to use when communicating with an\next_authz authorization server.\n\nWhen this is set to GRPC, each backend must use the Envoy ext_authz protocol\non the port specified in `backendRefs`. Requests and responses are defined\nin the protobufs explained at:\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto\n\nWhen this is set to HTTP, each backend must respond with a `200` status\ncode in on a successful authorization. Any other code is considered\nan authorization failure.\n\nFeature Names:\nGRPC Support - HTTPRouteExternalAuthGRPC\nHTTP Support - HTTPRouteExternalAuthHTTP",
+ "enum": [
+ "HTTP",
+ "GRPC"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRef",
+ "protocol"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "grpc must be specified when protocol is set to 'GRPC'",
+ "rule": "self.protocol == 'GRPC' ? has(self.grpc) : true"
+ },
+ {
+ "message": "protocol must be 'GRPC' when grpc is set",
+ "rule": "has(self.grpc) ? self.protocol == 'GRPC' : true"
+ },
+ {
+ "message": "http must be specified when protocol is set to 'HTTP'",
+ "rule": "self.protocol == 'HTTP' ? has(self.http) : true"
+ },
+ {
+ "message": "protocol must be 'HTTP' when http is set",
+ "rule": "has(self.http) ? self.protocol == 'HTTP' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
"requestHeaderModifier": {
"description": "RequestHeaderModifier defines a schema for a filter that modifies request\nheaders.\n\nSupport: Core",
"properties": {
@@ -770,9 +1283,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -812,9 +1326,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1013,7 +1528,10 @@
"description": "StatusCode is the HTTP status code to be used in response.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.\n\nSupport: Core",
"enum": [
301,
- 302
+ 302,
+ 303,
+ 307,
+ 308
],
"type": "integer"
}
@@ -1037,9 +1555,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1079,9 +1598,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1111,7 +1631,9 @@
"RequestMirror",
"RequestRedirect",
"URLRewrite",
- "ExtensionRef"
+ "ExtensionRef",
+ "CORS",
+ "ExternalAuth"
],
"type": "string"
},
@@ -1181,6 +1703,14 @@
],
"type": "object",
"x-kubernetes-validations": [
+ {
+ "message": "filter.cors must be nil if the filter.type is not CORS",
+ "rule": "!(has(self.cors) && self.type != 'CORS')"
+ },
+ {
+ "message": "filter.cors must be specified for CORS filter.type",
+ "rule": "!(!has(self.cors) && self.type == 'CORS')"
+ },
{
"message": "filter.requestHeaderModifier must be nil if the filter.type is not RequestHeaderModifier",
"rule": "!(has(self.requestHeaderModifier) && self.type != 'RequestHeaderModifier')"
@@ -1228,6 +1758,14 @@
{
"message": "filter.extensionRef must be specified for ExtensionRef filter.type",
"rule": "!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
+ },
+ {
+ "message": "filter.externalAuth must be nil if the filter.type is not ExternalAuth",
+ "rule": "!(has(self.externalAuth) && self.type != 'ExternalAuth')"
+ },
+ {
+ "message": "filter.externalAuth must be specified for ExternalAuth filter.type",
+ "rule": "!(!has(self.externalAuth) && self.type == 'ExternalAuth')"
}
],
"additionalProperties": false
@@ -1240,6 +1778,10 @@
"message": "May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",
"rule": "!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
},
+ {
+ "message": "CORS filter cannot be repeated",
+ "rule": "self.filter(f, f.type == 'CORS').size() <= 1"
+ },
{
"message": "RequestHeaderModifier filter cannot be repeated",
"rule": "self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
@@ -1293,9 +1835,10 @@
"type": "string"
},
"value": {
- "description": "Value is the value of HTTP Header to be matched.",
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2",
"maxLength": 4096,
"minLength": 1,
+ "pattern": "^[!-~]+([\\t ]?[!-~]+)*$",
"type": "string"
}
},
@@ -1458,6 +2001,90 @@
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
"type": "string"
},
+ "retry": {
+ "description": "Retry defines the configuration for when to retry an HTTP request.\n\nSupport: Extended",
+ "properties": {
+ "attempts": {
+ "description": "Attempts specifies the maximum number of times an individual request\nfrom the gateway to a backend should be retried.\n\nIf the maximum number of retries has been attempted without a successful\nresponse from the backend, the Gateway MUST return an error.\n\nWhen this field is unspecified, the number of times to attempt to retry\na backend request is implementation-specific.\n\nSupport: Extended",
+ "type": "integer"
+ },
+ "backoff": {
+ "description": "Backoff specifies the minimum duration a Gateway should wait between\nretry attempts and is represented in Gateway API Duration formatting.\n\nFor example, setting the `rules[].retry.backoff` field to the value\n`100ms` will cause a backend request to first be retried approximately\n100 milliseconds after timing out or receiving a response code configured\nto be retriable.\n\nAn implementation MAY use an exponential or alternative backoff strategy\nfor subsequent retry attempts, MAY cap the maximum backoff duration to\nsome amount greater than the specified minimum, and MAY add arbitrary\njitter to stagger requests, as long as unsuccessful backend requests are\nnot retried before the configured minimum duration.\n\nIf a Request timeout (`rules[].timeouts.request`) is configured on the\nroute, the entire duration of the initial request and any retry attempts\nMUST not exceed the Request timeout duration. If any retry attempts are\nstill in progress when the Request timeout duration has been reached,\nthese SHOULD be canceled if possible and the Gateway MUST immediately\nreturn a timeout error.\n\nIf a BackendRequest timeout (`rules[].timeouts.backendRequest`) is\nconfigured on the route, any retry attempts which reach the configured\nBackendRequest timeout duration without a response SHOULD be canceled if\npossible and the Gateway should wait for at least the specified backoff\nduration before attempting to retry the backend request again.\n\nIf a BackendRequest timeout is _not_ configured on the route, retry\nattempts MAY time out after an implementation default duration, or MAY\nremain pending until a configured Request timeout or implementation\ndefault duration for total request time is reached.\n\nWhen this field is unspecified, the time to wait between retry attempts\nis implementation-specific.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "codes": {
+ "description": "Codes defines the HTTP response status codes for which a backend request\nshould be retried.\n\nSupport: Extended",
+ "items": {
+ "description": "HTTPRouteRetryStatusCode defines an HTTP response status code for\nwhich a backend request should be retried.\n\nImplementations MUST support the following status codes as retriable:\n\n* 500\n* 502\n* 503\n* 504\n\nImplementations MAY support specifying additional discrete values in the\n500-599 range.\n\nImplementations MAY support specifying discrete values in the 400-499 range,\nwhich are often inadvisable to retry.",
+ "maximum": 599,
+ "minimum": 400,
+ "type": "integer"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the route rule.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
+ },
"timeouts": {
"description": "Timeouts defines the timeouts that can be configured for an HTTP request.\n\nSupport: Extended",
"properties": {
@@ -1508,14 +2135,27 @@
"additionalProperties": false
},
"maxItems": 16,
+ "minItems": 1,
"type": "array",
"x-kubernetes-list-type": "atomic",
"x-kubernetes-validations": [
{
"message": "While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",
"rule": "(self.size() > 0 ? self[0].matches.size() : 0) + (self.size() > 1 ? self[1].matches.size() : 0) + (self.size() > 2 ? self[2].matches.size() : 0) + (self.size() > 3 ? self[3].matches.size() : 0) + (self.size() > 4 ? self[4].matches.size() : 0) + (self.size() > 5 ? self[5].matches.size() : 0) + (self.size() > 6 ? self[6].matches.size() : 0) + (self.size() > 7 ? self[7].matches.size() : 0) + (self.size() > 8 ? self[8].matches.size() : 0) + (self.size() > 9 ? self[9].matches.size() : 0) + (self.size() > 10 ? self[10].matches.size() : 0) + (self.size() > 11 ? self[11].matches.size() : 0) + (self.size() > 12 ? self[12].matches.size() : 0) + (self.size() > 13 ? self[13].matches.size() : 0) + (self.size() > 14 ? self[14].matches.size() : 0) + (self.size() > 15 ? self[15].matches.size() : 0) <= 128"
+ },
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
}
]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
}
},
"type": "object",
@@ -1530,7 +2170,7 @@
"description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
"properties": {
"conditions": {
- "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace the controller does not have access to.",
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
@@ -1623,14 +2263,14 @@
"type": "string"
},
"namespace": {
- "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\nSupport: Core",
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"port": {
- "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
"format": "int32",
"maximum": 65535,
"minimum": 1,
diff --git a/crdSchemas/master-standalone/httproutefilter-stable-v1alpha1.json b/crdSchemas/master-standalone/httproutefilter-stable-v1alpha1.json
new file mode 100644
index 0000000..6a3e24c
--- /dev/null
+++ b/crdSchemas/master-standalone/httproutefilter-stable-v1alpha1.json
@@ -0,0 +1,411 @@
+{
+ "description": "HTTPRouteFilter is a custom Envoy Gateway HTTPRouteFilter which provides extended\ntraffic processing options such as path regex rewrite, direct response and more.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of HTTPRouteFilter.",
+ "properties": {
+ "credentialInjection": {
+ "description": "HTTPCredentialInjectionFilter defines the configuration to inject credentials into the request.\nThis is useful when the backend service requires credentials in the request, and the original\nrequest does not contain them. The filter can inject credentials into the request before forwarding\nit to the backend service.",
+ "properties": {
+ "credential": {
+ "description": "Credential is the credential to be injected.",
+ "properties": {
+ "valueRef": {
+ "description": "ValueRef is a reference to the secret containing the credentials to be injected.\nThis is an Opaque secret. The credential should be stored in the key\n\"credential\", and the value should be the credential to be injected.\nFor example, for basic authentication, the value should be \"Basic \".\nfor bearer token, the value should be \"Bearer \".",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "valueRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header is the name of the header where the credentials are injected.\nIf not specified, the credentials are injected into the Authorization header.",
+ "type": "string"
+ },
+ "overwrite": {
+ "description": "Whether to overwrite the value or not if the injected headers already exist.\nIf not specified, the default value is false.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "credential"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "directResponse": {
+ "description": "HTTPDirectResponseFilter defines the configuration to return a fixed response.",
+ "properties": {
+ "body": {
+ "description": "Body of the direct response.\nSupports Envoy command operators for dynamic content (see https://www.envoyproxy.io/docs/envoy/latest/configuration/observability/access_log/usage#command-operators).",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the value as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ },
+ {
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ]
+ }
+ ],
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the body value.\nValid values are Inline and ValueRef, default is Inline.",
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef contains the contents of the body\nspecified as a local object reference.\nOnly a reference to ConfigMap is supported.\n\nThe value of key `response.body` in the ConfigMap will be used as the response body.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "inline must be set for type Inline",
+ "rule": "(!has(self.type) || self.type == 'Inline')? has(self.inline) : true"
+ },
+ {
+ "message": "valueRef must be set for type ValueRef",
+ "rule": "(has(self.type) && self.type == 'ValueRef')? has(self.valueRef) : true"
+ },
+ {
+ "message": "only ConfigMap is supported for ValueRef",
+ "rule": "has(self.valueRef) ? self.valueRef.kind == 'ConfigMap' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "contentType": {
+ "description": "Content Type of the direct response. This will be set in the Content-Type header.",
+ "type": "string"
+ },
+ "header": {
+ "description": "Header defines the headers of the direct response.",
+ "properties": {
+ "add": {
+ "description": "Add adds the given header(s) (name, value) to the request\nbefore the action. It appends to any existing values associated\nwith the header name.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n add:\n - name: \"my-header\"\n value: \"bar,baz\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: foo,bar,baz",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "remove": {
+ "description": "Remove the given header(s) from the HTTP request before the action. The\nvalue of Remove is a list of HTTP header names. Note that the header\nnames are case-insensitive (see\nhttps://datatracker.ietf.org/doc/html/rfc2616#section-4.2).\n\nInput:\n GET /foo HTTP/1.1\n my-header1: foo\n my-header2: bar\n my-header3: baz\n\nConfig:\n remove: [\"my-header1\", \"my-header3\"]\n\nOutput:\n GET /foo HTTP/1.1\n my-header2: bar",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "set"
+ },
+ "set": {
+ "description": "Set overwrites the request with the given header (name, value)\nbefore the action.\n\nInput:\n GET /foo HTTP/1.1\n my-header: foo\n\nConfig:\n set:\n - name: \"my-header\"\n value: \"bar\"\n\nOutput:\n GET /foo HTTP/1.1\n my-header: bar",
+ "items": {
+ "description": "HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the HTTP Header to be matched. Name matching MUST be\ncase-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).\n\nIf multiple entries specify equivalent header names, the first entry with\nan equivalent name MUST be considered for a match. Subsequent entries\nwith an equivalent header name MUST be ignored. Due to the\ncase-insensitivity of header names, \"foo\" and \"Foo\" are considered\nequivalent.",
+ "maxLength": 256,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9!#$%&'*+\\-.^_\\x60|~]+$",
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the value of HTTP Header to be matched.\n\nMust consist of printable US-ASCII characters, optionally separated\nby single tabs or spaces. See: https://tools.ietf.org/html/rfc7230#section-3.2\n\n\n",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "header.remove is not supported for DirectResponse",
+ "rule": "!has(self.remove) || size(self.remove) == 0"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "statusCode": {
+ "description": "Status Code of the HTTP response\nIf unset, defaults to 200.",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "matches": {
+ "description": "Matches defines additional matching criteria for the HTTPRoute rule.\nAs with HTTPRouteRule.Matches, the rule is matched if any one match applies.\nWhen both HTTPRouteRule.Matches and HTTPRouteFilter.Matches are set, the\neffective matching is the logical AND of the two sets.",
+ "items": {
+ "description": "HTTPRouteMatchFilter defines additional matching criteria for the HTTPRoute rule.\nAt least one matcher must be specified.",
+ "minProperties": 1,
+ "properties": {
+ "cookies": {
+ "description": "Cookies is a list of cookie matchers evaluated against the HTTP request.\nAll specified matchers must match.",
+ "items": {
+ "description": "HTTPCookieMatch defines how to match a single cookie.",
+ "properties": {
+ "name": {
+ "description": "Name is the cookie name to evaluate.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against the value of the cookie.",
+ "enum": [
+ "Exact",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value is the cookie value to be matched.",
+ "maxLength": 4096,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "urlRewrite": {
+ "description": "HTTPURLRewriteFilter define rewrites of HTTP URL components such as path and host",
+ "properties": {
+ "appendXForwardedHost": {
+ "description": "AppendXForwardedHost controls whether the original Host header value is\nappended to the X-Forwarded-Host header when hostname rewriting is configured.\nDefaults to true for backward compatibility.",
+ "type": "boolean"
+ },
+ "hostname": {
+ "description": "Hostname is the value to be used to replace the Host header value during\nforwarding.",
+ "properties": {
+ "header": {
+ "description": "Header is the name of the header whose value would be used to rewrite the Host header",
+ "type": "string"
+ },
+ "type": {
+ "description": "HTTPPathModifierType defines the type of Hostname rewrite.",
+ "enum": [
+ "Header",
+ "Backend"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "header must be nil if the type is not Header",
+ "rule": "!(has(self.header) && self.type != 'Header')"
+ },
+ {
+ "message": "header must be specified for Header type",
+ "rule": "!(!has(self.header) && self.type == 'Header')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "path": {
+ "description": "Path defines a path rewrite.",
+ "properties": {
+ "replaceRegexMatch": {
+ "description": "ReplaceRegexMatch defines a path regex rewrite. The path portions matched by the regex pattern are replaced by the defined substitution.\nhttps://www.envoyproxy.io/docs/envoy/latest/api-v3/config/route/v3/route_components.proto#envoy-v3-api-field-config-route-v3-routeaction-regex-rewrite\nSome examples:\n(1) replaceRegexMatch:\n pattern: ^/service/([^/]+)(/.*)$\n substitution: \\2/instance/\\1\n Would transform /service/foo/v1/api into /v1/api/instance/foo.\n(2) replaceRegexMatch:\n pattern: one\n substitution: two\n Would transform /xxx/one/yyy/one/zzz into /xxx/two/yyy/two/zzz.\n(3) replaceRegexMatch:\n pattern: ^(.*?)one(.*)$\n substitution: \\1two\\2\n Would transform /xxx/one/yyy/one/zzz into /xxx/two/yyy/one/zzz.\n(3) replaceRegexMatch:\n pattern: (?i)/xxx/\n substitution: /yyy/\n Would transform path /aaa/XxX/bbb into /aaa/yyy/bbb (case-insensitive).",
+ "properties": {
+ "pattern": {
+ "description": "Pattern matches a regular expression against the value of the HTTP Path.The regex string must\nadhere to the syntax documented in https://github.com/google/re2/wiki/Syntax.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "substitution": {
+ "description": "Substitution is an expression that replaces the matched portion.The expression may include numbered\ncapture groups that adhere to syntax documented in https://github.com/google/re2/wiki/Syntax.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "pattern",
+ "substitution"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "HTTPPathModifierType defines the type of path redirect or rewrite.",
+ "enum": [
+ "ReplaceRegexMatch"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If HTTPPathModifier type is ReplaceRegexMatch, replaceRegexMatch field needs to be set.",
+ "rule": "self.type == 'ReplaceRegexMatch' ? has(self.replaceRegexMatch) : !has(self.replaceRegexMatch)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/listenerset-stable-v1.json b/crdSchemas/master-standalone/listenerset-stable-v1.json
new file mode 100644
index 0000000..487ba2b
--- /dev/null
+++ b/crdSchemas/master-standalone/listenerset-stable-v1.json
@@ -0,0 +1,556 @@
+{
+ "description": "ListenerSet defines a set of additional listeners to attach to an existing Gateway.\nThis resource provides a mechanism to merge multiple listeners into a single Gateway.\n\nThe parent Gateway must explicitly allow ListenerSet attachment through its\nAllowedListeners configuration. By default, Gateways do not allow ListenerSet\nattachment.\n\nRoutes can attach to a ListenerSet by specifying it as a parentRef, and can\noptionally target specific listeners using the sectionName field.\n\nPolicy Attachment:\n- Policies that attach to a ListenerSet apply to all listeners defined in that resource\n- Policies do not impact listeners in the parent Gateway\n- Different ListenerSets attached to the same Gateway can have different policies\n- If an implementation cannot apply a policy to specific listeners, it should reject the policy\n\nReferenceGrant Semantics:\n- ReferenceGrants applied to a Gateway are not inherited by child ListenerSets\n- ReferenceGrants applied to a ListenerSet do not grant permission to the parent Gateway's listeners\n- A ListenerSet can reference secrets/backends in its own namespace without a ReferenceGrant\n\nGateway Integration:\n - The parent Gateway's status will include \"AttachedListenerSets\"\n which is the count of ListenerSets that have successfully attached to a Gateway\n A ListenerSet is successfully attached to a Gateway when all the following conditions are met:\n - The ListenerSet is selected by the Gateway's AllowedListeners field\n - The ListenerSet has a valid ParentRef selecting the Gateway\n - The ListenerSet's status has the condition \"Accepted: true\"",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of ListenerSet.",
+ "properties": {
+ "listeners": {
+ "description": "Listeners associated with this ListenerSet. Listeners define\nlogical endpoints that are bound on this referenced parent Gateway's addresses.\n\nListeners in a `Gateway` and their attached `ListenerSets` are concatenated\nas a list when programming the underlying infrastructure. Each listener\nname does not need to be unique across the Gateway and ListenerSets.\nSee ListenerEntry.Name for more details.\n\nImplementations MUST treat the parent Gateway as having the merged\nlist of all listeners from itself and attached ListenerSets using\nthe following precedence:\n\n1. \"parent\" Gateway\n2. ListenerSet ordered by creation time (oldest first)\n3. ListenerSet ordered alphabetically by \"{namespace}/{name}\".\n\nAn implementation MAY reject listeners by setting the ListenerEntryStatus\n`Accepted` condition to False with the Reason `TooManyListeners`\n\nIf a listener has a conflict, this will be reported in the\nStatus.ListenerEntryStatus setting the `Conflicted` condition to True.\n\nImplementations SHOULD be cautious about what information from the\nparent or siblings are reported to avoid accidentally leaking\nsensitive information that the child would not otherwise have access\nto. This can include contents of secrets etc.",
+ "items": {
+ "properties": {
+ "allowedRoutes": {
+ "default": {
+ "namespaces": {
+ "from": "Same"
+ }
+ },
+ "description": "AllowedRoutes defines the types of routes that MAY be attached to a\nListener and the trusted namespaces where those Route resources MAY be\npresent.\n\nAlthough a client request may match multiple route rules, only one rule\nmay ultimately receive the request. Matching precedence MUST be\ndetermined in order of the following criteria:\n\n* The most specific match as defined by the Route type.\n* The oldest Route based on creation timestamp. For example, a Route with\n a creation timestamp of \"2020-09-08 01:02:03\" is given precedence over\n a Route with a creation timestamp of \"2020-09-08 01:02:04\".\n* If everything else is equivalent, the Route appearing first in\n alphabetical order (namespace/name) should be given precedence. For\n example, foo/bar is given precedence over foo/baz.\n\nAll valid rules within a Route attached to this Listener should be\nimplemented. Invalid Route rules can be ignored (sometimes that will mean\nthe full Route). If a Route rule transitions from valid to invalid,\nsupport for that Route rule should be dropped to ensure consistency. For\nexample, even if a filter specified by a Route rule is invalid, the rest\nof the rules within that Route should still be supported.",
+ "properties": {
+ "kinds": {
+ "description": "Kinds specifies the groups and kinds of Routes that are allowed to bind\nto this Gateway Listener. When unspecified or empty, the kinds of Routes\nselected are determined using the Listener protocol.\n\nA RouteGroupKind MUST correspond to kinds of Routes that are compatible\nwith the application protocol specified in the Listener's Protocol field.\nIf an implementation does not support or recognize this resource type, it\nMUST set the \"ResolvedRefs\" condition to False for this Listener with the\n\"InvalidRouteKinds\" reason.\n\nSupport: Core",
+ "items": {
+ "description": "RouteGroupKind indicates the group and kind of a Route resource.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the Route.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the Route.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "namespaces": {
+ "default": {
+ "from": "Same"
+ },
+ "description": "Namespaces indicates namespaces from which Routes may be attached to this\nListener. This is restricted to the namespace of this Gateway by default.\n\nSupport: Core",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates where Routes will be selected for this Gateway. Possible\nvalues are:\n\n* All: Routes in all namespaces may be used by this Gateway.\n* Selector: Routes in namespaces selected by the selector may be used by\n this Gateway.\n* Same: Only Routes in the same namespace may be used by this Gateway.\n\nSupport: Core",
+ "enum": [
+ "All",
+ "Selector",
+ "Same"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector must be specified when From is set to \"Selector\". In that case,\nonly Routes in Namespaces matching this Selector will be selected by this\nGateway. This field is ignored for other values of \"From\".\n\nSupport: Core",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "hostname": {
+ "description": "Hostname specifies the virtual hostname to match for protocol types that\ndefine this concept. When unspecified, all hostnames are matched. This\nfield is ignored for protocols that don't require hostname based\nmatching.\n\nImplementations MUST apply Hostname matching appropriately for each of\nthe following protocols:\n\n* TLS: The Listener Hostname MUST match the SNI.\n* HTTP: The Listener Hostname MUST match the Host header of the request.\n* HTTPS: The Listener Hostname SHOULD match at both the TLS and HTTP\n protocol layers as described above. If an implementation does not\n ensure that both the SNI and Host header match the Listener hostname,\n it MUST clearly document that.\n\nFor HTTPRoute and TLSRoute resources, there is an interaction with the\n`spec.hostnames` array. When both listener and route specify hostnames,\nthere MUST be an intersection between the values for a Route to be\naccepted. For more information, refer to the Route specific Hostnames\ndocumentation.\n\nHostnames that are prefixed with a wildcard label (`*.`) are interpreted\nas a suffix match. That means that a match for `*.example.com` would match\nboth `test.example.com`, and `foo.test.example.com`, but not `example.com`.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the Listener. This name MUST be unique within a\nListenerSet.\n\nName is not required to be unique across a Gateway and ListenerSets.\nRoutes can attach to a Listener by having a ListenerSet as a parentRef\nand setting the SectionName",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port. Multiple listeners may use the\nsame port, subject to the Listener compatibility rules.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "protocol": {
+ "description": "Protocol specifies the network protocol this listener expects to receive.",
+ "maxLength": 255,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z0-9]([-a-zA-Z0-9]*[a-zA-Z0-9])?$|[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9]+$",
+ "type": "string"
+ },
+ "tls": {
+ "description": "TLS is the TLS configuration for the Listener. This field is required if\nthe Protocol field is \"HTTPS\" or \"TLS\". It is invalid to set this field\nif the Protocol field is \"HTTP\", \"TCP\", or \"UDP\".\n\nThe association of SNIs to Certificate defined in ListenerTLSConfig is\ndefined based on the Hostname field for this listener.\n\nThe GatewayClass MUST use the longest matching SNI out of all\navailable certificates for any TLS handshake.",
+ "properties": {
+ "certificateRefs": {
+ "description": "CertificateRefs contains a series of references to Kubernetes objects that\ncontains TLS certificates and private keys. These certificates are used to\nestablish a TLS handshake for requests that match the hostname of the\nassociated listener.\n\nA single CertificateRef to a Kubernetes Secret has \"Core\" support.\nImplementations MAY choose to support attaching multiple certificates to\na Listener, but this behavior is implementation-specific.\n\nReferences to a resource in different namespace are invalid UNLESS there\nis a ReferenceGrant in the target namespace that allows the certificate\nto be attached. If a ReferenceGrant does not allow this reference, the\n\"ResolvedRefs\" condition MUST be set to False for this listener with the\n\"RefNotPermitted\" reason.\n\nThis field is required to have at least one element when the mode is set\nto \"Terminate\" (default) and is optional otherwise.\n\nCertificateRefs can reference to standard Kubernetes resources, i.e.\nSecret, or implementation-specific custom resources.\n\nSupport: Core - A single reference to a Kubernetes Secret of type kubernetes.io/tls\n\nSupport: Implementation-specific (More than one reference or other resource types)",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "mode": {
+ "default": "Terminate",
+ "description": "Mode defines the TLS behavior for the TLS session initiated by the client.\nThere are two possible modes:\n\n- Terminate: The TLS session between the downstream client and the\n Gateway is terminated at the Gateway. This mode requires certificates\n to be specified in some way, such as populating the certificateRefs\n field.\n- Passthrough: The TLS session is NOT terminated by the Gateway. This\n implies that the Gateway can't decipher the TLS stream except for\n the ClientHello message of the TLS protocol. The certificateRefs field\n is ignored in this mode.\n\nSupport: Core",
+ "enum": [
+ "Terminate",
+ "Passthrough"
+ ],
+ "type": "string"
+ },
+ "options": {
+ "additionalProperties": {
+ "description": "AnnotationValue is the value of an annotation in Gateway API. This is used\nfor validation of maps such as TLS options. This roughly matches Kubernetes\nannotation validation, although the length validation in that case is based\non the entire size of the annotations struct.",
+ "maxLength": 4096,
+ "minLength": 0,
+ "type": "string"
+ },
+ "description": "Options are a list of key/value pairs to enable extended TLS\nconfiguration for each implementation. For example, configuring the\nminimum TLS version or supported cipher suites.\n\nA set of common keys MAY be defined by the API in the future. To avoid\nany ambiguity, implementation-specific definitions MUST use\ndomain-prefixed names, such as `example.com/my-custom-option`.\nUn-prefixed names are reserved for key names defined by Gateway API.\n\nSupport: Implementation-specific",
+ "maxProperties": 16,
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "certificateRefs or options must be specified when mode is Terminate",
+ "rule": "self.mode == 'Terminate' ? size(self.certificateRefs) > 0 || size(self.options) > 0 : true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "port",
+ "protocol"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map",
+ "x-kubernetes-validations": [
+ {
+ "message": "tls must not be specified for protocols ['HTTP', 'TCP', 'UDP']",
+ "rule": "self.all(l, l.protocol in ['HTTP', 'TCP', 'UDP'] ? !has(l.tls) : true)"
+ },
+ {
+ "message": "tls mode must be Terminate for protocol HTTPS",
+ "rule": "self.all(l, (l.protocol == 'HTTPS' && has(l.tls)) ? (l.tls.mode == '' || l.tls.mode == 'Terminate') : true)"
+ },
+ {
+ "message": "tls mode must be set for protocol TLS",
+ "rule": "self.all(l, (l.protocol == 'TLS' ? has(l.tls) && has(l.tls.mode) && l.tls.mode != '' : true))"
+ },
+ {
+ "message": "hostname must not be specified for protocols ['TCP', 'UDP']",
+ "rule": "self.all(l, l.protocol in ['TCP', 'UDP'] ? (!has(l.hostname) || l.hostname == '') : true)"
+ },
+ {
+ "message": "Listener name must be unique within the Gateway",
+ "rule": "self.all(l1, self.exists_one(l2, l1.name == l2.name))"
+ },
+ {
+ "message": "Combination of port, protocol and hostname must be unique for each listener",
+ "rule": "self.all(l1, !has(l1.port) || self.exists_one(l2, has(l2.port) && l1.port == l2.port && l1.protocol == l2.protocol && (has(l1.hostname) && has(l2.hostname) ? l1.hostname == l2.hostname : !has(l1.hostname) && !has(l2.hostname))))"
+ }
+ ]
+ },
+ "parentRef": {
+ "description": "ParentRef references the Gateway that the listeners are attached to.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent. For example \"Gateway\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. If not present,\nthe namespace of the referent is assumed to be the same as\nthe namespace of the referring object.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "listeners",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "default": {
+ "conditions": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ },
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Programmed"
+ }
+ ]
+ },
+ "description": "Status defines the current state of ListenerSet.",
+ "properties": {
+ "conditions": {
+ "default": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ },
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Programmed"
+ }
+ ],
+ "description": "Conditions describe the current conditions of the ListenerSet.\n\nImplementations MUST express ListenerSet conditions using the\n`ListenerSetConditionType` and `ListenerSetConditionReason`\nconstants so that operators and tools can converge on a common\nvocabulary to describe ListenerSet state.\n\nKnown condition types are:\n\n* \"Accepted\"\n* \"Programmed\"",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "listeners": {
+ "description": "Listeners provide status for each unique listener port defined in the Spec.",
+ "items": {
+ "description": "ListenerStatus is the status associated with a Listener.",
+ "properties": {
+ "attachedRoutes": {
+ "description": "AttachedRoutes represents the total number of Routes that have been\nsuccessfully attached to this Listener.\n\nSuccessful attachment of a Route to a Listener is based solely on the\ncombination of the AllowedRoutes field on the corresponding Listener\nand the Route's ParentRefs field. A Route is successfully attached to\na Listener when it is selected by the Listener's AllowedRoutes field\nAND the Route has a valid ParentRef selecting the whole Gateway\nresource or a specific Listener as a parent resource (more detail on\nattachment semantics can be found in the documentation on the various\nRoute kinds ParentRefs fields). Listener status does not impact\nsuccessful attachment, i.e. the AttachedRoutes field count MUST be set\nfor Listeners, even if the Accepted condition of an individual Listener is set\nto \"False\". The AttachedRoutes number represents the number of Routes with\nthe Accepted condition set to \"True\" that have been attached to this Listener.\nRoutes with any other value for the Accepted condition MUST NOT be included\nin this count.\n\nUses for this field include troubleshooting Route attachment and\nmeasuring blast radius/impact of changes to a Listener.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "conditions": {
+ "description": "Conditions describe the current condition of this listener.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "name": {
+ "description": "Name is the name of the Listener that this status corresponds to.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "supportedKinds": {
+ "description": "SupportedKinds is the list indicating the Kinds supported by this\nlistener. This MUST represent the kinds supported by an implementation for\nthat Listener configuration.\n\nIf kinds are specified in Spec that are not supported, they MUST NOT\nappear in this list and an implementation MUST set the \"ResolvedRefs\"\ncondition to \"False\" with the \"InvalidRouteKinds\" reason. If both valid\nand invalid Route kinds are specified, the implementation MUST\nreference the valid Route kinds that have been specified.",
+ "items": {
+ "description": "RouteGroupKind indicates the group and kind of a Route resource.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the Route.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the Route.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "attachedRoutes",
+ "conditions",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/podmonitor-stable-v1.json b/crdSchemas/master-standalone/podmonitor-stable-v1.json
index 402413d..8d6f5c2 100644
--- a/crdSchemas/master-standalone/podmonitor-stable-v1.json
+++ b/crdSchemas/master-standalone/podmonitor-stable-v1.json
@@ -19,7 +19,7 @@
"description": "attachMetadata defines additional metadata which is added to the\ndiscovered targets.\n\nIt requires Prometheus >= v2.35.0.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -53,21 +53,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"namespaceSelector": {
@@ -91,6 +95,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -287,6 +292,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -635,7 +641,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -750,6 +756,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -998,6 +1005,7 @@
"sampleLimit": {
"description": "sampleLimit defines a per-scrape limit on the number of scraped samples\nthat will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scrapeClass": {
@@ -1087,6 +1095,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will\nbe accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
}
},
diff --git a/crdSchemas/master-standalone/policyfilter-stable-v1alpha1.json b/crdSchemas/master-standalone/policyfilter-stable-v1alpha1.json
new file mode 100644
index 0000000..7a75ad8
--- /dev/null
+++ b/crdSchemas/master-standalone/policyfilter-stable-v1alpha1.json
@@ -0,0 +1,95 @@
+{
+ "description": "PolicyFilter represents a Pomerium policy that can be attached to a particular route defined\nvia the Kubernetes Gateway API.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the content of the policy.",
+ "properties": {
+ "ppl": {
+ "description": "Policy rules in Pomerium Policy Language (PPL) syntax. May be expressed\nin either YAML or JSON format.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status contains the status of the policy (e.g. is the policy valid).",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describe the current state of the PolicyFilter.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.\n---\nThis struct is intended for direct use as an array at the field path .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents the observations of a foo's current state.\n\t // Known .status.conditions.type are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other fields\n\t}",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.\n---\nMany .condition.type values are consistent across resources like Available, but because arbitrary conditions can be\nuseful (see .node.status.conditions), the ability to deconflict is important.\nThe regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/pomerium-stable-v1.json b/crdSchemas/master-standalone/pomerium-stable-v1.json
new file mode 100644
index 0000000..7e524ae
--- /dev/null
+++ b/crdSchemas/master-standalone/pomerium-stable-v1.json
@@ -0,0 +1,744 @@
+{
+ "description": "Pomerium define runtime-configurable Pomerium settings\nthat do not fall into the category of deployment parameters",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "PomeriumSpec defines Pomerium-specific configuration parameters.",
+ "properties": {
+ "accessLogFields": {
+ "description": "AccessLogFields sets the access fields to log.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "allowUpgrades": {
+ "description": "AllowUpgrades sets the allowed upgrade types.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "authenticate": {
+ "description": "Authenticate sets authenticate service parameters.\nIf not specified, a Pomerium-hosted authenticate service would be used.",
+ "properties": {
+ "url": {
+ "description": "AuthenticateURL is a dedicated domain URL\nthe non-authenticated persons would be referred to.\n\n\n - You do not need to create a dedicated
Ingress for this\n\t\tvirtual route, as it is handled by Pomerium internally. \n\t- You do need create a secret with corresponding TLS certificate for this route\n\t\tand reference it via
certificates.\n\t\tIf you use cert-manager with HTTP01 challenge,\n\t\tyou may use pomerium ingressClass to solve it. \n
",
+ "format": "uri",
+ "pattern": "^https://",
+ "type": "string"
+ }
+ },
+ "required": [
+ "url"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "authorizeLogFields": {
+ "description": "AuthorizeLogFields sets the authorize fields to log.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "bearerTokenFormat": {
+ "description": "BearerTokenFormat sets the Bearer Token Format.",
+ "enum": [
+ "default",
+ "idp_access_token",
+ "idp_identity_token"
+ ],
+ "type": "string"
+ },
+ "caSecrets": {
+ "description": "CASecret should refer to k8s secrets with key ca.crt containing a CA certificate.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "certificateAutoProvision": {
+ "description": "CertificateAutoProvision sets the certificate auto provision settings.\nThis is a fallback for routes that are not defined via Ingress or\nGateway resources. When configured, cert-manager certificate resources\nwill be created for any routes which have no matching TLS certificate.",
+ "properties": {
+ "clusterIssuer": {
+ "description": "The cert-manager ClusterIssuer that will be used for new certificates.\nCertificates will be created in the same namespace as the controller\npod.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "issuer": {
+ "description": "The cert-manager Issuer that will be used for new certificates.\nCertificates will be created in the same namespace as the Issuer.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "certificates": {
+ "description": "Certificates is a list of secrets of type TLS to use",
+ "format": "namespace/name",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "circuitBreakerThresholds": {
+ "description": "CircuitBreakerThresholds sets the circuit breaker thresholds settings.",
+ "properties": {
+ "maxConnectionPools": {
+ "description": "MaxConnectionPools sets the maximum number of connection pools per\ncluster that Envoy will concurrently support at once. If not specified,\nthe default is unlimited. Set this for clusters which create a large\nnumber of connection pools.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxConnections": {
+ "description": "MaxConnections sets the maximum number of connections that Envoy will\nmake to the upstream cluster. If not specified, the default is 1024.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "description": "MaxPendingRequests sets the maximum number of pending requests that\nEnvoy will allow to the upstream cluster. If not specified, the\ndefault is 1024. This limit is applied as a connection limit for\nnon-HTTP traffic.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxRequests": {
+ "description": "MaxRequests sets the maximum number of parallel requests that Envoy\nwill make to the upstream cluster. If not specified, the default is\n1024. This limit does not apply to non-HTTP traffic.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "maxRetries": {
+ "description": "MaxRetries sets the maximum number of parallel retries that Envoy\nwill allow to the upstream cluster. If not specified, the default is 3.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "codecType": {
+ "description": "CodecType sets the Codec Type.",
+ "enum": [
+ "auto",
+ "http1",
+ "http2",
+ "http3"
+ ],
+ "type": "string"
+ },
+ "cookie": {
+ "description": "Cookie defines Pomerium session cookie options.",
+ "properties": {
+ "domain": {
+ "description": "Domain defaults to the same host that set the cookie.\nIf you specify the domain explicitly, then subdomains would also be included.",
+ "type": "string"
+ },
+ "expire": {
+ "description": "Expire sets cookie and Pomerium session expiration time.\nOnce session expires, users would have to re-login.\nIf you change this parameter, existing sessions are not affected.\nSee Session Management\n(Enterprise) for a more fine-grained session controls.
\nDefaults to 14 hours.
",
+ "format": "duration",
+ "type": "string"
+ },
+ "httpOnly": {
+ "description": "HTTPOnly if set to false, the cookie would be accessible from within the JavaScript.\nDefaults to true.",
+ "type": "boolean"
+ },
+ "name": {
+ "description": "Name sets the Pomerium session cookie name.\nDefaults to _pomerium",
+ "type": "string"
+ },
+ "sameSite": {
+ "description": "SameSite sets the SameSite option for cookies.\nDefaults to .",
+ "enum": [
+ "strict",
+ "lax",
+ "none"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dataBroker": {
+ "description": "DataBroker sets the databroker settings.",
+ "properties": {
+ "clusterLeaderId": {
+ "description": "ClusterLeaderID defines the cluster leader in a clustered databroker.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS sets the dns settings.",
+ "properties": {
+ "failureRefreshRate": {
+ "description": "FailureRefreshRate is the rate at which DNS lookups are refreshed when requests are failing.",
+ "format": "duration",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily is the DNS IP address resolution policy.",
+ "enum": [
+ "auto",
+ "v4_only",
+ "v6_only",
+ "v4_preferred",
+ "all"
+ ],
+ "type": "string"
+ },
+ "queryTimeout": {
+ "description": "QueryTimeout is the amount of time each name server is given to respond to a query on the first try of any given server.",
+ "format": "duration",
+ "type": "string"
+ },
+ "queryTries": {
+ "description": "QueryTries is the maximum number of query attempts the resolver will make before giving up. Each attempt may use a different name server.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "refreshRate": {
+ "description": "RefreshRate is the rate at which DNS lookups are refreshed.",
+ "format": "duration",
+ "type": "string"
+ },
+ "udpMaxQueries": {
+ "description": "UDPMaxQueries caps the number of UDP based DNS queries on a single port.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "useTcp": {
+ "description": "UseTCP uses TCP for all DNS queries instead of the default protocol UDP.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "downstreamMtls": {
+ "description": "DownstreamMTLS sets the Downstream MTLS Settings.",
+ "properties": {
+ "ca": {
+ "description": "CA is a bundle of PEM-encoded X.509 certificates that will be treated as trust anchors when verifying client certificates.",
+ "format": "byte",
+ "type": "string"
+ },
+ "crl": {
+ "description": "CRL is a bundle of PEM-encoded certificate revocation lists to be consulted during certificate validation.",
+ "format": "byte",
+ "type": "string"
+ },
+ "enforcement": {
+ "description": "Enforcement controls Pomerium's behavior when a client does not present a trusted client certificate.",
+ "enum": [
+ "policy_with_default_deny",
+ "policy",
+ "reject_connection"
+ ],
+ "type": "string"
+ },
+ "matchSubjectAltNames": {
+ "description": "Match Subject Alt Names can be used to add an additional constraint when validating client certificates.",
+ "properties": {
+ "dns": {
+ "type": "string"
+ },
+ "email": {
+ "type": "string"
+ },
+ "ipAddress": {
+ "type": "string"
+ },
+ "uri": {
+ "type": "string"
+ },
+ "userPrincipalName": {
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxVerifyDepth": {
+ "description": "MaxVerifyDepth sets a limit on the depth of a certificate chain presented by the client.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "envoyDynamicExtensions": {
+ "description": "EnvoyDynamicExtensions file paths to the extensions to be loaded by Envoy at runtime.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "headersWithUnderscoresAction": {
+ "description": "HeadersWithUnderscoresAction controls the behavior for a request with a\nheader name containing an underscore character. The default behavior is\nreject_request.",
+ "enum": [
+ "allow",
+ "reject_request",
+ "drop_header"
+ ],
+ "type": "string"
+ },
+ "identityProvider": {
+ "description": "IdentityProvider configure single-sign-on authentication and user identity details\nby integrating with your Identity Provider",
+ "properties": {
+ "provider": {
+ "description": "Provider is the short-hand name of a built-in OpenID Connect (oidc) identity provider to be used for authentication.\nTo use a generic provider, set to oidc.",
+ "enum": [
+ "apple",
+ "auth0",
+ "azure",
+ "cognito",
+ "github",
+ "gitlab",
+ "google",
+ "hosted",
+ "oidc",
+ "okta",
+ "onelogin",
+ "ping"
+ ],
+ "type": "string"
+ },
+ "refreshDirectory": {
+ "description": "RefreshDirectory is no longer supported,\nplease see Upgrade Guide.",
+ "properties": {
+ "interval": {
+ "description": "interval is the time that pomerium will sync your IDP directory.",
+ "format": "duration",
+ "type": "string"
+ },
+ "timeout": {
+ "description": "timeout is the maximum time allowed each run.",
+ "format": "duration",
+ "type": "string"
+ }
+ },
+ "required": [
+ "interval",
+ "timeout"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "requestParams": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "RequestParams to be added as part of a sign-in request using OAuth2 code flow.",
+ "format": "namespace/name",
+ "type": "object"
+ },
+ "requestParamsSecret": {
+ "description": "RequestParamsSecret is a reference to a secret for additional parameters you'd prefer not to provide in plaintext.",
+ "format": "namespace/name",
+ "type": "string"
+ },
+ "scopes": {
+ "description": "Scopes Identity provider scopes correspond to access privilege scopes\nas defined in Section 3.3 of OAuth 2.0 RFC6749.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "secret": {
+ "description": "Secret containing IdP provider specific parameters.\nand must contain at least client_id and client_secret values.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "serviceAccountFromSecret": {
+ "description": "ServiceAccountFromSecret is no longer supported,\nsee Upgrade Guide.",
+ "type": "string"
+ },
+ "url": {
+ "description": "URL is the base path to an identity provider's OpenID connect discovery document.\nSee Identity Providers guides for details.",
+ "format": "uri",
+ "pattern": "^https://",
+ "type": "string"
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "fieldPath": ".secret",
+ "message": "secret is required unless provider is 'hosted'",
+ "reason": "FieldValueRequired",
+ "rule": "self.provider != 'hosted' ? has(self.secret) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "idpAccessTokenAllowedAudiences": {
+ "description": "IDPAccessTokenAllowedAudiences specifies the\nidp access token allowed audiences\nlist.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "jwtClaimHeaders": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "JWTClaimHeaders convert claims from the assertion token\ninto HTTP headers and adds them into JWT assertion header.\nPlease make sure to read\n\nGetting User Identity guide.",
+ "type": "object"
+ },
+ "mcpAllowedAsMetadataDomains": {
+ "description": "MCPAllowedASMetadataDomains specifies the allowed domains for upstream AS/PRM metadata URLs.\nSupports wildcard patterns like \"*.example.com\".\nThis restricts which domains Pomerium will contact during upstream OAuth discovery\n(resource_metadata from WWW-Authenticate, authorization_servers from PRM).\nSee MCP Settings.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "mcpAllowedClientIdDomains": {
+ "description": "MCPAllowedClientIDDomains specifies the allowed domains for MCP client ID metadata URLs.\nThis is required when MCP is enabled.\nSee MCP Settings.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "mergeSlashes": {
+ "description": "MergeSlashes controls whether adjacent slashes in the request URI path\nwill be merged into one. Defaults to true.",
+ "type": "boolean"
+ },
+ "normalizePath": {
+ "description": "NormalizePath controls whether request URI paths will be normalized\naccording to RFC 3986. Defaults to true.",
+ "type": "boolean"
+ },
+ "otel": {
+ "description": "OTEL sets the OpenTelemetry Tracing.",
+ "properties": {
+ "bspMaxExportBatchSize": {
+ "description": "BSPMaxExportBatchSize sets the maximum number of spans to export in a single batch",
+ "format": "int32",
+ "type": "integer"
+ },
+ "bspScheduleDelay": {
+ "description": "BSPScheduleDelay sets interval between two consecutive exports",
+ "format": "duration",
+ "type": "string"
+ },
+ "endpoint": {
+ "description": "An OTLP/gRPC or OTLP/HTTP base endpoint URL with optional port.
Example: `http://localhost:4318`",
+ "type": "string"
+ },
+ "headers": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Extra headers",
+ "type": "object"
+ },
+ "logLevel": {
+ "description": "LogLevel sets the log level for the OpenTelemetry SDK.",
+ "enum": [
+ "trace",
+ "debug",
+ "info",
+ "warn",
+ "error"
+ ],
+ "type": "string"
+ },
+ "protocol": {
+ "description": "Valid values are `\"grpc\"` or `\"http/protobuf\"`.",
+ "enum": [
+ "grpc",
+ "http/protobuf"
+ ],
+ "type": "string"
+ },
+ "resourceAttributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "ResourceAttributes sets the additional attributes to be added to the trace.",
+ "type": "object"
+ },
+ "sampling": {
+ "description": "Sampling sets sampling probability between [0, 1].",
+ "format": "number",
+ "type": "string"
+ },
+ "timeout": {
+ "description": "Export request timeout duration",
+ "format": "duration",
+ "type": "string"
+ }
+ },
+ "required": [
+ "endpoint",
+ "protocol"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "passIdentityHeaders": {
+ "description": "PassIdentityHeaders sets the pass identity headers option.",
+ "type": "boolean"
+ },
+ "pathWithEscapedSlashesAction": {
+ "description": "PathWithEscapedSlashesAction controls the behavior for a request with an\nescaped slash or backslash character in the URI path. This operation will\noccur before path normalization and the merge slashes operation. The\ndefault behavior is reject_request.",
+ "enum": [
+ "keep_unchanged",
+ "reject_request",
+ "unescape_and_redirect",
+ "unescape_and_forward"
+ ],
+ "type": "string"
+ },
+ "programmaticRedirectDomains": {
+ "description": "ProgrammaticRedirectDomains specifies a list of domains that can be used for\nprogrammatic redirects.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "runtimeFlags": {
+ "additionalProperties": {
+ "type": "boolean"
+ },
+ "description": "RuntimeFlags sets the runtime flags to enable/disable certain features.",
+ "type": "object"
+ },
+ "secrets": {
+ "description": "Secrets references a Secret with Pomerium bootstrap parameters.\n\n\n
\n\n\nIn a default Pomerium installation manifest, they would be generated via a\none-time job\nand stored in a pomerium/bootstrap Secret.\nYou may re-run the job to rotate the secrets, or update the Secret values manually.\n
\n\nWhen defining the Secret in a manifest, put raw values in stringData so\nKubernetes base64-encodes them. Use data only when values are already\nbase64-encoded.\n
\n\nExample: stringData.shared_secret and stringData.cookie_secret are\nraw strings, while data.signing_key is base64-encoded.\n
",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "setResponseHeaders": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "SetResponseHeaders specifies a mapping of HTTP Header to be added globally to all managed routes and pomerium's authenticate service.\nSee Set Response Headers",
+ "type": "object"
+ },
+ "ssh": {
+ "description": "SSH sets the ssh settings.",
+ "properties": {
+ "hostKeySecrets": {
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "userCaKeySecret": {
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "storage": {
+ "description": "Storage defines persistent storage for sessions and other data.\nSee Storage for details.\nIf no storage is specified, Pomerium would use a transient in-memory storage (not recommended for production).",
+ "properties": {
+ "file": {
+ "description": "File specifies file storage options.",
+ "properties": {
+ "path": {
+ "description": "Path defines the local file system path to store data.",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "postgres": {
+ "description": "Postgres specifies PostgreSQL database connection parameters",
+ "properties": {
+ "caSecret": {
+ "description": "CASecret should refer to a k8s secret with key ca.crt containing CA certificate\nthat, if specified, would be used to populate sslrootcert parameter of the connection string.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "secret": {
+ "description": "Secret specifies a name of a Secret that must contain\nconnection key. See\nDSN Format and Parameters.\nDo not set sslrootcert, sslcert and sslkey via connection string,\nuse tlsSecret and caSecret CRD options instead.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "tlsSecret": {
+ "description": "TLSSecret should refer to a k8s secret of type kubernetes.io/tls\nand allows to specify an optional client certificate and key,\nby constructing sslcert and sslkey connection string\n\nparameter values.",
+ "format": "namespace/name",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "secret"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeouts": {
+ "description": "Timeout specifies the global timeouts for all routes.",
+ "properties": {
+ "idle": {
+ "description": "Idle specifies the time at which a downstream or upstream connection will be terminated if there are no active streams.",
+ "format": "duration",
+ "type": "string"
+ },
+ "read": {
+ "description": "Read specifies the amount of time for the entire request stream to be received from the client.",
+ "format": "duration",
+ "type": "string"
+ },
+ "write": {
+ "description": "Write specifies max stream duration is the maximum time that a stream\u2019s lifetime will span.\nAn HTTP request/response exchange fully consumes a single stream.\nTherefore, this value must be greater than read_timeout as it covers both request and response time.",
+ "format": "duration",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "useProxyProtocol": {
+ "description": "UseProxyProtocol enables Proxy Protocol support.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "secrets"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "fieldPath": ".authenticate",
+ "message": "authenticate is required if identityProvider is set",
+ "reason": "FieldValueRequired",
+ "rule": "!has(self.identityProvider) || has(self.authenticate)"
+ },
+ {
+ "fieldPath": ".identityProvider",
+ "message": "identityProvider is required if authenticate is set",
+ "reason": "FieldValueRequired",
+ "rule": "!has(self.authenticate) || has(self.identityProvider)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "PomeriumStatus represents configuration and Ingress status.",
+ "properties": {
+ "certificateAutoProvisionStatus": {
+ "description": "Status of certificate auto provisioning.",
+ "properties": {
+ "dataBrokerLastUpdated": {
+ "format": "date-time",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "ingress": {
+ "additionalProperties": {
+ "description": "ResourceStatus represents the outcome of the latest attempt to reconcile\nrelevant Kubernetes resource with Pomerium.",
+ "properties": {
+ "error": {
+ "description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
+ "type": "string"
+ },
+ "observedAt": {
+ "description": "ObservedAt is when last reconciliation attempt was made.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "reconciled": {
+ "description": "Reconciled is whether this object generation was successfully synced with pomerium.",
+ "type": "boolean"
+ },
+ "warnings": {
+ "description": "Warnings while parsing the resource.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "reconciled"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "description": "Routes provide per-Ingress status.",
+ "type": "object"
+ },
+ "settingsStatus": {
+ "description": "SettingsStatus represent most recent main configuration reconciliation status.",
+ "properties": {
+ "error": {
+ "description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
+ "type": "string"
+ },
+ "observedAt": {
+ "description": "ObservedAt is when last reconciliation attempt was made.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "reconciled": {
+ "description": "Reconciled is whether this object generation was successfully synced with pomerium.",
+ "type": "boolean"
+ },
+ "warnings": {
+ "description": "Warnings while parsing the resource.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "reconciled"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/probe-stable-v1.json b/crdSchemas/master-standalone/probe-stable-v1.json
index c8f33e4..73bb196 100644
--- a/crdSchemas/master-standalone/probe-stable-v1.json
+++ b/crdSchemas/master-standalone/probe-stable-v1.json
@@ -164,21 +164,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"metricRelabelings": {
@@ -218,6 +222,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -257,6 +262,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -584,7 +590,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -707,6 +713,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scrapeClass": {
@@ -746,6 +753,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"targets": {
@@ -809,6 +817,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -939,6 +948,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
diff --git a/crdSchemas/master-standalone/prometheus-stable-v1.json b/crdSchemas/master-standalone/prometheus-stable-v1.json
index c679f5c..b28de5d 100644
--- a/crdSchemas/master-standalone/prometheus-stable-v1.json
+++ b/crdSchemas/master-standalone/prometheus-stable-v1.json
@@ -944,6 +944,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -1193,6 +1194,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -2939,7 +2941,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -3296,7 +3298,7 @@
"type": "boolean"
},
"disableCompaction": {
- "description": "disableCompaction when true, the Prometheus compaction is disabled.\nWhen `spec.thanos.objectStorageConfig` or `spec.objectStorageConfigFile` are defined, the operator automatically\ndisables block compaction to avoid race conditions during block uploads (as the Thanos documentation recommends).",
+ "description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.41.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.41.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.",
"type": "boolean"
},
"dnsConfig": {
@@ -3394,21 +3396,25 @@
"enforcedKeepDroppedTargets": {
"description": "enforcedKeepDroppedTargets when defined specifies a global limit on the number of targets\ndropped by relabeling that will be kept in memory. The value overrides\nany `spec.keepDroppedTargets` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.keepDroppedTargets` is\ngreater than zero and less than `spec.enforcedKeepDroppedTargets`.\n\nIt requires Prometheus >= v2.47.0.\n\nWhen both `enforcedKeepDroppedTargets` and `keepDroppedTargets` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined keepDroppedTargets value will inherit the global keepDroppedTargets value (Prometheus >= 2.45.0) or the enforcedKeepDroppedTargets value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedKeepDroppedTargets` is greater than the `keepDroppedTargets`, the `keepDroppedTargets` will be set to `enforcedKeepDroppedTargets`.\n* Scrape objects with a keepDroppedTargets value less than or equal to enforcedKeepDroppedTargets keep their specific value.\n* Scrape objects with a keepDroppedTargets value greater than enforcedKeepDroppedTargets are set to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelLimit": {
"description": "enforcedLabelLimit when defined specifies a global limit on the number\nof labels per sample. The value overrides any `spec.labelLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelLimit` is\ngreater than zero and less than `spec.enforcedLabelLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelLimit` and `labelLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelLimit value will inherit the global labelLimit value (Prometheus >= 2.45.0) or the enforcedLabelLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelLimit` is greater than the `labelLimit`, the `labelLimit` will be set to `enforcedLabelLimit`.\n* Scrape objects with a labelLimit value less than or equal to enforcedLabelLimit keep their specific value.\n* Scrape objects with a labelLimit value greater than enforcedLabelLimit are set to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelNameLengthLimit": {
"description": "enforcedLabelNameLengthLimit when defined specifies a global limit on the length\nof labels name per sample. The value overrides any `spec.labelNameLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelNameLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelNameLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelNameLengthLimit` and `labelNameLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelNameLengthLimit value will inherit the global labelNameLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelNameLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelNameLengthLimit` is greater than the `labelNameLengthLimit`, the `labelNameLengthLimit` will be set to `enforcedLabelNameLengthLimit`.\n* Scrape objects with a labelNameLengthLimit value less than or equal to enforcedLabelNameLengthLimit keep their specific value.\n* Scrape objects with a labelNameLengthLimit value greater than enforcedLabelNameLengthLimit are set to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelValueLengthLimit": {
"description": "enforcedLabelValueLengthLimit when not null defines a global limit on the length\nof labels value per sample. The value overrides any `spec.labelValueLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelValueLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelValueLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelValueLengthLimit` and `labelValueLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelValueLengthLimit value will inherit the global labelValueLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelValueLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelValueLengthLimit` is greater than the `labelValueLengthLimit`, the `labelValueLengthLimit` will be set to `enforcedLabelValueLengthLimit`.\n* Scrape objects with a labelValueLengthLimit value less than or equal to enforcedLabelValueLengthLimit keep their specific value.\n* Scrape objects with a labelValueLengthLimit value greater than enforcedLabelValueLengthLimit are set to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedNamespaceLabel": {
@@ -3418,11 +3424,13 @@
"enforcedSampleLimit": {
"description": "enforcedSampleLimit when defined specifies a global limit on the number\nof scraped samples that will be accepted. This overrides any\n`spec.sampleLimit` set by ServiceMonitor, PodMonitor, Probe objects\nunless `spec.sampleLimit` is greater than zero and less than\n`spec.enforcedSampleLimit`.\n\nIt is meant to be used by admins to keep the overall number of\nsamples/series under a desired limit.\n\nWhen both `enforcedSampleLimit` and `sampleLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined sampleLimit value will inherit the global sampleLimit value (Prometheus >= 2.45.0) or the enforcedSampleLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedSampleLimit` is greater than the `sampleLimit`, the `sampleLimit` will be set to `enforcedSampleLimit`.\n* Scrape objects with a sampleLimit value less than or equal to enforcedSampleLimit keep their specific value.\n* Scrape objects with a sampleLimit value greater than enforcedSampleLimit are set to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedTargetLimit": {
"description": "enforcedTargetLimit when defined specifies a global limit on the number\nof scraped targets. The value overrides any `spec.targetLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.targetLimit` is\ngreater than zero and less than `spec.enforcedTargetLimit`.\n\nIt is meant to be used by admins to to keep the overall number of\ntargets under a desired limit.\n\nWhen both `enforcedTargetLimit` and `targetLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined targetLimit value will inherit the global targetLimit value (Prometheus >= 2.45.0) or the enforcedTargetLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedTargetLimit` is greater than the `targetLimit`, the `targetLimit` will be set to `enforcedTargetLimit`.\n* Scrape objects with a targetLimit value less than or equal to enforcedTargetLimit keep their specific value.\n* Scrape objects with a targetLimit value greater than enforcedTargetLimit are set to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"evaluationInterval": {
@@ -4612,7 +4620,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -4967,21 +4975,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"listenLocal": {
@@ -5066,6 +5078,14 @@
"description": "keepIdentifyingResourceAttributes enables adding `service.name`, `service.namespace` and `service.instance.id`\nresource attributes to the `target_info` metric, on top of converting them into the `instance` and `job` labels.\n\nIt requires Prometheus >= v3.1.0.",
"type": "boolean"
},
+ "labelNamePreserveMultipleUnderscores": {
+ "description": "labelNamePreserveMultipleUnderscores enables preserving of multiple consecutive underscores in label names when translation_strategy uses\nunderscore escaping.\nWhen true (default), multiple consecutive underscores are preserved during label name sanitization.\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
+ "labelNameUnderscoreSanitization": {
+ "description": "labelNameUnderscoreSanitization controls whether to enable prepending of 'key_' to labels starting with '_'.\nReserved labels starting with '__' are not modified.\nThis is only relevant when translation_strategy uses underscore escaping (e.g., \"UnderscoreEscapingWithSuffixes\" or \"UnderscoreEscapingWithoutSuffixes\").\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
"promoteAllResourceAttributes": {
"description": "promoteAllResourceAttributes promotes all resource attributes to metric labels except the ones defined in `ignoreResourceAttributes`.\n\nCannot be true when `promoteResourceAttributes` is defined.\nIt requires Prometheus >= v3.5.0.",
"type": "boolean"
@@ -5870,7 +5890,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6121,7 +6141,8 @@
"additionalProperties": false
},
"url": {
- "description": "url defines the URL of the endpoint to query from.",
+ "description": "url defines the URL of the endpoint to query from.\n\nIt must use the HTTP or HTTPS scheme.",
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6386,7 +6407,7 @@
"type": "integer"
},
"send": {
- "description": "send defines whether metric metadata is sent to the remote storage or not.",
+ "description": "send defines whether metric metadata is sent to the remote storage or not.\n\nThe setting is ignored when Remote Write message's version 2.0 is used.",
"type": "boolean"
},
"sendInterval": {
@@ -6718,7 +6739,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -7144,6 +7165,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -7427,6 +7449,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"schedulerName": {
@@ -7442,7 +7465,7 @@
"description": "attachMetadata defines additional metadata to the discovered targets.\nWhen the scrape object defines its own configuration, it takes\nprecedence over the scrape class configuration.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -7540,6 +7563,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -7614,6 +7638,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -8251,7 +8276,7 @@
"type": "string"
},
"shardRetentionPolicy": {
- "description": "shardRetentionPolicy defines the retention policy for the Prometheus shards.\n(Alpha) Using this field requires the 'PrometheusShardRetentionPolicy' feature gate to be enabled.\n\nThe final goals for this feature can be seen at https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/proposals/202310-shard-autoscaling.md#graceful-scale-down-of-prometheus-servers,\nhowever, the feature is not yet fully implemented in this PR. The limitation being:\n* Retention duration is not settable, for now, shards are retained forever.",
+ "description": "shardRetentionPolicy defines the retention policy for the Prometheus shards.\n\n(Beta) Using this mode requires the `PrometheusShardRetentionPolicy` feature gate (enabled by default).",
"properties": {
"retain": {
"description": "retain defines the config for retention when the retention policy is set\nto `Retain`.\n\nIf not defined, the operator will use the retention duration configured\nfor the Prometheus data. If the resource uses size-based retention, the\nshard(s) are kept forever (unless manually deleted).",
@@ -8321,7 +8346,8 @@
"additionalProperties": false
},
"shards": {
- "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.",
+ "default": 1,
+ "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.\n\nDefault: 1",
"format": "int32",
"type": "integer"
},
@@ -8891,6 +8917,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"terminationGracePeriodSeconds": {
@@ -9751,10 +9778,38 @@
"tsdb": {
"description": "tsdb defines the runtime reloadable configuration of the timeseries database(TSDB).\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"properties": {
+ "chunkEncoding": {
+ "description": "chunkEncoding configures per-chunk-type encoding overrides.\n\nIt requires Prometheus >= v3.13.0.\n\nNotice: Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).",
+ "properties": {
+ "floats": {
+ "description": "floats selects the encoding used for float chunks.\nValid values are \"Xor\" and \"Xor2\".\n\nNotice:\n * Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).\n * Setting \"Xor2\" automatically adds the `xor2-encoding` feature flag.\n\nIt requires Prometheus >= v3.13.0.",
+ "enum": [
+ "Xor",
+ "Xor2"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"outOfOrderTimeWindow": {
"description": "outOfOrderTimeWindow defines how old an out-of-order/out-of-bounds sample can be with\nrespect to the TSDB max time.\n\nAn out-of-order/out-of-bounds sample is ingested into the TSDB as long as\nthe timestamp of the sample is >= (TSDB.MaxTime - outOfOrderTimeWindow).\n\nThis is an *experimental feature*, it may change in any upcoming release\nin a breaking way.\n\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string"
+ },
+ "staleSeriesCompactionThreshold": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "staleSeriesCompactionThreshold configures the trigger point for compacting\nstale series from memory into persistent blocks and removing those stale\nseries from memory.\n\nThe threshold is a number between 0.0 and 1.0. It represents the ratio of\nstale series in memory to the total series in memory. The stale series\ncompaction is triggered when this ratio crosses the configured threshold.\nIt may not trigger the stale series compaction if the usual head compaction\nis about to happen soon.\n\nIf set to 0, stale series compaction is disabled.\n\nIt requires Prometheus >= v3.10.0.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
}
},
"type": "object",
@@ -10601,7 +10656,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -10750,7 +10805,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
diff --git a/crdSchemas/master-standalone/prometheusagent-stable-v1alpha1.json b/crdSchemas/master-standalone/prometheusagent-stable-v1alpha1.json
index 62f5ac3..2a6f001 100644
--- a/crdSchemas/master-standalone/prometheusagent-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/prometheusagent-stable-v1alpha1.json
@@ -2262,7 +2262,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -2709,21 +2709,25 @@
"enforcedKeepDroppedTargets": {
"description": "enforcedKeepDroppedTargets when defined specifies a global limit on the number of targets\ndropped by relabeling that will be kept in memory. The value overrides\nany `spec.keepDroppedTargets` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.keepDroppedTargets` is\ngreater than zero and less than `spec.enforcedKeepDroppedTargets`.\n\nIt requires Prometheus >= v2.47.0.\n\nWhen both `enforcedKeepDroppedTargets` and `keepDroppedTargets` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined keepDroppedTargets value will inherit the global keepDroppedTargets value (Prometheus >= 2.45.0) or the enforcedKeepDroppedTargets value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedKeepDroppedTargets` is greater than the `keepDroppedTargets`, the `keepDroppedTargets` will be set to `enforcedKeepDroppedTargets`.\n* Scrape objects with a keepDroppedTargets value less than or equal to enforcedKeepDroppedTargets keep their specific value.\n* Scrape objects with a keepDroppedTargets value greater than enforcedKeepDroppedTargets are set to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelLimit": {
"description": "enforcedLabelLimit when defined specifies a global limit on the number\nof labels per sample. The value overrides any `spec.labelLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelLimit` is\ngreater than zero and less than `spec.enforcedLabelLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelLimit` and `labelLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelLimit value will inherit the global labelLimit value (Prometheus >= 2.45.0) or the enforcedLabelLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelLimit` is greater than the `labelLimit`, the `labelLimit` will be set to `enforcedLabelLimit`.\n* Scrape objects with a labelLimit value less than or equal to enforcedLabelLimit keep their specific value.\n* Scrape objects with a labelLimit value greater than enforcedLabelLimit are set to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelNameLengthLimit": {
"description": "enforcedLabelNameLengthLimit when defined specifies a global limit on the length\nof labels name per sample. The value overrides any `spec.labelNameLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelNameLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelNameLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelNameLengthLimit` and `labelNameLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelNameLengthLimit value will inherit the global labelNameLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelNameLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelNameLengthLimit` is greater than the `labelNameLengthLimit`, the `labelNameLengthLimit` will be set to `enforcedLabelNameLengthLimit`.\n* Scrape objects with a labelNameLengthLimit value less than or equal to enforcedLabelNameLengthLimit keep their specific value.\n* Scrape objects with a labelNameLengthLimit value greater than enforcedLabelNameLengthLimit are set to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelValueLengthLimit": {
"description": "enforcedLabelValueLengthLimit when not null defines a global limit on the length\nof labels value per sample. The value overrides any `spec.labelValueLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelValueLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelValueLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelValueLengthLimit` and `labelValueLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelValueLengthLimit value will inherit the global labelValueLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelValueLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelValueLengthLimit` is greater than the `labelValueLengthLimit`, the `labelValueLengthLimit` will be set to `enforcedLabelValueLengthLimit`.\n* Scrape objects with a labelValueLengthLimit value less than or equal to enforcedLabelValueLengthLimit keep their specific value.\n* Scrape objects with a labelValueLengthLimit value greater than enforcedLabelValueLengthLimit are set to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedNamespaceLabel": {
@@ -2733,11 +2737,13 @@
"enforcedSampleLimit": {
"description": "enforcedSampleLimit when defined specifies a global limit on the number\nof scraped samples that will be accepted. This overrides any\n`spec.sampleLimit` set by ServiceMonitor, PodMonitor, Probe objects\nunless `spec.sampleLimit` is greater than zero and less than\n`spec.enforcedSampleLimit`.\n\nIt is meant to be used by admins to keep the overall number of\nsamples/series under a desired limit.\n\nWhen both `enforcedSampleLimit` and `sampleLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined sampleLimit value will inherit the global sampleLimit value (Prometheus >= 2.45.0) or the enforcedSampleLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedSampleLimit` is greater than the `sampleLimit`, the `sampleLimit` will be set to `enforcedSampleLimit`.\n* Scrape objects with a sampleLimit value less than or equal to enforcedSampleLimit keep their specific value.\n* Scrape objects with a sampleLimit value greater than enforcedSampleLimit are set to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedTargetLimit": {
"description": "enforcedTargetLimit when defined specifies a global limit on the number\nof scraped targets. The value overrides any `spec.targetLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.targetLimit` is\ngreater than zero and less than `spec.enforcedTargetLimit`.\n\nIt is meant to be used by admins to to keep the overall number of\ntargets under a desired limit.\n\nWhen both `enforcedTargetLimit` and `targetLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined targetLimit value will inherit the global targetLimit value (Prometheus >= 2.45.0) or the enforcedTargetLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedTargetLimit` is greater than the `targetLimit`, the `targetLimit` will be set to `enforcedTargetLimit`.\n* Scrape objects with a targetLimit value less than or equal to enforcedTargetLimit keep their specific value.\n* Scrape objects with a targetLimit value greater than enforcedTargetLimit are set to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"excludedFromEnforcement": {
@@ -3909,7 +3915,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -4264,21 +4270,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"listenLocal": {
@@ -4371,6 +4381,14 @@
"description": "keepIdentifyingResourceAttributes enables adding `service.name`, `service.namespace` and `service.instance.id`\nresource attributes to the `target_info` metric, on top of converting them into the `instance` and `job` labels.\n\nIt requires Prometheus >= v3.1.0.",
"type": "boolean"
},
+ "labelNamePreserveMultipleUnderscores": {
+ "description": "labelNamePreserveMultipleUnderscores enables preserving of multiple consecutive underscores in label names when translation_strategy uses\nunderscore escaping.\nWhen true (default), multiple consecutive underscores are preserved during label name sanitization.\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
+ "labelNameUnderscoreSanitization": {
+ "description": "labelNameUnderscoreSanitization controls whether to enable prepending of 'key_' to labels starting with '_'.\nReserved labels starting with '__' are not modified.\nThis is only relevant when translation_strategy uses underscore escaping (e.g., \"UnderscoreEscapingWithSuffixes\" or \"UnderscoreEscapingWithoutSuffixes\").\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
"promoteAllResourceAttributes": {
"description": "promoteAllResourceAttributes promotes all resource attributes to metric labels except the ones defined in `ignoreResourceAttributes`.\n\nCannot be true when `promoteResourceAttributes` is defined.\nIt requires Prometheus >= v3.5.0.",
"type": "boolean"
@@ -4932,7 +4950,7 @@
"type": "integer"
},
"send": {
- "description": "send defines whether metric metadata is sent to the remote storage or not.",
+ "description": "send defines whether metric metadata is sent to the remote storage or not.\n\nThe setting is ignored when Remote Write message's version 2.0 is used.",
"type": "boolean"
},
"sendInterval": {
@@ -5264,7 +5282,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5690,6 +5708,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -5838,6 +5857,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"schedulerName": {
@@ -5853,7 +5873,7 @@
"description": "attachMetadata defines additional metadata to the discovered targets.\nWhen the scrape object defines its own configuration, it takes\nprecedence over the scrape class configuration.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -5951,6 +5971,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -6025,6 +6046,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -6698,7 +6720,8 @@
"additionalProperties": false
},
"shards": {
- "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.",
+ "default": 1,
+ "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.\n\nDefault: 1",
"format": "int32",
"type": "integer"
},
@@ -7264,6 +7287,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"terminationGracePeriodSeconds": {
@@ -7654,10 +7678,38 @@
"tsdb": {
"description": "tsdb defines the runtime reloadable configuration of the timeseries database(TSDB).\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"properties": {
+ "chunkEncoding": {
+ "description": "chunkEncoding configures per-chunk-type encoding overrides.\n\nIt requires Prometheus >= v3.13.0.\n\nNotice: Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).",
+ "properties": {
+ "floats": {
+ "description": "floats selects the encoding used for float chunks.\nValid values are \"Xor\" and \"Xor2\".\n\nNotice:\n * Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).\n * Setting \"Xor2\" automatically adds the `xor2-encoding` feature flag.\n\nIt requires Prometheus >= v3.13.0.",
+ "enum": [
+ "Xor",
+ "Xor2"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"outOfOrderTimeWindow": {
"description": "outOfOrderTimeWindow defines how old an out-of-order/out-of-bounds sample can be with\nrespect to the TSDB max time.\n\nAn out-of-order/out-of-bounds sample is ingested into the TSDB as long as\nthe timestamp of the sample is >= (TSDB.MaxTime - outOfOrderTimeWindow).\n\nThis is an *experimental feature*, it may change in any upcoming release\nin a breaking way.\n\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string"
+ },
+ "staleSeriesCompactionThreshold": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "staleSeriesCompactionThreshold configures the trigger point for compacting\nstale series from memory into persistent blocks and removing those stale\nseries from memory.\n\nThe threshold is a number between 0.0 and 1.0. It represents the ratio of\nstale series in memory to the total series in memory. The stale series\ncompaction is triggered when this ratio crosses the configured threshold.\nIt may not trigger the stale series compaction if the usual head compaction\nis about to happen soon.\n\nIf set to 0, stale series compaction is disabled.\n\nIt requires Prometheus >= v3.10.0.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
}
},
"type": "object",
@@ -8504,7 +8556,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -8653,7 +8705,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
diff --git a/crdSchemas/master-standalone/referencegrant-stable-v1.json b/crdSchemas/master-standalone/referencegrant-stable-v1.json
new file mode 100644
index 0000000..2097e00
--- /dev/null
+++ b/crdSchemas/master-standalone/referencegrant-stable-v1.json
@@ -0,0 +1,104 @@
+{
+ "description": "ReferenceGrant identifies kinds of resources in other namespaces that are\ntrusted to reference the specified kinds of resources in the same namespace\nas the policy.\n\nEach ReferenceGrant can be used to represent a unique trust relationship.\nAdditional Reference Grants can be used to add to the set of trusted\nsources of inbound references for the namespace they are defined within.\n\nAll cross-namespace references in Gateway API (with the exception of cross-namespace\nGateway-route attachment) require a ReferenceGrant.\n\nReferenceGrant is a form of runtime verification allowing users to assert\nwhich cross-namespace object references are permitted. Implementations that\nsupport ReferenceGrant MUST NOT permit cross-namespace references which have\nno grant, and MUST respond to the removal of a grant by revoking the access\nthat the grant allowed.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of ReferenceGrant.",
+ "properties": {
+ "from": {
+ "description": "From describes the trusted namespaces and kinds that can reference the\nresources described in \"To\". Each entry in this list MUST be considered\nto be an additional place that references can be valid from, or to put\nthis another way, entries MUST be combined using OR.\n\nSupport: Core",
+ "items": {
+ "description": "ReferenceGrantFrom describes trusted namespaces and kinds.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent.\nWhen empty, the Kubernetes core API group is inferred.\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the referent. Although implementations may support\nadditional resources, the following types are part of the \"Core\"\nsupport level for this field.\n\nWhen used to permit a SecretObjectReference:\n\n* Gateway\n\nWhen used to permit a BackendObjectReference:\n\n* GRPCRoute\n* HTTPRoute\n* TCPRoute\n* TLSRoute\n* UDPRoute",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "namespace"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "to": {
+ "description": "To describes the resources that may be referenced by the resources\ndescribed in \"From\". Each entry in this list MUST be considered to be an\nadditional place that references can be valid to, or to put this another\nway, entries MUST be combined using OR.\n\nSupport: Core",
+ "items": {
+ "description": "ReferenceGrantTo describes what Kinds are allowed as targets of the\nreferences.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent.\nWhen empty, the Kubernetes core API group is inferred.\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the kind of the referent. Although implementations may support\nadditional resources, the following types are part of the \"Core\"\nsupport level for this field:\n\n* Secret when used to permit a SecretObjectReference\n* Service when used to permit a BackendObjectReference",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent. When unspecified, this policy\nrefers to all resources of the specified Group and Kind in the local\nnamespace.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "from",
+ "to"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/resourceset-stable-v1.json b/crdSchemas/master-standalone/resourceset-stable-v1.json
index 2ec37dd..e815454 100644
--- a/crdSchemas/master-standalone/resourceset-stable-v1.json
+++ b/crdSchemas/master-standalone/resourceset-stable-v1.json
@@ -204,6 +204,7 @@
"resources": {
"description": "Resources contains the list of Kubernetes resources to reconcile.",
"items": {
+ "type": "object",
"x-kubernetes-preserve-unknown-fields": true
},
"type": "array"
@@ -216,12 +217,73 @@
"description": "The name of the Kubernetes service account to impersonate\nwhen reconciling the generated resources.",
"type": "string"
},
+ "steps": {
+ "description": "Steps contains an ordered list of named steps to reconcile in sequence.\nEach step's resources are applied and health-checked before the next\nstep starts. Mutually exclusive with Resources and ResourcesTemplate.",
+ "items": {
+ "description": "ResourceSetStep defines a named step in the ResourceSet reconciliation\nsequence. The step's resources are applied and health-checked before\nthe next step starts.",
+ "properties": {
+ "name": {
+ "description": "Name of the step, must be unique within the ResourceSet.",
+ "maxLength": 63,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "resources": {
+ "description": "Resources contains the list of Kubernetes resources to reconcile.",
+ "items": {
+ "type": "object",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "type": "array"
+ },
+ "resourcesTemplate": {
+ "description": "ResourcesTemplate is a Go template that generates the list of\nKubernetes resources to reconcile. The template is rendered\nas multi-document YAML, the resources should be separated by '---'.\nWhen both Resources and ResourcesTemplate are set, the resulting\nobjects are merged and deduplicated, with the ones from Resources taking precedence.",
+ "type": "string"
+ },
+ "timeout": {
+ "description": "Timeout is the maximum time to wait for the step's resources to\nbecome ready. When not set, the ResourceSet reconciliation\ntimeout is used.",
+ "pattern": "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of resources or resourcesTemplate must be set",
+ "rule": "has(self.resources) || has(self.resourcesTemplate)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 20,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-validations": [
+ {
+ "message": "step names must be unique",
+ "rule": "self.all(s, self.exists_one(t, t.name == s.name))"
+ }
+ ]
+ },
"wait": {
"description": "Wait instructs the controller to check the health\nof all the reconciled resources.",
"type": "boolean"
}
},
"type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "steps is mutually exclusive with resources and resourcesTemplate",
+ "rule": "!has(self.steps) || (!has(self.resources) && !has(self.resourcesTemplate))"
+ },
+ {
+ "message": "at least one of steps, resources or resourcesTemplate must be set",
+ "rule": "has(self.steps) || has(self.resources) || has(self.resourcesTemplate)"
+ }
+ ],
"additionalProperties": false
},
"status": {
diff --git a/crdSchemas/master-standalone/resourcesetinputprovider-stable-v1.json b/crdSchemas/master-standalone/resourcesetinputprovider-stable-v1.json
index bec2eeb..12702a5 100644
--- a/crdSchemas/master-standalone/resourcesetinputprovider-stable-v1.json
+++ b/crdSchemas/master-standalone/resourcesetinputprovider-stable-v1.json
@@ -162,6 +162,9 @@
"AzureDevOpsBranch",
"AzureDevOpsTag",
"AzureDevOpsPullRequest",
+ "AWSCodeCommitBranch",
+ "AWSCodeCommitTag",
+ "AWSCodeCommitPullRequest",
"GiteaBranch",
"GiteaTag",
"GiteaPullRequest",
@@ -197,8 +200,12 @@
"rule": "!self.type.startsWith('Git') || self.url.startsWith('http')"
},
{
- "message": "spec.url must start with 'http://' or 'https://' when spec.type is a Git provider",
- "rule": "!self.type.startsWith('AzureDevOps') || self.url.startsWith('http')"
+ "message": "spec.url must start with 'http://' or 'https://' when spec.type is an AzureDevOps provider",
+ "rule": "!self.type.startsWith('AzureDevOps') || self.url.startsWith('http://') || self.url.startsWith('https://')"
+ },
+ {
+ "message": "spec.url must start with 'https://' when spec.type is a AWSCodeCommit provider",
+ "rule": "!self.type.startsWith('AWSCodeCommit') || self.url.startsWith('https://')"
},
{
"message": "spec.url must start with 'oci://' when spec.type is an OCI provider",
@@ -217,16 +224,16 @@
"rule": "self.type != 'ExternalService' || !self.url.startsWith('http://') || (has(self.insecure) && self.insecure)"
},
{
- "message": "cannot specify spec.serviceAccountName when spec.type is not one of AzureDevOps* or *ArtifactTag",
- "rule": "!has(self.serviceAccountName) || self.type.startsWith('AzureDevOps') || self.type.endsWith('ArtifactTag')"
+ "message": "cannot specify spec.serviceAccountName when spec.type is not one of AzureDevOps*, AWSCodeCommit* or *ArtifactTag",
+ "rule": "!has(self.serviceAccountName) || self.type.startsWith('AzureDevOps') || self.type.startsWith('AWSCodeCommit') || self.type.endsWith('ArtifactTag')"
},
{
- "message": "cannot specify spec.certSecretRef when spec.type is one of Static, AzureDevOps*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
- "rule": "!has(self.certSecretRef) || !(self.url == 'Static' || self.type.startsWith('AzureDevOps') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
+ "message": "cannot specify spec.certSecretRef when spec.type is one of Static, AzureDevOps*, AWSCodeCommit*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
+ "rule": "!has(self.certSecretRef) || !(self.type == 'Static' || self.type.startsWith('AzureDevOps') || self.type.startsWith('AWSCodeCommit') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
},
{
- "message": "cannot specify spec.secretRef when spec.type is one of Static, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
- "rule": "!has(self.secretRef) || !(self.url == 'Static' || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
+ "message": "cannot specify spec.secretRef when spec.type is one of Static, AWSCodeCommit*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
+ "rule": "!has(self.secretRef) || !(self.type == 'Static' || self.type.startsWith('AWSCodeCommit') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
}
],
"additionalProperties": false
diff --git a/crdSchemas/master-standalone/scrapeconfig-stable-v1alpha1.json b/crdSchemas/master-standalone/scrapeconfig-stable-v1alpha1.json
index 75a7ec3..0734c3f 100644
--- a/crdSchemas/master-standalone/scrapeconfig-stable-v1alpha1.json
+++ b/crdSchemas/master-standalone/scrapeconfig-stable-v1alpha1.json
@@ -513,7 +513,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -1282,7 +1282,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -1956,7 +1956,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -2710,7 +2710,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -3411,7 +3411,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -4428,7 +4428,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5181,7 +5181,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5861,7 +5861,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6471,7 +6471,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6723,6 +6723,7 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"kubernetesSDConfigs": {
@@ -7179,7 +7180,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -7891,7 +7892,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -8135,16 +8136,19 @@
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"lightSailSDConfigs": {
@@ -8595,7 +8599,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9233,7 +9237,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9520,6 +9524,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -9579,6 +9584,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -10026,7 +10032,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -10589,7 +10595,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -11483,7 +11489,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -11774,6 +11780,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -11810,6 +11817,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scalewaySDConfigs": {
@@ -12216,6 +12224,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"tlsConfig": {
diff --git a/crdSchemas/master-standalone/securitypolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/securitypolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..f55b400
--- /dev/null
+++ b/crdSchemas/master-standalone/securitypolicy-stable-v1alpha1.json
@@ -0,0 +1,7022 @@
+{
+ "description": "SecurityPolicy allows the user to configure various security settings for a\nGateway.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of SecurityPolicy.",
+ "properties": {
+ "apiKeyAuth": {
+ "description": "APIKeyAuth defines the configuration for the API Key Authentication.",
+ "properties": {
+ "credentialRefs": {
+ "description": "CredentialRefs is the Kubernetes secret which contains the API keys.\nThis is an Opaque secret.\nEach API key is stored in the key representing the client id.\nIf the secrets have a key for a duplicated client, the first one will be used.",
+ "items": {
+ "description": "SecretObjectReference identifies an API object including its namespace,\ndefaulting to Secret.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.\n\nReferences to objects with invalid Group and Kind are not valid, and must\nbe rejected by the implementation, with appropriate Conditions set\non the containing object.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "extractFrom": {
+ "description": "ExtractFrom is where to fetch the key from the coming request.\nThe value from the first source that has a key will be used.",
+ "items": {
+ "description": "ExtractFrom is where to fetch the key from the coming request.\nOnly one of headers, params or cookies must be specified.",
+ "properties": {
+ "cookies": {
+ "description": "Cookies is the names of the cookie to fetch the key from.\nIf multiple cookies are specified, envoy will look for the api key in the order of the list.\nThis field is optional, but only one of headers, params or cookies must be specified.",
+ "items": {
+ "minLength": 1,
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "headers": {
+ "description": "Headers is the names of the header to fetch the key from.\nIf multiple headers are specified, envoy will look for the api key in the order of the list.\nThis field is optional, but only one of headers, params or cookies must be specified.",
+ "items": {
+ "minLength": 1,
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "params": {
+ "description": "Params is the names of the query parameter to fetch the key from.\nIf multiple params are specified, envoy will look for the api key in the order of the list.\nThis field is optional, but only one of headers, params or cookies must be specified.",
+ "items": {
+ "minLength": 1,
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "exactly one of headers, params, or cookies must be specified",
+ "rule": "(has(self.headers) ? 1 : 0) + (has(self.params) ? 1 : 0) + (has(self.cookies) ? 1 : 0) == 1"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "forwardClientIDHeader": {
+ "description": "ForwardClientIDHeader is the name of the header to forward the client identity to the backend\nservice. The header will be added to the request with the client id as the value.",
+ "type": "string"
+ },
+ "sanitize": {
+ "description": "Sanitize indicates whether to remove the API key from the request before forwarding it to the backend service.",
+ "type": "boolean"
+ }
+ },
+ "required": [
+ "credentialRefs",
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "authorization": {
+ "description": "Authorization defines the authorization configuration.",
+ "properties": {
+ "defaultAction": {
+ "description": "DefaultAction defines the default action to be taken if no rules match.\nIf not specified, the default action is Deny.",
+ "enum": [
+ "Allow",
+ "Deny"
+ ],
+ "type": "string"
+ },
+ "rules": {
+ "description": "Rules defines a list of authorization rules.\nThese rules are evaluated in order, the first matching rule will be applied,\nand the rest will be skipped.\n\nFor example, if there are two rules: the first rule allows the request\nand the second rule denies it, when a request matches both rules, it will be allowed.",
+ "items": {
+ "description": "AuthorizationRule defines a single authorization rule.",
+ "properties": {
+ "action": {
+ "description": "Action defines the action to be taken if the rule matches.",
+ "enum": [
+ "Allow",
+ "Deny"
+ ],
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is a user-friendly name for the rule.\nIf not specified, Envoy Gateway will generate a unique name for the rule.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "operation": {
+ "description": "Operation specifies the operation of a request, such as HTTP methods.\nIf not specified, all operations are matched on.",
+ "properties": {
+ "methods": {
+ "description": "Methods are the HTTP methods of the request.\nIf multiple methods are specified, all specified methods are allowed or denied, based on the action of the rule.",
+ "items": {
+ "description": "HTTPMethod describes how to select a HTTP route by matching the HTTP\nmethod as defined by\n[RFC 7231](https://datatracker.ietf.org/doc/html/rfc7231#section-4) and\n[RFC 5789](https://datatracker.ietf.org/doc/html/rfc5789#section-2).\nThe value is expected in upper case.\n\nNote that values may be added to this enum, implementations\nmust ensure that unknown values will not cause a crash.\n\nUnknown values here must result in the implementation setting the\nAccepted Condition for the Route to `status: False`, with a\nReason of `UnsupportedValue`.",
+ "enum": [
+ "GET",
+ "HEAD",
+ "POST",
+ "PUT",
+ "DELETE",
+ "CONNECT",
+ "OPTIONS",
+ "TRACE",
+ "PATCH"
+ ],
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "methods"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "principal": {
+ "description": "Principal specifies the client identity of a request.\nIf there are multiple principal types, all principals must match for the rule to match.\nFor example, if there are two principals: one for client IP and one for JWT claim,\nthe rule will match only if both the client IP and the JWT claim match.",
+ "properties": {
+ "clientCIDRs": {
+ "description": "ClientCIDRs are the IP CIDR ranges of the client.\nValid examples are \"192.168.1.0/24\" or \"2001:db8::/64\"\n\nIf multiple CIDR ranges are specified, one of the CIDR ranges must match\nthe client IP for the rule to match.\n\nThe client IP is inferred from the X-Forwarded-For header, a custom header,\nor the proxy protocol.\nYou can use the `ClientIPDetection` or the `ProxyProtocol` field in\nthe `ClientTrafficPolicy` to configure how the client IP is detected.\n\nFor TCPRoute targets (raw TCP connections), HTTP headers such as\nX-Forwarded-For are not available. The client IP is obtained from the\nTCP connection's peer address. If intermediaries (load balancers, NAT)\nterminate or proxy TCP, the original client IP will only be available\nif the intermediary preserves the source address (for example by\nenabling the PROXY protocol or avoiding SNAT). Ensure your L4 proxy is\nconfigured to preserve the source IP to enable correct client-IP\nmatching for TCPRoute targets.",
+ "items": {
+ "description": "CIDR defines a CIDR Address range.\nA CIDR can be an IPv4 address range such as \"192.168.1.0/24\" or an IPv6 address range such as \"2001:0db8:11a3:09d7::/64\".",
+ "pattern": "((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]+))|((([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))\\/([0-9]+))",
+ "type": "string"
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "clientIPGeoLocations": {
+ "description": "ClientIPGeoLocations authorizes the request based on geolocation metadata derived from the client IP.\nThis field is supported for HTTPRoute and GRPCRoute authorization.\nIt is not supported for TCPRoute targets.\n\nIf multiple entries are specified, one of the ClientIPGeoLocation entries must match for the rule to match.\n\nThe client IP is inferred from the X-Forwarded-For header or a custom header.\nYou can use the `ClientIPDetection` field in the `ClientTrafficPolicy` to configure the client IP detection.",
+ "items": {
+ "description": "ClientIPGeoLocation specifies geolocation-based match criteria for authorization.",
+ "properties": {
+ "anonymous": {
+ "description": "Anonymous matches anonymous network detection signals.",
+ "properties": {
+ "isAnonymous": {
+ "description": "IsAnonymous matches whether the client IP is considered anonymous.",
+ "type": "boolean"
+ },
+ "isHosting": {
+ "description": "IsHosting matches whether the client IP belongs to a hosting provider.",
+ "type": "boolean"
+ },
+ "isProxy": {
+ "description": "IsProxy matches whether the client IP belongs to a public proxy.",
+ "type": "boolean"
+ },
+ "isTor": {
+ "description": "IsTor matches whether the client IP belongs to a Tor exit node.",
+ "type": "boolean"
+ },
+ "isVPN": {
+ "description": "IsVPN matches whether the client IP is detected as VPN.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of isAnonymous, isVPN, isHosting, isTor, or isProxy must be specified",
+ "rule": "has(self.isAnonymous) || has(self.isVPN) || has(self.isHosting) || has(self.isTor) || has(self.isProxy)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "asn": {
+ "description": "ASN is the autonomous system number associated with the client IP.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "city": {
+ "description": "City is the city associated with the client IP.",
+ "maxLength": 128,
+ "minLength": 1,
+ "type": "string"
+ },
+ "country": {
+ "description": "Country is the country ISO code associated with the client IP.",
+ "maxLength": 2,
+ "minLength": 2,
+ "pattern": "^[A-Za-z]{2}$",
+ "type": "string"
+ },
+ "isp": {
+ "description": "ISP is the internet service provider associated with the client IP.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "region": {
+ "description": "Region is the region ISO code associated with the client IP.",
+ "maxLength": 16,
+ "minLength": 1,
+ "pattern": "^[A-Za-z0-9-]+$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of country, region, city, asn, isp, or anonymous must be specified",
+ "rule": "has(self.country) || has(self.region) || has(self.city) || has(self.asn) || has(self.isp) || has(self.anonymous)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "minItems": 1,
+ "type": "array"
+ },
+ "headers": {
+ "description": "Headers authorize the request based on user identity extracted from custom headers.\nIf multiple headers are specified, all headers must match for the rule to match.",
+ "items": {
+ "description": "AuthorizationHeaderMatch specifies how to match against the value of an HTTP header within a authorization rule.",
+ "properties": {
+ "name": {
+ "description": "Name of the HTTP header.\nThe header name is case-insensitive unless PreserveHeaderCase is set to true.\nFor example, \"Foo\" and \"foo\" are considered the same header.",
+ "maxLength": 256,
+ "minLength": 1,
+ "type": "string"
+ },
+ "values": {
+ "description": "Values are the values that the header must match.\nIf multiple values are specified, the rule will match if any of the values match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 256,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "name",
+ "values"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 256,
+ "minItems": 1,
+ "type": "array"
+ },
+ "jwt": {
+ "description": "JWT authorize the request based on the JWT claims and scopes.\nNote: in order to use JWT claims for authorization, you must configure the\nJWT authentication in the same `SecurityPolicy`.",
+ "properties": {
+ "claims": {
+ "description": "Claims are the claims in a JWT token.\n\nIf multiple claims are specified, all claims must match for the rule to match.\nFor example, if there are two claims: one for the audience and one for the issuer,\nthe rule will match only if both the audience and the issuer match.",
+ "items": {
+ "description": "JWTClaim specifies a claim in a JWT token.",
+ "properties": {
+ "name": {
+ "description": "Name is the name of the claim.\nIf it is a nested claim, use a dot (.) separated string as the name to\nrepresent the full path to the claim.\nFor example, if the claim is in the \"department\" field in the \"organization\" field,\nthe name should be \"organization.department\".",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "valueType": {
+ "default": "String",
+ "description": "ValueType is the type of the claim value.\nOnly String and StringArray types are supported for now.",
+ "enum": [
+ "String",
+ "StringArray"
+ ],
+ "type": "string"
+ },
+ "values": {
+ "description": "Values are the values that the claim must match.\nIf the claim is a string type, the specified value must match exactly.\nIf the claim is a string array type, the specified value must match one of the values in the array.\nIf multiple values are specified, one of the values must match for the rule to match.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 128,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "name",
+ "values"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ },
+ "provider": {
+ "description": "Provider is the name of the JWT provider that used to verify the JWT token.\nIn order to use JWT claims for authorization, you must configure the JWT\nauthentication with the same provider in the same `SecurityPolicy`.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "scopes": {
+ "description": "Scopes are a special type of claim in a JWT token that represents the permissions of the client.\n\nThe value of the scopes field should be a space delimited string that is expected in the\nscope (or scp) claim, as defined in RFC 6749: https://datatracker.ietf.org/doc/html/rfc6749#page-23.\n\nIf multiple scopes are specified, all scopes must match for the rule to match.",
+ "items": {
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of claims or scopes must be specified",
+ "rule": "(has(self.claims) || has(self.scopes))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "at least one of clientCIDRs, jwt, headers, or clientIPGeoLocations must be specified",
+ "rule": "(has(self.clientCIDRs) || has(self.jwt) || has(self.headers) || has(self.clientIPGeoLocations))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "action",
+ "principal"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "basicAuth": {
+ "description": "BasicAuth defines the configuration for the HTTP Basic Authentication.",
+ "properties": {
+ "forwardUsernameHeader": {
+ "description": "This field specifies the header name to forward a successfully authenticated user to\nthe backend. The header will be added to the request with the username as the value.\n\nIf it is not specified, the username will not be forwarded.",
+ "type": "string"
+ },
+ "users": {
+ "description": "The Kubernetes secret which contains the username-password pairs in\nhtpasswd format, used to verify user credentials in the \"Authorization\"\nheader.\n\nThis is an Opaque secret. The username-password pairs should be stored in\nthe key \".htpasswd\". As the key name indicates, the value needs to be the\nhtpasswd format, for example: \"user1:{SHA}hashed_user1_password\".\nRight now, only SHA hash algorithm is supported.\nReference to https://httpd.apache.org/docs/2.4/programs/htpasswd.html\nfor more details.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "users"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cors": {
+ "description": "CORS defines the configuration for Cross-Origin Resource Sharing (CORS).",
+ "properties": {
+ "allowCredentials": {
+ "description": "AllowCredentials indicates whether a request can include user credentials\nlike cookies, authentication headers, or TLS client certificates.\nIt specifies the value in the Access-Control-Allow-Credentials CORS response header.",
+ "type": "boolean"
+ },
+ "allowHeaders": {
+ "description": "AllowHeaders defines the headers that are allowed to be sent with requests.\nIt specifies the allowed headers in the Access-Control-Allow-Headers CORS response header..\nThe value \"*\" allows any header to be sent.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "allowMethods": {
+ "description": "AllowMethods defines the methods that are allowed to make requests.\nIt specifies the allowed methods in the Access-Control-Allow-Methods CORS response header..\nThe value \"*\" allows any method to be used.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "allowOrigins": {
+ "description": "AllowOrigins defines the origins that are allowed to make requests.\nIt specifies the allowed origins in the Access-Control-Allow-Origin CORS response header.\nThe value \"*\" allows any origin to make requests.",
+ "items": {
+ "description": "Origin is defined by the scheme (protocol), hostname (domain), and port of\nthe URL used to access it. The hostname can be \"precise\" which is just the\ndomain name or \"wildcard\" which is a domain name prefixed with a single\nwildcard label such as \"*.example.com\".\nIn addition to that a single wildcard (with or without scheme) can be\nconfigured to match any origin.\n\nFor example, the following are valid origins:\n- https://foo.example.com\n- https://*.example.com\n- http://foo.example.com:8080\n- http://*.example.com:8080\n- https://*",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*|https?:\\/\\/(\\*|(\\*\\.)?(([\\w-]+\\.?)+)?[\\w-]+)(:\\d{1,5})?)$",
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "exposeHeaders": {
+ "description": "ExposeHeaders defines which response headers should be made accessible to\nscripts running in the browser.\nIt specifies the headers in the Access-Control-Expose-Headers CORS response header..\nThe value \"*\" allows any header to be exposed.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "maxAge": {
+ "description": "MaxAge defines how long the results of a preflight request can be cached.\nIt specifies the value in the Access-Control-Max-Age CORS response header..",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "extAuth": {
+ "description": "ExtAuth defines the configuration for External Authorization.",
+ "properties": {
+ "bodyToExtAuth": {
+ "description": "BodyToExtAuth defines the Body to Ext Auth configuration.",
+ "properties": {
+ "maxRequestBytes": {
+ "description": "MaxRequestBytes is the maximum size of a message body that the filter will hold in memory.\nEnvoy will return HTTP 413 and will not initiate the authorization process when buffer\nreaches the number set in this field.\nNote that this setting will have precedence over failOpen mode.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "maxRequestBytes"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "contextExtensions": {
+ "description": "ContextExtensions are analogous to http_request.headers, however these\ncontents will not be sent to the upstream server. This provides an\nextension mechanism for sending additional information to the auth server\nwithout modifying the proto definition. It maps to the internal opaque\ncontext in the filter chain.",
+ "items": {
+ "description": "ContextExtension is analogous to http_request.headers, however these\ncontents will not be sent to the upstream server. This provides an\nextension mechanism for sending additional information to the auth server\nwithout modifying the proto definition. It maps to the internal opaque\ncontext in the filter chain.",
+ "properties": {
+ "name": {
+ "description": "Name of the context extension.",
+ "type": "string"
+ },
+ "type": {
+ "default": "Value",
+ "description": "Type is the type of method to use to read the ContextExtension value.\nValid values are Value and ValueRef, default is Value.",
+ "enum": [
+ "Value",
+ "ValueRef"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value of the context extension.",
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef for the context extension's value.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "key": {
+ "description": "The key to select.",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "key",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Only a reference to an object of kind ConfigMap or Secret belonging to default v1 API group is supported.",
+ "rule": "self.kind in ['ConfigMap', 'Secret'] && self.group in ['', 'v1']"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name",
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Exactly one of value or valueRef must be set with correct type.",
+ "rule": "(self.type == 'Value' && has(self.value) && !has(self.valueRef)) || (self.type == 'ValueRef' && !has(self.value) && has(self.valueRef))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "failOpen": {
+ "default": false,
+ "description": "FailOpen is a switch used to control the behavior when a response from the External Authorization service cannot be obtained.\nIf FailOpen is set to true, the system allows the traffic to pass through.\nOtherwise, if it is set to false or not set (defaulting to false),\nthe system blocks the traffic and returns a HTTP 5xx error, reflecting a fail-closed approach.\nThis setting determines whether to prioritize accessibility over strict security in case of authorization service failure.\n\nIf set to true, the External Authorization will also be bypassed if its configuration is invalid.",
+ "type": "boolean"
+ },
+ "grpc": {
+ "description": "GRPC defines the gRPC External Authorization service.\nEither GRPCService or HTTPService must be specified,\nand only one of them can be provided.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "backendRef or backendRefs needs to be set",
+ "rule": "has(self.backendRef) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs only supports Service, ServiceImport, and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'ServiceImport' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only supports Core, multicluster.x-k8s.io, and gateway.envoyproxy.io groups.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'multicluster.x-k8s.io' || f.group == 'gateway.envoyproxy.io')) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headersToExtAuth": {
+ "description": "HeadersToExtAuth defines the client request headers that will be included\nin the request to the external authorization service.\nNote: If not specified, the default behavior for gRPC and HTTP external\nauthorization services is different due to backward compatibility reasons.\nAll headers will be included in the check request to a gRPC authorization server.\nOnly the following headers will be included in the check request to an HTTP\nauthorization server: Host, Method, Path, Content-Length, and Authorization.\nAnd these headers will always be included to the check request to an HTTP\nauthorization server by default, no matter whether they are specified\nin HeadersToExtAuth or not.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "http": {
+ "description": "HTTP defines the HTTP External Authorization service.\nEither GRPCService or HTTPService must be specified,\nand only one of them can be provided.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "headersToBackend": {
+ "description": "HeadersToBackend are the authorization response headers that will be added\nto the original client request before sending it to the backend server.\nNote that coexisting headers will be overridden.\nIf not specified, no authorization response headers will be added to the\noriginal client request.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "path": {
+ "description": "Path is the path of the HTTP External Authorization service.\nIf path is specified, the authorization request will be sent to that path,\nor else the authorization request will use the path of the original request.\n\nPlease note that the original request path will be appended to the path specified here.\nFor example, if the original request path is \"/hello\", and the path specified here is \"/auth\",\nthen the path of the authorization request will be \"/auth/hello\". If the path is not specified,\nthe path of the authorization request will be \"/hello\".\nOnly one of Path or PathOverride can be set.",
+ "type": "string"
+ },
+ "pathOverride": {
+ "description": "PathOverride replaces the original request path in the authorization request.\nIf set, the path will be overridden to this value during authorization.\nFor example, if the original request path is \"/hello\", and PathOverride is set to \"/auth\",\nthen the path of the authorization request will be \"/auth\".\nOnly one of Path or PathOverride can be set.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "backendRef or backendRefs needs to be set",
+ "rule": "has(self.backendRef) || self.backendRefs.size() > 0"
+ },
+ {
+ "message": "BackendRefs only supports Service, ServiceImport, and Backend kind.",
+ "rule": "has(self.backendRefs) ? self.backendRefs.all(f, f.kind == 'Service' || f.kind == 'ServiceImport' || f.kind == 'Backend') : true"
+ },
+ {
+ "message": "BackendRefs only supports Core, multicluster.x-k8s.io, and gateway.envoyproxy.io groups.",
+ "rule": "has(self.backendRefs) ? (self.backendRefs.all(f, f.group == \"\" || f.group == 'multicluster.x-k8s.io' || f.group == 'gateway.envoyproxy.io')) : true"
+ },
+ {
+ "message": "only one of path or pathOverride can be specified",
+ "rule": "!(has(self.path) && has(self.pathOverride))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "includeRouteMetadata": {
+ "description": "IncludeRouteMetadata sends Envoy Gateway's built-in route metadata to the\nexternal authorization service as context.\n\nThis includes Envoy Gateway's built-in metadata for the selected route in\nthe \"envoy-gateway\" metadata namespace.\n\nThe metadata is exposed under the \"resources\" field as a list of route\nresource objects. For example:\n\nenvoy-gateway:\n resources:\n - kind: HTTPRoute\n name: backend\n namespace: default\n annotations:\n foo: bar\n\nThe resource object may include fields such as kind, namespace, name,\nsectionName, and supported route annotations.",
+ "type": "boolean"
+ },
+ "recomputeRoute": {
+ "description": "RecomputeRoute clears the route cache and recalculates the routing decision.\nThis field must be enabled if the headers added or modified by the ExtAuth are used for\nroute matching decisions. If the recomputation selects a new route, features targeting\nthe new matched route will be applied.",
+ "type": "boolean"
+ },
+ "statusOnError": {
+ "description": "Sets the HTTP status that is returned when the authorization service returns an error\nor cannot be reached. Defaults to 403 Forbidden.\nOnly 4xx and 5xx status codes are supported.",
+ "enum": [
+ 400,
+ 401,
+ 402,
+ 403,
+ 404,
+ 405,
+ 406,
+ 407,
+ 408,
+ 409,
+ 410,
+ 411,
+ 412,
+ 413,
+ 414,
+ 415,
+ 416,
+ 417,
+ 421,
+ 422,
+ 423,
+ 424,
+ 426,
+ 428,
+ 429,
+ 431,
+ 500,
+ 501,
+ 502,
+ 503,
+ 504,
+ 505,
+ 506,
+ 507,
+ 508,
+ 510,
+ 511
+ ],
+ "format": "int32",
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout defines the timeout for requests to the external authorization service.\nIf not specified, defaults to 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "one of grpc or http must be specified",
+ "rule": "(has(self.grpc) || has(self.http))"
+ },
+ {
+ "message": "only one of grpc or http can be specified",
+ "rule": "(has(self.grpc) && !has(self.http)) || (!has(self.grpc) && has(self.http))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "jwt": {
+ "description": "JWT defines the configuration for JSON Web Token (JWT) authentication.",
+ "properties": {
+ "optional": {
+ "description": "Optional determines whether a missing JWT is acceptable, defaulting to false if not specified.\nNote: Even if optional is set to true, JWT authentication will still fail if an invalid JWT is presented.",
+ "type": "boolean"
+ },
+ "providers": {
+ "description": "Providers defines the JSON Web Token (JWT) authentication provider type.\nWhen multiple JWT providers are specified, the JWT is considered valid if\nany of the providers successfully validate the JWT. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/jwt_authn_filter.html.",
+ "items": {
+ "description": "JWTProvider defines how a JSON Web Token (JWT) can be verified.",
+ "properties": {
+ "audiences": {
+ "description": "Audiences is a list of JWT audiences allowed access. For additional details, see\nhttps://tools.ietf.org/html/rfc7519#section-4.1.3. If not provided, JWT audiences\nare not checked.",
+ "items": {
+ "type": "string"
+ },
+ "maxItems": 8,
+ "type": "array"
+ },
+ "claimToHeaders": {
+ "description": "ClaimToHeaders is a list of JWT claims that must be extracted into HTTP request headers\nFor examples, following config:\nThe claim must be of type; string, int, double, bool. Array type claims are not supported",
+ "items": {
+ "description": "ClaimToHeader defines a configuration to convert JWT claims into HTTP headers",
+ "properties": {
+ "claim": {
+ "description": "Claim is the JWT Claim that should be saved into the header : it can be a nested claim of type\n(eg. \"claim.nested.key\", \"sub\"). The nested claim name must use dot \".\"\nto separate the JSON name path.",
+ "type": "string"
+ },
+ "header": {
+ "description": "Header defines the name of the HTTP request header that the JWT Claim will be saved into.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "claim",
+ "header"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "extractFrom": {
+ "description": "ExtractFrom defines different ways to extract the JWT token from HTTP request.\nIf empty, it defaults to extract JWT token from the Authorization HTTP request header using Bearer schema\nor access_token from query parameters.",
+ "properties": {
+ "cookies": {
+ "description": "Cookies represents a list of cookie names to extract the JWT token from.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "headers": {
+ "description": "Headers represents a list of HTTP request headers to extract the JWT token from.",
+ "items": {
+ "description": "JWTHeaderExtractor defines an HTTP header location to extract JWT token",
+ "properties": {
+ "name": {
+ "description": "Name is the HTTP header name to retrieve the token",
+ "type": "string"
+ },
+ "valuePrefix": {
+ "description": "ValuePrefix is the prefix that should be stripped before extracting the token.\nThe format would be used by Envoy like \"{ValuePrefix}\".\nFor example, \"Authorization: Bearer \", then the ValuePrefix=\"Bearer \" with a space at the end.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "params": {
+ "description": "Params represents a list of query parameters to extract the JWT token from.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "issuer": {
+ "description": "Issuer is the principal that issued the JWT and takes the form of a URL or email address.\nFor additional details, see https://tools.ietf.org/html/rfc7519#section-4.1.1 for\nURL format and https://rfc-editor.org/rfc/rfc5322.html for email format. If not provided,\nthe JWT issuer is not checked.",
+ "maxLength": 253,
+ "type": "string"
+ },
+ "localJWKS": {
+ "description": "LocalJWKS defines how to get the JSON Web Key Sets (JWKS) from a local source.",
+ "properties": {
+ "inline": {
+ "description": "Inline contains the value as an inline string.",
+ "type": "string"
+ },
+ "type": {
+ "default": "Inline",
+ "description": "Type is the type of method to use to read the body value.\nValid values are Inline and ValueRef, default is Inline.",
+ "enum": [
+ "Inline",
+ "ValueRef"
+ ],
+ "type": "string"
+ },
+ "valueRef": {
+ "description": "ValueRef is a reference to a local ConfigMap that contains the JSON Web Key Sets (JWKS).\n\nThe value of key `jwks` in the ConfigMap will be used.\nIf the key is not found, the first value in the ConfigMap will be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent. For example \"HTTPRoute\" or \"Service\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Exactly one of inline or valueRef must be set with correct type.",
+ "rule": "(self.type == 'Inline' && has(self.inline) && !has(self.valueRef)) || (self.type == 'ValueRef' && !has(self.inline) && has(self.valueRef))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "name": {
+ "description": "Name defines a unique name for the JWT provider. A name can have a variety of forms,\nincluding RFC1123 subdomains, RFC 1123 labels, or RFC 1035 labels.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "recomputeRoute": {
+ "description": "RecomputeRoute clears the route cache and recalculates the routing decision.\nThis field must be enabled if the headers generated from the claim are used for\nroute matching decisions. If the recomputation selects a new route, features targeting\nthe new matched route will be applied.",
+ "type": "boolean"
+ },
+ "remoteJWKS": {
+ "description": "RemoteJWKS defines how to fetch and cache JSON Web Key Sets (JWKS) from a remote\nHTTP/HTTPS endpoint.",
+ "properties": {
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "cacheDuration": {
+ "default": "300s",
+ "description": "Duration is a string value representing a duration in time. The format is as specified\nin GEP-2257, a strict subset of the syntax parsed by Golang time.ParseDuration.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "uri": {
+ "description": "URI is the HTTPS URI to fetch the JWKS. Envoy's system trust bundle is used to validate the server certificate.\nIf a custom trust bundle is needed, it can be specified in a BackendTLSConfig resource and target the BackendRefs.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "uri"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "Retry timeout is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.perRetry)? !has(self.backendSettings.retry.perRetry.timeout):true):true):true"
+ },
+ {
+ "message": "HTTPStatusCodes is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.retryOn)? !has(self.backendSettings.retry.retryOn.httpStatusCodes):true):true):true"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "claimToHeaders must be specified if recomputeRoute is enabled.",
+ "rule": "(has(self.recomputeRoute) && self.recomputeRoute) ? size(self.claimToHeaders) > 0 : true"
+ },
+ {
+ "message": "either remoteJWKS or localJWKS must be specified.",
+ "rule": "has(self.remoteJWKS) || has(self.localJWKS)"
+ },
+ {
+ "message": "remoteJWKS and localJWKS cannot both be specified.",
+ "rule": "!(has(self.remoteJWKS) && has(self.localJWKS))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "providers"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "mergeType": {
+ "description": "MergeType determines how this configuration is merged with existing SecurityPolicy\nconfigurations targeting a parent resource. When set, this configuration will be merged\ninto a parent SecurityPolicy (i.e. the one targeting a Gateway or Listener).\nThis field cannot be set when targeting a parent resource (Gateway).\nIf unset, no merging occurs, and only the most specific configuration takes effect.",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Replace is not a valid MergeType for SecurityPolicy",
+ "rule": "self != 'Replace'"
+ }
+ ]
+ },
+ "oidc": {
+ "description": "OIDC defines the configuration for the OpenID Connect (OIDC) authentication.",
+ "properties": {
+ "clientID": {
+ "description": "The client ID to be used in the OIDC\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\n\nOnly one of clientID or clientIDRef must be set.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "clientIDRef": {
+ "description": "The Kubernetes secret which contains the client ID to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nExactly one of clientID or clientIDRef must be set.\nThis is an Opaque secret. The client ID should be stored in the key \"client-id\".\n\nOnly one of clientID or clientIDRef must be set.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "clientSecret": {
+ "description": "The Kubernetes secret which contains the OIDC client secret to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\n\nThis is an Opaque secret. The client secret should be stored in the key\n\"client-secret\".",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Secret",
+ "description": "Kind is kind of the referent. For example \"Secret\".",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referenced object. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cookieConfig": {
+ "description": "CookieConfigs allows setting the SameSite attribute for OIDC cookies.\nBy default, its unset.",
+ "properties": {
+ "sameSite": {
+ "enum": [
+ "Lax",
+ "Strict",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "cookieDomain": {
+ "description": "The optional domain to set the access and ID token cookies on.\nIf not set, the cookies will default to the host of the request, not including the subdomains.\nIf set, the cookies will be set on the specified domain and all subdomains.\nThis means that requests to any subdomain will not require reauthentication after users log in to the parent domain.",
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9]))*$",
+ "type": "string"
+ },
+ "cookieNames": {
+ "description": "The optional cookie name overrides to be used for Bearer and IdToken cookies in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, uses a randomly generated suffix",
+ "properties": {
+ "accessToken": {
+ "description": "The name of the cookie used to store the AccessToken in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, defaults to \"AccessToken-(randomly generated uid)\"",
+ "type": "string"
+ },
+ "idToken": {
+ "description": "The name of the cookie used to store the IdToken in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, defaults to \"IdToken-(randomly generated uid)\"",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "csrfTokenTTL": {
+ "description": "CSRFTokenTTL defines how long the CSRF token generated during the OAuth2 authorization flow remains valid.\n\nThis duration determines the lifetime of the CSRF cookie, which is validated against the CSRF token\nin the \"state\" parameter when the provider redirects back to the callback endpoint.\n\nIf omitted, Envoy Gateway defaults the token expiration to 10 minutes.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "defaultRefreshTokenTTL": {
+ "description": "DefaultRefreshTokenTTL is the default lifetime of the refresh token.\nThis field is only used when the exp (expiration time) claim is omitted in\nthe refresh token or the refresh token is not JWT.\n\nIf not specified, defaults to 604800s (one week).\nNote: this field is only applicable when the \"refreshToken\" field is set to true.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "defaultTokenTTL": {
+ "description": "DefaultTokenTTL is the default lifetime of the id token and access token.\nPlease note that Envoy will always use the expiry time from the response\nof the authorization server if it is provided. This field is only used when\nthe expiry time is not provided by the authorization.\n\nIf not specified, defaults to 0. In this case, the \"expires_in\" field in\nthe authorization response must be set by the authorization server, or the\nOAuth flow will fail.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "denyRedirect": {
+ "description": "Any request that matches any of the provided matchers (with either tokens that are expired or missing tokens) will not be redirected to the OIDC Provider.\nThis behavior can be useful for AJAX or machine requests.",
+ "properties": {
+ "headers": {
+ "description": "Defines the headers to match against the request to deny redirect to the OIDC Provider.",
+ "items": {
+ "description": "OIDCDenyRedirectHeader defines how a header is matched",
+ "properties": {
+ "name": {
+ "description": "Specifies the name of the header in the request.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "type": {
+ "default": "Exact",
+ "description": "Type specifies how to match against a string.",
+ "enum": [
+ "Exact",
+ "Prefix",
+ "Suffix",
+ "RegularExpression"
+ ],
+ "type": "string"
+ },
+ "value": {
+ "description": "Value specifies the string value that the match must have.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "name",
+ "value"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "headers"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "disableTokenEncryption": {
+ "description": "Disable token encryption. When set to true, both the access token and the ID token will be stored in plain text.\nThis option should only be used in secure environments where token encryption is not required.\nDefault is false (tokens are encrypted).",
+ "type": "boolean"
+ },
+ "forwardAccessToken": {
+ "description": "ForwardAccessToken indicates whether the Envoy should forward the access token\nvia the Authorization header Bearer scheme to the upstream.\nIf not specified, defaults to false.",
+ "type": "boolean"
+ },
+ "forwardIDToken": {
+ "description": "ForwardIDToken configures forwarding of the OIDC ID token to the upstream.\n\nIf the configured header is \"Authorization\", EG forwards the ID token using\nthe \"Bearer \" prefix. For any other header, EG forwards the raw token value.\nIf not specified, the ID token will not be forwarded.",
+ "properties": {
+ "header": {
+ "description": "Header is the upstream request header that will carry the ID token.",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "header"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "logoutPath": {
+ "description": "The path to log a user out, clearing their credential cookies.\n\nIf not specified, uses a default logout path \"/logout\"",
+ "type": "string"
+ },
+ "passThroughAuthHeader": {
+ "description": "Skips OIDC authentication when the request contains a header that will be extracted by the JWT filter. Unless\nexplicitly stated otherwise in the extractFrom field, this will be the \"Authorization: Bearer ...\" header.\n\nThe passThroughAuthHeader option is typically used for non-browser clients that may not be able to handle OIDC\nredirects and wish to directly supply a token instead.\n\nIf not specified, defaults to false.",
+ "type": "boolean"
+ },
+ "provider": {
+ "description": "The OIDC Provider configuration.",
+ "properties": {
+ "authorizationEndpoint": {
+ "description": "The OIDC Provider's [authorization endpoint](https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint).\nIf not provided, EG will try to discover it from the provider's [Well-Known Configuration Endpoint](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse).",
+ "type": "string"
+ },
+ "backendRef": {
+ "description": "BackendRef references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.\n\nDeprecated: Use BackendRefs instead.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "backendRefs": {
+ "description": "BackendRefs references a Kubernetes object that represents the\nbackend server to which the authorization request will be sent.",
+ "items": {
+ "description": "BackendRef defines how an ObjectReference that is specific to BackendRef.",
+ "properties": {
+ "fallback": {
+ "description": "Fallback indicates whether the backend is designated as a fallback.\nMultiple fallback backends can be configured.\nIt is highly recommended to configure active or passive health checks to ensure that failover can be detected\nwhen the active backends become unhealthy and to automatically readjust once the primary backends are healthy again.\nThe overprovisioning factor is set to 1.4, meaning the fallback backends will only start receiving traffic when\nthe health of the active backends falls below 72%.",
+ "type": "boolean"
+ },
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array"
+ },
+ "backendSettings": {
+ "description": "BackendSettings holds configuration for managing the connection\nto the backend.",
+ "properties": {
+ "circuitBreaker": {
+ "description": "Circuit Breaker settings for the upstream connections and requests.\nIf not set, circuit breakers will be enabled with the default thresholds",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "The maximum number of connections that Envoy will establish to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRequests": {
+ "default": 1024,
+ "description": "The maximum number of parallel requests that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxParallelRetries": {
+ "default": 1024,
+ "description": "The maximum number of parallel retries that Envoy will make to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxPendingRequests": {
+ "default": 1024,
+ "description": "The maximum number of pending requests that Envoy will queue to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "maxRequestsPerConnection": {
+ "description": "The maximum number of requests that Envoy will make over a single connection to the referenced backend defined within a xRoute rule.\nDefault: unlimited.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perEndpoint": {
+ "description": "PerEndpoint defines Circuit Breakers that will apply per-endpoint for an upstream cluster",
+ "properties": {
+ "maxConnections": {
+ "default": 1024,
+ "description": "MaxConnections configures the maximum number of connections that Envoy will establish per-endpoint to the referenced backend defined within a xRoute rule.",
+ "format": "int64",
+ "maximum": 4294967295,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryBudget": {
+ "description": "RetryBudget provides settings for retry budget, which limits the number of retries in a given percentage.\nRetryBudget take precedence over maxParallelRetries.",
+ "properties": {
+ "minRetryConcurrency": {
+ "description": "MinRetryConcurrency specifies the minimum retry concurrency allowed for the retry budget.\nFor example, a budget of 20% with a minimum retry concurrency of 3\nwill allow 5 active retries while there are 25 active requests.\nIf there are 2 active requests, there are still 3 active retries\nallowed because of the minimum retry concurrency.\nDefaults to 3.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "percent": {
+ "description": "Percent specifies the limit on concurrent retries as a percentage [0, 100] of\nthe sum of active requests and active pending requests.",
+ "properties": {
+ "denominator": {
+ "default": 100,
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "numerator": {
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "numerator"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "numerator must be less than or equal to denominator",
+ "rule": "self.numerator <= self.denominator"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "percent"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "connection": {
+ "description": "Connection includes backend connection settings.",
+ "properties": {
+ "bufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "BufferLimit Soft limit on size of the cluster\u2019s connections read and write buffers.\nBufferLimit applies to connection streaming (maybe non-streaming) channel between processes, it's in user space.\nIf unspecified, an implementation defined default is applied (32768 bytes).\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote: that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ },
+ "preconnect": {
+ "description": "Preconnect configures proactive upstream connections to reduce latency by establishing\nconnections before they\u2019re needed and avoiding connection establishment overhead.\n\nIf unset, Envoy will fetch connections as needed to serve in-flight requests.",
+ "properties": {
+ "perEndpointPercent": {
+ "description": "PerEndpointPercent configures how many additional connections to maintain per\nupstream endpoint, useful for high-QPS or latency sensitive services. Expressed as a\npercentage of the connections required by active streams\n(e.g. 100 = preconnect disabled, 105 = 1.05x connections per-endpoint, 200 = 2.00\u00d7).\n\nAllowed value range is between 100-300. When both PerEndpointPercent and\nPredictivePercent are set, Envoy ensures both are satisfied (max of the two).",
+ "format": "int32",
+ "maximum": 300,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "predictivePercent": {
+ "description": "PredictivePercent configures how many additional connections to maintain\nacross the cluster by anticipating which upstream endpoint the load balancer\nwill select next, useful for low-QPS services. Relies on deterministic\nloadbalancing and is only supported with Random or RoundRobin.\nExpressed as a percentage of the connections required by active streams\n(e.g. 100 = 1.0 (no preconnect), 105 = 1.05\u00d7 connections across the cluster, 200 = 2.00\u00d7).\n\nMinimum allowed value is 100. When both PerEndpointPercent and PredictivePercent are\nset Envoy ensures both are satisfied per host (max of the two).",
+ "format": "int32",
+ "minimum": 100,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "socketBufferLimit": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "SocketBufferLimit provides configuration for the maximum buffer size in bytes for each socket\nto backend.\nSocketBufferLimit applies to socket streaming channel between TCP/IP stacks, it's in kernel space.\nFor example, 20Mi, 1Gi, 256Ki etc.\nNote that when the suffix is not provided, the value is interpreted as bytes.",
+ "x-kubernetes-int-or-string": true
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "dns": {
+ "description": "DNS includes dns resolution settings.",
+ "properties": {
+ "dnsRefreshRate": {
+ "description": "DNSRefreshRate specifies the rate at which DNS records should be refreshed.\nDefaults to 30 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "lookupFamily": {
+ "description": "LookupFamily determines how Envoy would resolve DNS for Routes where the backend is specified as a fully qualified domain name (FQDN).\nIf set, this configuration overrides other defaults.",
+ "enum": [
+ "IPv4",
+ "IPv6",
+ "IPv4Preferred",
+ "IPv6Preferred",
+ "IPv4AndIPv6"
+ ],
+ "type": "string"
+ },
+ "respectDnsTtl": {
+ "description": "RespectDNSTTL indicates whether the DNS Time-To-Live (TTL) should be respected.\nIf the value is set to true, the DNS refresh rate will be set to the resource record\u2019s TTL.\nDefaults to true.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthCheck": {
+ "description": "HealthCheck allows gateway to perform active health checking on backends.",
+ "properties": {
+ "active": {
+ "description": "Active health check configuration",
+ "properties": {
+ "grpc": {
+ "description": "GRPC defines the configuration of the GRPC health checker.\nIt's optional, and can only be used if the specified type is GRPC.",
+ "properties": {
+ "service": {
+ "description": "Service to send in the health check request.\nIf this is not specified, then the health check request applies to the entire\nserver and not to a specific service.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "healthyThreshold": {
+ "default": 1,
+ "description": "HealthyThreshold defines the number of healthy health checks required before a backend host is marked healthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ },
+ "http": {
+ "description": "HTTP defines the configuration of http health checker.\nIt's required while the health checker type is HTTP.",
+ "properties": {
+ "expectedResponse": {
+ "description": "ExpectedResponse defines a list of HTTP expected responses to match.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "expectedStatuses": {
+ "description": "ExpectedStatuses defines a list of HTTP response statuses considered healthy.\nDefaults to 200 only",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "hostname": {
+ "description": "Hostname defines the HTTP Host header used for active HTTP health checks.\nHost selection uses this order: this field, the associated Backend endpoint\nhostname if available, then the effective Route hostname.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "method": {
+ "description": "Method defines the HTTP method used for health checking.\nDefaults to GET",
+ "type": "string"
+ },
+ "path": {
+ "description": "Path defines the HTTP path that will be requested during health checking.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "type": "string"
+ },
+ "retriableStatuses": {
+ "description": "RetriableStatuses defines a list of HTTP response statuses considered retriable.\nResponses matching these statuses count towards the unhealthy threshold but\ndo not result in the host being considered immediately unhealthy.\nThe expected statuses take precedence for any range overlaps with this field.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "path"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "initialJitter": {
+ "description": "InitialJitter defines the maximum time Envoy will wait before the first health check.\nEnvoy will randomly select a value between 0 and the initial jitter value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between active health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "overrides": {
+ "description": "Overrides defines the configuration of the overriding health check settings for all endpoints\nin the backend cluster. This allows customization of port and other settings that may differ\nfrom the main service configuration.",
+ "properties": {
+ "port": {
+ "description": "Port overrides the health check port.\nIf not set, the endpoint's serving port is used for health checks.\nThis is useful when health checks are served on a different port than\nthe main service port (e.g., port 443 for service, port 9090 for health checks).",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "TCP defines the configuration of tcp health checker.\nIt's required while the health checker type is TCP.",
+ "properties": {
+ "receive": {
+ "description": "Receive defines the expected response payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "send": {
+ "description": "Send defines the request payload.",
+ "properties": {
+ "binary": {
+ "description": "Binary payload base64 encoded.",
+ "format": "byte",
+ "type": "string"
+ },
+ "text": {
+ "description": "Text payload in plain text.",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ },
+ {
+ "enum": [
+ "Text",
+ "Binary"
+ ]
+ }
+ ],
+ "description": "Type defines the type of the payload.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If payload type is Text, text field needs to be set.",
+ "rule": "self.type == 'Text' ? has(self.text) : !has(self.text)"
+ },
+ {
+ "message": "If payload type is Binary, binary field needs to be set.",
+ "rule": "self.type == 'Binary' ? has(self.binary) : !has(self.binary)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "default": "1s",
+ "description": "Timeout defines the time to wait for a health check response.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "type": {
+ "allOf": [
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ },
+ {
+ "enum": [
+ "HTTP",
+ "TCP",
+ "GRPC"
+ ]
+ }
+ ],
+ "description": "Type defines the type of health checker.",
+ "type": "string"
+ },
+ "unhealthyThreshold": {
+ "default": 3,
+ "description": "UnhealthyThreshold defines the number of unhealthy health checks required before a backend host is marked unhealthy.\nWithout RetriableStatuses configured, any health check failure results in the host being immediately\nconsidered unhealthy. When RetriableStatuses is set, health checks returning those statuses are retried\nup to this threshold before the host is marked unhealthy.",
+ "format": "int32",
+ "minimum": 1,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If Health Checker type is HTTP, http field needs to be set.",
+ "rule": "self.type == 'HTTP' ? has(self.http) : !has(self.http)"
+ },
+ {
+ "message": "If Health Checker type is TCP, tcp field needs to be set.",
+ "rule": "self.type == 'TCP' ? has(self.tcp) : !has(self.tcp)"
+ },
+ {
+ "message": "The grpc field can only be set if the Health Checker type is GRPC.",
+ "rule": "has(self.grpc) ? self.type == 'GRPC' : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "panicThreshold": {
+ "description": "When number of unhealthy endpoints for a backend reaches this threshold\nEnvoy will disregard health status and balance across all endpoints.\nIt's designed to prevent a situation in which host failures cascade throughout the cluster\nas load increases. If not set, the default value is 50%. To disable panic mode, set value to `0`.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "passive": {
+ "description": "Passive passive check configuration",
+ "properties": {
+ "alwaysEjectOneEndpoint": {
+ "default": false,
+ "description": "AlwaysEjectOneEndpoint defines whether at least one host should be ejected,\nregardless of MaxEjectionPercent.",
+ "type": "boolean"
+ },
+ "baseEjectionTime": {
+ "default": "30s",
+ "description": "BaseEjectionTime defines the base duration for which a host will be ejected on consecutive failures.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "consecutive5XxErrors": {
+ "default": 5,
+ "description": "Consecutive5xxErrors sets the number of consecutive 5xx errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveGatewayErrors": {
+ "description": "ConsecutiveGatewayErrors sets the number of consecutive gateway errors triggering ejection.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "consecutiveLocalOriginFailures": {
+ "default": 5,
+ "description": "ConsecutiveLocalOriginFailures sets the number of consecutive local origin failures triggering ejection.\nParameter takes effect only when split_external_local_origin_errors is set to true.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "failurePercentageThreshold": {
+ "description": "FailurePercentageThreshold sets the failure percentage threshold for outlier detection.\nIf the failure percentage of a given host is greater than or equal to this value, it will be ejected.\nDefaults to 85.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "interval": {
+ "default": "3s",
+ "description": "Interval defines the time between passive health checks.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxEjectionPercent": {
+ "default": 10,
+ "description": "MaxEjectionPercent sets the maximum percentage of hosts in a cluster that can be ejected.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "splitExternalLocalOriginErrors": {
+ "default": false,
+ "description": "SplitExternalLocalOriginErrors enables splitting of errors between external and local origin.",
+ "type": "boolean"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "http2": {
+ "description": "HTTP2 provides HTTP/2 configuration for backend connections.",
+ "properties": {
+ "connectionKeepalive": {
+ "description": "ConnectionKeepalive configures HTTP/2 connection keepalive using PING frames.",
+ "properties": {
+ "idleInterval": {
+ "description": "IdleInterval specifies how long a connection must be idle before a PING is sent.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "Interval specifies how often to send HTTP/2 PING frames to keep the connection alive.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "intervalJitter": {
+ "description": "IntervalJitter specifies a random jitter percentage added to each interval.\nDefaults to 15% if not specified.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ },
+ "timeout": {
+ "description": "Timeout specifies how long to wait for a PING response before considering the connection dead.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "timeout must be less than interval",
+ "rule": "!has(self.timeout) || !has(self.interval) || duration(self.timeout) < duration(self.interval)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "initialConnectionWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialConnectionWindowSize sets the initial window size for HTTP/2 connections.\nIf not set, the default value is 1 MiB.",
+ "x-kubernetes-int-or-string": true
+ },
+ "initialStreamWindowSize": {
+ "allOf": [
+ {
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$"
+ },
+ {
+ "pattern": "^[1-9]+[0-9]*([EPTGMK]i|[EPTGMk])?$"
+ }
+ ],
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "InitialStreamWindowSize sets the initial window size for HTTP/2 streams.\nIf not set, the default value is 64 KiB(64*1024).",
+ "x-kubernetes-int-or-string": true
+ },
+ "maxConcurrentStreams": {
+ "description": "MaxConcurrentStreams sets the maximum number of concurrent streams allowed per connection.\nIf not set, the default value is 100.",
+ "format": "int32",
+ "maximum": 2147483647,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "onInvalidMessage": {
+ "description": "OnInvalidMessage determines if Envoy will terminate the connection or just the offending stream in the event of HTTP messaging error\nIt's recommended for L2 Envoy deployments to set this value to TerminateStream.\nhttps://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/level_two\nDefault: TerminateConnection",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "loadBalancer": {
+ "description": "LoadBalancer policy to apply when routing traffic from the gateway to\nthe backend endpoints. Defaults to `LeastRequest`.",
+ "properties": {
+ "backendUtilization": {
+ "description": "BackendUtilization defines the configuration when the load balancer type is\nset to BackendUtilization.",
+ "properties": {
+ "blackoutPeriod": {
+ "description": "A given endpoint must report load metrics continuously for at least this long before the endpoint weight will be used.\nDefault is 10s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "errorUtilizationPenaltyPercent": {
+ "description": "ErrorUtilizationPenaltyPercent adjusts endpoint weights based on the error rate (eps/qps).\nThis is expressed as a percentage-based integer where 100 represents 1.0, 150 represents 1.5, etc.\n\nFor example:\n- 100 => 1.0x\n- 120 => 1.2x\n- 200 => 2.0x\n\nMust be non-negative.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "keepResponseHeaders": {
+ "default": false,
+ "description": "KeepResponseHeaders keeps the ORCA load report headers/trailers before sending the response to the client.\nDefaults to false.",
+ "type": "boolean"
+ },
+ "metricNamesForComputingUtilization": {
+ "description": "Metric names used to compute utilization if application_utilization is not set.\nFor map fields in ORCA proto, use the form \".\", e.g., \"named_metrics.foo\".",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "weightExpirationPeriod": {
+ "description": "If a given endpoint has not reported load metrics in this long, stop using the reported weight. Defaults to 3m.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "weightUpdatePeriod": {
+ "description": "How often endpoint weights are recalculated. Values less than 100ms are capped at 100ms. Default 1s.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "consistentHash": {
+ "description": "ConsistentHash defines the configuration when the load balancer type is\nset to ConsistentHash",
+ "properties": {
+ "cookie": {
+ "description": "Cookie configures the cookie hash policy when the consistent hash type is set to Cookie.",
+ "properties": {
+ "attributes": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "Additional Attributes to set for the generated cookie.",
+ "type": "object"
+ },
+ "name": {
+ "description": "Name of the cookie to hash.\nIf this cookie does not exist in the request, Envoy will generate a cookie and set\nthe TTL on the response back to the client based on Layer 4\nattributes of the backend endpoint, to ensure that these future requests\ngo to the same backend endpoint. Make sure to set the TTL field for this case.",
+ "type": "string"
+ },
+ "ttl": {
+ "description": "TTL of the generated cookie if the cookie is not present. This value sets the\nMax-Age attribute value.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "header": {
+ "description": "Header configures the header hash policy when the consistent hash type is set to Header.\n\nDeprecated: use Headers instead",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "headers": {
+ "description": "Headers configures the header hash policy for each header, when the consistent hash type is set to Headers.",
+ "items": {
+ "description": "Header defines the header hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the header to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "queryParams": {
+ "description": "QueryParams configures the query parameter hash policy when the consistent hash type is set to QueryParams.",
+ "items": {
+ "description": "QueryParam defines the query parameter name hashing configuration for consistent hash based\nload balancing.",
+ "properties": {
+ "name": {
+ "description": "Name of the query param to hash.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "tableSize": {
+ "default": 65537,
+ "description": "The table size for consistent hashing, must be prime number limited to 5000011.",
+ "format": "int64",
+ "maximum": 5000011,
+ "minimum": 2,
+ "type": "integer"
+ },
+ "type": {
+ "description": "ConsistentHashType defines the type of input to hash on. Valid Type values are\n\"SourceIP\",\n\"Header\",\n\"Headers\",\n\"Cookie\".\n\"QueryParams\".",
+ "enum": [
+ "SourceIP",
+ "Header",
+ "Headers",
+ "Cookie",
+ "QueryParams"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If consistent hash type is header, the header field must be set.",
+ "rule": "self.type == 'Header' ? has(self.header) : !has(self.header)"
+ },
+ {
+ "message": "If consistent hash type is headers, the headers field must be set.",
+ "rule": "self.type == 'Headers' ? has(self.headers) : !has(self.headers)"
+ },
+ {
+ "message": "If consistent hash type is cookie, the cookie field must be set.",
+ "rule": "self.type == 'Cookie' ? has(self.cookie) : !has(self.cookie)"
+ },
+ {
+ "message": "If consistent hash type is queryParams, the queryParams field must be set.",
+ "rule": "self.type == 'QueryParams' ? has(self.queryParams) : !has(self.queryParams)"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "dynamicModule": {
+ "description": "DynamicModule defines the configuration when the load balancer type is\nset to DynamicModule. The referenced module must be registered in the\nEnvoyProxy resource's dynamicModules allowlist.",
+ "properties": {
+ "config": {
+ "description": "Config is optional configuration for the module's load balancer\nimplementation. This is serialized and passed to the module's\ninitialization function.",
+ "x-kubernetes-preserve-unknown-fields": true
+ },
+ "lbPolicyName": {
+ "description": "LBPolicyName identifies a specific load balancer implementation within\nthe dynamic module. A single shared library can contain multiple LB\npolicy implementations. This value is passed to the module's\ninitialization function to select the appropriate implementation.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "name": {
+ "description": "Name references a dynamic module registered in the EnvoyProxy resource's\ndynamicModules list. The referenced module must exist in the registry;\notherwise, the policy will be rejected.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([a-z0-9.-]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lbPolicyName",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "endpointOverride": {
+ "description": "EndpointOverride defines the configuration for endpoint override.\nWhen specified, the load balancer will attempt to route requests to endpoints\nbased on the override information extracted from request headers or metadata.\n If the override endpoints are not available, the configured load balancer policy will be used as fallback.",
+ "properties": {
+ "extractFrom": {
+ "description": "ExtractFrom defines the sources to extract endpoint override information from.",
+ "items": {
+ "description": "EndpointOverrideExtractFrom defines a source to extract endpoint override information from.",
+ "properties": {
+ "header": {
+ "description": "Header defines the header to get the override endpoint addresses.\nThe header value must specify at least one endpoint in `IP:Port` format or multiple endpoints in `IP:Port,IP:Port,...` format.\nFor example `10.0.0.5:8080` or `[2600:4040:5204::1574:24ae]:80`.\nThe IPv6 address is enclosed in square brackets.",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 10,
+ "minItems": 1,
+ "type": "array"
+ }
+ },
+ "required": [
+ "extractFrom"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "slowStart": {
+ "description": "SlowStart defines the configuration related to the slow start load balancer policy.\nIf set, during slow start window, traffic sent to the newly added hosts will gradually increase.\nSupported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "properties": {
+ "window": {
+ "description": "Window defines the duration of the warm up period for newly added host.\nDuring slow start window, traffic sent to the newly added hosts will gradually increase.\nCurrently only supports linear growth of traffic. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/api-v3/config/cluster/v3/cluster.proto#config-cluster-v3-cluster-slowstartconfig",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "window"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": {
+ "description": "Type decides the type of Load Balancer policy.\nValid LoadBalancerType values are\n\"ConsistentHash\",\n\"LeastRequest\",\n\"Random\",\n\"RoundRobin\",\n\"BackendUtilization\",\n\"DynamicModule\".",
+ "enum": [
+ "ConsistentHash",
+ "LeastRequest",
+ "Random",
+ "RoundRobin",
+ "BackendUtilization",
+ "DynamicModule"
+ ],
+ "type": "string"
+ },
+ "zoneAware": {
+ "description": "ZoneAware defines the configuration related to the distribution of requests between locality zones.",
+ "properties": {
+ "preferLocal": {
+ "description": "PreferLocalZone configures zone-aware routing to prefer sending traffic to the local locality zone.",
+ "properties": {
+ "force": {
+ "description": "ForceLocalZone defines override configuration for forcing all traffic to stay within the local zone instead of the default behavior\nwhich maintains equal distribution among upstream endpoints while sending as much traffic as possible locally.",
+ "properties": {
+ "minEndpointsInZoneThreshold": {
+ "description": "MinEndpointsInZoneThreshold is the minimum number of upstream endpoints in the local zone required to honor the forceLocalZone\noverride. This is useful for protecting zones with fewer endpoints.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minEndpointsThreshold": {
+ "description": "MinEndpointsThreshold is the minimum number of total upstream endpoints across all zones required to enable zone-aware routing.",
+ "format": "int64",
+ "type": "integer"
+ },
+ "percentageEnabled": {
+ "description": "Configures percentage of requests that will be considered for zone aware routing if zone aware routing is configured. If not specified, Envoy defaults to 100%.",
+ "format": "int32",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "weightedZones": {
+ "description": "WeightedZones configures weight-based traffic distribution across locality zones.\nTraffic is distributed proportionally based on the sum of all zone weights.",
+ "items": {
+ "description": "WeightedZoneConfig defines the weight for a specific locality zone.",
+ "properties": {
+ "weight": {
+ "description": "Weight defines the weight for this locality.\nHigher values receive more traffic. The actual traffic distribution\nis proportional to this value relative to other localities.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "zone": {
+ "description": "Zone specifies the topology zone this weight applies to.\nThe value should match the topology.kubernetes.io/zone label\nof the nodes where endpoints are running.\nZones not listed in the configuration receive a default weight of 1.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "weight",
+ "zone"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "zone"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "type"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "If LoadBalancer type is consistentHash, consistentHash field needs to be set.",
+ "rule": "self.type == 'ConsistentHash' ? has(self.consistentHash) : !has(self.consistentHash)"
+ },
+ {
+ "message": "If LoadBalancer type is BackendUtilization, backendUtilization field needs to be set.",
+ "rule": "self.type == 'BackendUtilization' ? has(self.backendUtilization) : !has(self.backendUtilization)"
+ },
+ {
+ "message": "If LoadBalancer type is DynamicModule, dynamicModule field needs to be set.",
+ "rule": "self.type == 'DynamicModule' ? has(self.dynamicModule) : !has(self.dynamicModule)"
+ },
+ {
+ "message": "Currently SlowStart is only supported for RoundRobin, LeastRequest, and BackendUtilization load balancers.",
+ "rule": "self.type in ['Random', 'ConsistentHash', 'DynamicModule'] ? !has(self.slowStart) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not supported for ConsistentHash load balancers. Use weightedZones instead.",
+ "rule": "self.type == 'ConsistentHash' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "PreferLocal zone-aware routing is not currently supported for BackendUtilization load balancers. Only WeightedZones can be used with BackendUtilization.",
+ "rule": "self.type == 'BackendUtilization' && has(self.zoneAware) ? !has(self.zoneAware.preferLocal) : true"
+ },
+ {
+ "message": "ZoneAware routing is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.zoneAware) : true"
+ },
+ {
+ "message": "ZoneAware PreferLocal and WeightedZones cannot be specified together.",
+ "rule": "has(self.zoneAware) ? !(has(self.zoneAware.preferLocal) && has(self.zoneAware.weightedZones)) : true"
+ },
+ {
+ "message": "EndpointOverride is not supported for DynamicModule load balancers.",
+ "rule": "self.type == 'DynamicModule' ? !has(self.endpointOverride) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "proxyProtocol": {
+ "description": "ProxyProtocol enables the Proxy Protocol when communicating with the backend.",
+ "properties": {
+ "version": {
+ "description": "Version of ProxyProtocol\nValid ProxyProtocolVersion values are\n\"V1\"\n\"V2\"",
+ "enum": [
+ "V1",
+ "V2"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "version"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retry": {
+ "description": "Retry provides more advanced usage, allowing users to customize the number of retries, retry fallback strategy, and retry triggering conditions.\nIf not set, retry will be disabled.",
+ "properties": {
+ "numAttemptsPerPriority": {
+ "description": "NumAttemptsPerPriority defines the number of requests (initial attempt + retries)\nthat should be sent to the same priority before switching to a different one.\nIf not specified or set to 0, all requests are sent to the highest priority that is healthy.",
+ "format": "int32",
+ "type": "integer"
+ },
+ "numRetries": {
+ "default": 2,
+ "description": "NumRetries is the number of retries to be attempted. Defaults to 2.",
+ "format": "int32",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "perRetry": {
+ "description": "PerRetry is the retry policy to be applied per retry attempt.",
+ "properties": {
+ "backOff": {
+ "description": "Backoff is the backoff policy to be applied per retry attempt. gateway uses a fully jittered exponential\nback-off algorithm for retries. For additional details,\nsee https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/router_filter#config-http-filters-router-x-envoy-max-retries",
+ "properties": {
+ "baseInterval": {
+ "description": "BaseInterval is the base interval between retries.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxInterval": {
+ "description": "MaxInterval is the maximum interval between retries. This parameter is optional, but must be greater than or equal to the base_interval if set.\nThe default is 10 times the base_interval",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout is the timeout per retry attempt.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "retryOn": {
+ "description": "RetryOn specifies the retry trigger condition.\n\nIf not specified, the default is to retry on connect-failure,refused-stream,unavailable,cancelled,retriable-status-codes(503).",
+ "properties": {
+ "httpStatusCodes": {
+ "description": "HttpStatusCodes specifies the http status codes to be retried.\nThe retriable-status-codes trigger must also be configured for these status codes to trigger a retry.",
+ "items": {
+ "description": "HTTPStatus defines the http status code.",
+ "maximum": 599,
+ "minimum": 100,
+ "type": "integer"
+ },
+ "type": "array"
+ },
+ "triggers": {
+ "description": "Triggers specifies the retry trigger condition(Http/Grpc).",
+ "items": {
+ "description": "TriggerEnum specifies the conditions that trigger retries.",
+ "enum": [
+ "5xx",
+ "gateway-error",
+ "reset",
+ "reset-before-request",
+ "connect-failure",
+ "retriable-4xx",
+ "refused-stream",
+ "retriable-status-codes",
+ "cancelled",
+ "deadline-exceeded",
+ "internal",
+ "resource-exhausted",
+ "unavailable"
+ ],
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcpKeepalive": {
+ "description": "TcpKeepalive settings associated with the upstream client connection.\nDisabled by default.",
+ "properties": {
+ "idleTime": {
+ "description": "The duration a connection needs to be idle before keep-alive\nprobes start being sent.\nThe duration format is\nDefaults to `7200s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "interval": {
+ "description": "The duration between keep-alive probes.\nDefaults to `75s`.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "probes": {
+ "description": "The total number of unacknowledged probes to send before deciding\nthe connection is dead.\nDefaults to 9.",
+ "format": "int32",
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "timeout": {
+ "description": "Timeout settings for the backend connections.",
+ "properties": {
+ "http": {
+ "description": "Timeout settings for HTTP.",
+ "properties": {
+ "connectionIdleTimeout": {
+ "description": "The idle timeout for an HTTP connection. Idle time is defined as a period in which there are no active requests in the connection.\nDefault: 1 hour.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxConnectionDuration": {
+ "description": "The maximum duration of an HTTP connection.\nDefault: unlimited.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "maxStreamDuration": {
+ "description": "MaxStreamDuration is the maximum duration for a stream to complete. This timeout measures the time\nfrom when the request is sent until the response stream is fully consumed and does not apply to\nnon-streaming requests.\nWhen set to \"0s\", no max duration is applied and streams can run indefinitely.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "requestTimeout": {
+ "description": "RequestTimeout is the time until which entire response is received from the upstream.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "streamIdleTimeout": {
+ "description": " The stream idle timeout defines the amount of time a stream can exist without any upstream or downstream activity.\n If not specified, StreamIdleTimeout is inherited from the listener-level setting, which can be configured via ClientTrafficPolicy.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "tcp": {
+ "description": "Timeout settings for TCP.",
+ "properties": {
+ "connectTimeout": {
+ "description": "The timeout for network connection establishment, including TCP and TLS handshakes.\nDefault: 10 seconds.",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "predictivePercent in preconnect policy only works with RoundRobin or Random load balancers",
+ "rule": "!((has(self.connection) && has(self.connection.preconnect) && has(self.connection.preconnect.predictivePercent)) && !(has(self.loadBalancer) && has(self.loadBalancer.type) && self.loadBalancer.type in ['Random', 'RoundRobin']))"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "endSessionEndpoint": {
+ "description": "The OIDC Provider's [end session endpoint](https://openid.net/specs/openid-connect-core-1_0.html#RPLogout).\n\nIf the end session endpoint is provided, EG will use it to log out the user from the OIDC Provider when the user accesses the logout path.\nEG will also try to discover the end session endpoint from the provider's [Well-Known Configuration Endpoint](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse) when authorizationEndpoint or tokenEndpoint is not provided.",
+ "type": "string"
+ },
+ "issuer": {
+ "description": "The OIDC Provider's [issuer identifier](https://openid.net/specs/openid-connect-discovery-1_0.html#IssuerDiscovery).\nIssuer MUST be a URI RFC 3986 [RFC3986] with a scheme component that MUST\nbe https, a host component, and optionally, port and path components and\nno query or fragment components.",
+ "minLength": 1,
+ "type": "string"
+ },
+ "tokenEndpoint": {
+ "description": "The OIDC Provider's [token endpoint](https://openid.net/specs/openid-connect-core-1_0.html#TokenEndpoint).\nIf not provided, EG will try to discover it from the provider's [Well-Known Configuration Endpoint](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse).",
+ "type": "string"
+ }
+ },
+ "required": [
+ "issuer"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "BackendRefs must be used, backendRef is not supported.",
+ "rule": "!has(self.backendRef)"
+ },
+ {
+ "message": "Retry timeout is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.perRetry)? !has(self.backendSettings.retry.perRetry.timeout):true):true):true"
+ },
+ {
+ "message": "HTTPStatusCodes is not supported.",
+ "rule": "has(self.backendSettings)? (has(self.backendSettings.retry)?(has(self.backendSettings.retry.retryOn)? !has(self.backendSettings.retry.retryOn.httpStatusCodes):true):true):true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "redirectURL": {
+ "description": "The redirect URL to be used in the OIDC\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nIf not specified, uses the default redirect URI \"%REQ(x-forwarded-proto)%://%REQ(:authority)%/oauth2/callback\"",
+ "type": "string"
+ },
+ "refreshToken": {
+ "default": true,
+ "description": "RefreshToken indicates whether the Envoy should automatically refresh the\nid token and access token when they expire.\nWhen set to true, the Envoy will use the refresh token to get a new id token\nand access token when they expire.\n\nIf not specified, defaults to true.",
+ "type": "boolean"
+ },
+ "resources": {
+ "description": "The OIDC resources to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "scopes": {
+ "description": "The OIDC scopes to be used in the\n[Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest).\nThe \"openid\" scope is always added to the list of scopes if not already\nspecified.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ }
+ },
+ "required": [
+ "clientSecret",
+ "provider"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "only one of clientID or clientIDRef must be set",
+ "rule": "(has(self.clientID) && !has(self.clientIDRef)) || (!has(self.clientID) && has(self.clientIDRef))"
+ },
+ {
+ "message": "forwardAccessToken cannot be true when forwardIDToken.header is Authorization",
+ "rule": "!(has(self.forwardAccessToken) && self.forwardAccessToken && has(self.forwardIDToken) && self.forwardIDToken.header.lowerAscii() == 'authorization')"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "targetRef": {
+ "description": "TargetRef is the name of the resource this policy is being attached to.\nThis policy and the TargetRef MUST be in the same namespace for this\nPolicy to have effect\n\nDeprecated: use targetRefs/targetSelectors instead",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs are the names of the Gateway resources this policy\nis being attached to.",
+ "items": {
+ "description": "LocalPolicyTargetReferenceWithSectionName identifies an API object to apply a\ndirect policy to. This should be used as part of Policy resources that can\ntarget single resources. For more information on how this policy attachment\nmode works, and a sample Policy resource, refer to the policy attachment\ndocumentation for Gateway API.\n\nNote: This should only be used for direct policy attachment when references\nto SectionName are actually needed. In all other cases,\nLocalPolicyTargetReference should be used.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. When\nunspecified, this targetRef targets the entire resource. In the following\nresources, SectionName is interpreted as the following:\n\n* Gateway: Listener name\n* HTTPRoute: HTTPRouteRule name\n* Service: Port name\n\nIf a SectionName is specified, but does not exist on the targeted object,\nthe Policy must fail to attach, and the policy implementation should record\na `ResolvedRefs` or similar Condition in the Policy's status.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array"
+ },
+ "targetSelectors": {
+ "description": "TargetSelectors allow targeting resources for this policy based on labels",
+ "items": {
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group that this selector targets. Defaults to gateway.networking.k8s.io",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is the resource kind that this selector targets.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "matchExpressions": {
+ "description": "MatchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "MatchLabels are the set of label selectors for identifying the targeted resource.",
+ "type": "object"
+ },
+ "namespaces": {
+ "description": "Namespaces determines which namespaces are considered for target selection.\n\nIf unspecified, only targets in the same namespace as this policy are considered.\n\nWhen specified, the effective set of namespaces is always constrained to the\nnamespaces watched by Envoy Gateway.\n\nSelecting targets across namespaces requires a ReferenceGrant in the target\nnamespace that allows this policy kind to reference the selected target kind.\nCross-namespace targets without a matching ReferenceGrant are ignored.",
+ "properties": {
+ "from": {
+ "default": "Same",
+ "description": "From indicates how namespaces are selected for this target selector.\n\nAll means all namespaces watched by Envoy Gateway.\nSelector means namespaces watched by Envoy Gateway that match Selector.",
+ "enum": [
+ "Same",
+ "All",
+ "Selector"
+ ],
+ "type": "string"
+ },
+ "selector": {
+ "description": "Selector selects namespaces when From is set to Selector.",
+ "properties": {
+ "matchExpressions": {
+ "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
+ "items": {
+ "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
+ "properties": {
+ "key": {
+ "description": "key is the label key that the selector applies to.",
+ "type": "string"
+ },
+ "operator": {
+ "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
+ "type": "string"
+ },
+ "values": {
+ "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "key",
+ "operator"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "matchLabels": {
+ "additionalProperties": {
+ "type": "string"
+ },
+ "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
+ "type": "object"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-map-type": "atomic",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "from"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "selector must be specified when from is Selector",
+ "rule": "self.from != 'Selector' || has(self.selector)"
+ }
+ ],
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "kind"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "group must be gateway.networking.k8s.io",
+ "rule": "has(self.group) ? self.group == 'gateway.networking.k8s.io' : true "
+ }
+ ],
+ "additionalProperties": false
+ },
+ "type": "array"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "either targetRef or targetRefs must be used",
+ "rule": "(has(self.targetRef) && !has(self.targetRefs)) || (!has(self.targetRef) && has(self.targetRefs)) || (has(self.targetSelectors) && self.targetSelectors.size() > 0) "
+ },
+ {
+ "message": "this policy can only have a targetRef.group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRef) ? self.targetRef.group == 'gateway.networking.k8s.io' : true"
+ },
+ {
+ "message": "this policy can only have a targetRef.kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute",
+ "rule": "has(self.targetRef) ? self.targetRef.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'TCPRoute'] : true"
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].group of gateway.networking.k8s.io",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.group == 'gateway.networking.k8s.io') : true "
+ },
+ {
+ "message": "this policy can only have a targetRefs[*].kind of Gateway/HTTPRoute/GRPCRoute/TCPRoute",
+ "rule": "has(self.targetRefs) ? self.targetRefs.all(ref, ref.kind in ['Gateway', 'HTTPRoute', 'GRPCRoute', 'TCPRoute']) : true "
+ },
+ {
+ "message": "if authorization.rules.principal.jwt is used, jwt must be defined",
+ "rule": "(has(self.authorization) && has(self.authorization.rules) && self.authorization.rules.exists(r, has(r.principal.jwt))) ? has(self.jwt) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current status of SecurityPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.\n\n\n\nNotes for implementors:\n\nConditions are a listType `map`, which means that they function like a\nmap with a key of the `type` field _in the k8s apiserver_.\n\nThis means that implementations must obey some rules when updating this\nsection.\n\n* Implementations MUST perform a read-modify-write cycle on this field\n before modifying it. That is, when modifying this field, implementations\n must be confident they have fetched the most recent version of this field,\n and ensure that changes they make are on that recent version.\n* Implementations MUST NOT remove or reorder Conditions that they are not\n directly responsible for. For example, if an implementation sees a Condition\n with type `special.io/SomeField`, it MUST NOT remove, change or update that\n Condition.\n* Implementations MUST always _merge_ changes into Conditions of the same Type,\n rather than creating more than one Condition of the same Type.\n* Implementations MUST always update the `observedGeneration` field of the\n Condition to the `metadata.generation` of the Gateway at the time of update creation.\n* If the `observedGeneration` of a Condition is _greater than_ the value the\n implementation knows about, then it MUST NOT perform the update on that Condition,\n but must wait for a future reconciliation and status update. (The assumption is that\n the implementation's copy of the object is stale and an update will be re-triggered\n if relevant.)\n\n",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/servicemonitor-stable-v1.json b/crdSchemas/master-standalone/servicemonitor-stable-v1.json
index fb6852a..077d44c 100644
--- a/crdSchemas/master-standalone/servicemonitor-stable-v1.json
+++ b/crdSchemas/master-standalone/servicemonitor-stable-v1.json
@@ -19,7 +19,7 @@
"description": "attachMetadata defines additional metadata which is added to the\ndiscovered targets.\n\nIt requires Prometheus >= v2.37.0.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -220,6 +220,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -568,7 +569,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -595,7 +596,7 @@
"type": "string"
},
"port": {
- "description": "port defines the name of the Service port which this endpoint refers to.\n\nIt takes precedence over `targetPort`.",
+ "description": "port defines the name of the Service port which this endpoint refers to\n(e.g. `.spec.ports[].name`).\n\nIt takes precedence over `targetPort`.",
"type": "string"
},
"proxyConnectHeader": {
@@ -676,6 +677,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -732,7 +734,7 @@
"type": "string"
}
],
- "description": "targetPort defines the name or number of the target port of the `Pod` object behind the\nService. The port must be specified with the container's port property.",
+ "description": "targetPort defines the name or number of a container port on Pods selected\nby the Service.\nIf a name, it matches against `.spec.containers[].ports[].name` of the Pods.\nIf a number, it matches against `.spec.containers[].ports[].containerPort` of the Pods.",
"x-kubernetes-int-or-string": true
},
"tlsConfig": {
@@ -944,21 +946,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"namespaceSelector": {
@@ -982,6 +988,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -1007,6 +1014,7 @@
"sampleLimit": {
"description": "sampleLimit defines a per-scrape limit on the number of scraped samples\nthat will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scrapeClass": {
@@ -1111,6 +1119,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will\nbe accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
}
},
diff --git a/crdSchemas/master-standalone/tcproute-stable-v1alpha2.json b/crdSchemas/master-standalone/tcproute-stable-v1alpha2.json
new file mode 100644
index 0000000..17ae551
--- /dev/null
+++ b/crdSchemas/master-standalone/tcproute-stable-v1alpha2.json
@@ -0,0 +1,351 @@
+{
+ "description": "TCPRoute provides a way to route TCP requests. When combined with a Gateway\nlistener, it can be used to forward connections on the port specified by the\nlistener to a set of backends specified by the TCPRoute.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TCPRoute.",
+ "properties": {
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of TCP matchers and actions.",
+ "items": {
+ "description": "TCPRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or a\nService with no endpoints), the underlying implementation MUST actively\nreject connection attempts to this backend. Connection rejections must\nrespect weight; if an invalid backend is requested to have 80% of\nconnections, then 80% of connections must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.\n\nSupport: Extended",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
+ }
+ ]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TCPRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/thanosruler-stable-v1.json b/crdSchemas/master-standalone/thanosruler-stable-v1.json
index c42d27b..c06a62c 100644
--- a/crdSchemas/master-standalone/thanosruler-stable-v1.json
+++ b/crdSchemas/master-standalone/thanosruler-stable-v1.json
@@ -1939,7 +1939,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -3729,7 +3729,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -4506,7 +4506,7 @@
"type": "integer"
},
"send": {
- "description": "send defines whether metric metadata is sent to the remote storage or not.",
+ "description": "send defines whether metric metadata is sent to the remote storage or not.\n\nThe setting is ignored when Remote Write message's version 2.0 is used.",
"type": "boolean"
},
"sendInterval": {
@@ -4838,7 +4838,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5264,6 +5264,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -7235,7 +7236,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -7384,7 +7385,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
diff --git a/crdSchemas/master-standalone/tlsroute-stable-v1.json b/crdSchemas/master-standalone/tlsroute-stable-v1.json
new file mode 100644
index 0000000..5c9a7c1
--- /dev/null
+++ b/crdSchemas/master-standalone/tlsroute-stable-v1.json
@@ -0,0 +1,374 @@
+{
+ "description": "The TLSRoute resource is similar to TCPRoute, but can be configured\nto match against TLS-specific metadata. This allows more flexibility\nin matching streams for a given TLS listener.\n\nIf you need to forward traffic to a single target for a TLS listener, you\ncould choose to use a TCPRoute with a TLS listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TLSRoute.",
+ "properties": {
+ "hostnames": {
+ "description": "Hostnames defines a set of SNI hostnames that should match against the\nSNI attribute of TLS ClientHello message in TLS handshake. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n1. IPs are not allowed in SNI hostnames per RFC 6066.\n2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.",
+ "items": {
+ "description": "Hostname is the fully qualified domain name of a network host. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n 1. IPs are not allowed.\n 2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nHostname can be \"precise\" which is a domain name without the terminating\ndot of a network host (e.g. \"foo.example.com\") or \"wildcard\", which is a\ndomain name prefixed with a single wildcard label (e.g. `*.example.com`).\n\nNote that as per RFC1035 and RFC1123, a *label* must consist of lower case\nalphanumeric characters or '-', and must start and end with an alphanumeric\ncharacter. No other punctuation is allowed.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Hostnames cannot contain an IP",
+ "rule": "self.all(h, !isIP(h))"
+ },
+ {
+ "message": "Hostnames must be valid based on RFC-1123",
+ "rule": "self.all(h, !h.contains('*') ? h.matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$') : true)"
+ },
+ {
+ "message": "Wildcards on hostnames must be the first label, and the rest of hostname must be valid based on RFC-1123",
+ "rule": "self.all(h, h.contains('*') ? (h.startsWith('*.') && h.substring(2).matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$')) : true)"
+ }
+ ]
+ },
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of actions.",
+ "items": {
+ "description": "TLSRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or\na Service with no endpoints), the rule performs no forwarding; if no\nfilters are specified that would result in a response being sent, the\nunderlying implementation must actively reject request attempts to this\nbackend, by rejecting the connection. Request rejections must respect\nweight; if an invalid backend is requested to have 80% of requests, then\n80% of requests must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 1,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "hostnames",
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TLSRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/tlsroute-stable-v1alpha2.json b/crdSchemas/master-standalone/tlsroute-stable-v1alpha2.json
new file mode 100644
index 0000000..8e29f4c
--- /dev/null
+++ b/crdSchemas/master-standalone/tlsroute-stable-v1alpha2.json
@@ -0,0 +1,364 @@
+{
+ "description": "The TLSRoute resource is similar to TCPRoute, but can be configured\nto match against TLS-specific metadata. This allows more flexibility\nin matching streams for a given TLS listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TLSRoute.",
+ "properties": {
+ "hostnames": {
+ "description": "Hostnames defines a set of SNI names that should match against the\nSNI attribute of TLS ClientHello message in TLS handshake. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n1. IPs are not allowed in SNI names per RFC 6066.\n2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nIf a hostname is specified by both the Listener and TLSRoute, there\nmust be at least one intersecting hostname for the TLSRoute to be\nattached to the Listener. For example:\n\n* A Listener with `test.example.com` as the hostname matches TLSRoutes\n that have either not specified any hostnames, or have specified at\n least one of `test.example.com` or `*.example.com`.\n* A Listener with `*.example.com` as the hostname matches TLSRoutes\n that have either not specified any hostnames or have specified at least\n one hostname that matches the Listener hostname. For example,\n `test.example.com` and `*.example.com` would both match. On the other\n hand, `example.com` and `test.example.net` would not match.\n\nIf both the Listener and TLSRoute have specified hostnames, any\nTLSRoute hostnames that do not match the Listener hostname MUST be\nignored. For example, if a Listener specified `*.example.com`, and the\nTLSRoute specified `test.example.com` and `test.example.net`,\n`test.example.net` must not be considered for a match.\n\nIf both the Listener and TLSRoute have specified hostnames, and none\nmatch with the criteria above, then the TLSRoute is not accepted. The\nimplementation must raise an 'Accepted' Condition with a status of\n`False` in the corresponding RouteParentStatus.\n\nSupport: Core",
+ "items": {
+ "description": "Hostname is the fully qualified domain name of a network host. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n 1. IPs are not allowed.\n 2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nHostname can be \"precise\" which is a domain name without the terminating\ndot of a network host (e.g. \"foo.example.com\") or \"wildcard\", which is a\ndomain name prefixed with a single wildcard label (e.g. `*.example.com`).\n\nNote that as per RFC1035 and RFC1123, a *label* must consist of lower case\nalphanumeric characters or '-', and must start and end with an alphanumeric\ncharacter. No other punctuation is allowed.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of TLS matchers and actions.",
+ "items": {
+ "description": "TLSRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or\na Service with no endpoints), the rule performs no forwarding; if no\nfilters are specified that would result in a response being sent, the\nunderlying implementation must actively reject request attempts to this\nbackend, by rejecting the connection. Request rejections must respect\nweight; if an invalid backend is requested to have 80% of requests, then\n80% of requests must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
+ }
+ ]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TLSRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/tlsroute-stable-v1alpha3.json b/crdSchemas/master-standalone/tlsroute-stable-v1alpha3.json
new file mode 100644
index 0000000..5c9a7c1
--- /dev/null
+++ b/crdSchemas/master-standalone/tlsroute-stable-v1alpha3.json
@@ -0,0 +1,374 @@
+{
+ "description": "The TLSRoute resource is similar to TCPRoute, but can be configured\nto match against TLS-specific metadata. This allows more flexibility\nin matching streams for a given TLS listener.\n\nIf you need to forward traffic to a single target for a TLS listener, you\ncould choose to use a TCPRoute with a TLS listener.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of TLSRoute.",
+ "properties": {
+ "hostnames": {
+ "description": "Hostnames defines a set of SNI hostnames that should match against the\nSNI attribute of TLS ClientHello message in TLS handshake. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n1. IPs are not allowed in SNI hostnames per RFC 6066.\n2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.",
+ "items": {
+ "description": "Hostname is the fully qualified domain name of a network host. This matches\nthe RFC 1123 definition of a hostname with 2 notable exceptions:\n\n 1. IPs are not allowed.\n 2. A hostname may be prefixed with a wildcard label (`*.`). The wildcard\n label must appear by itself as the first label.\n\nHostname can be \"precise\" which is a domain name without the terminating\ndot of a network host (e.g. \"foo.example.com\") or \"wildcard\", which is a\ndomain name prefixed with a single wildcard label (e.g. `*.example.com`).\n\nNote that as per RFC1035 and RFC1123, a *label* must consist of lower case\nalphanumeric characters or '-', and must start and end with an alphanumeric\ncharacter. No other punctuation is allowed.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^(\\*\\.)?[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Hostnames cannot contain an IP",
+ "rule": "self.all(h, !isIP(h))"
+ },
+ {
+ "message": "Hostnames must be valid based on RFC-1123",
+ "rule": "self.all(h, !h.contains('*') ? h.matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$') : true)"
+ },
+ {
+ "message": "Wildcards on hostnames must be the first label, and the rest of hostname must be valid based on RFC-1123",
+ "rule": "self.all(h, h.contains('*') ? (h.startsWith('*.') && h.substring(2).matches('^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*)$')) : true)"
+ }
+ ]
+ },
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of actions.",
+ "items": {
+ "description": "TLSRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or\na Service with no endpoints), the rule performs no forwarding; if no\nfilters are specified that would result in a response being sent, the\nunderlying implementation must actively reject request attempts to this\nbackend, by rejecting the connection. Request rejections must respect\nweight; if an invalid backend is requested to have 80% of requests, then\n80% of requests must be rejected instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 1,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "hostnames",
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of TLSRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/udproute-stable-v1alpha2.json b/crdSchemas/master-standalone/udproute-stable-v1alpha2.json
new file mode 100644
index 0000000..7f43170
--- /dev/null
+++ b/crdSchemas/master-standalone/udproute-stable-v1alpha2.json
@@ -0,0 +1,351 @@
+{
+ "description": "UDPRoute provides a way to route UDP traffic. When combined with a Gateway\nlistener, it can be used to forward traffic on the port specified by the\nlistener to a set of backends specified by the UDPRoute.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of UDPRoute.",
+ "properties": {
+ "parentRefs": {
+ "description": "ParentRefs references the resources (usually Gateways) that a Route wants\nto be attached to. Note that the referenced parent resource needs to\nallow this for the attachment to be complete. For Gateways, that means\nthe Gateway needs to allow attachment from Routes of this kind and\nnamespace. For Services, that means the Service must either be in the same\nnamespace for a \"producer\" route, or the mesh implementation must support\nand allow \"consumer\" routes for the referenced Service. ReferenceGrant is\nnot applicable for governing ParentRefs to Services - it is not possible to\ncreate a \"producer\" route for a Service in a different namespace from the\nRoute.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nParentRefs must be _distinct_. This means either that:\n\n* They select different objects. If this is the case, then parentRef\n entries are distinct. In terms of fields, this means that the\n multi-part key defined by `group`, `kind`, `namespace`, and `name` must\n be unique across all parentRef entries in the Route.\n* They do not select different objects, but for each optional field used,\n each ParentRef that selects the same object must set the same set of\n optional fields to different values. If one ParentRef sets a\n combination of optional fields, all must set the same combination.\n\nSome examples:\n\n* If one ParentRef sets `sectionName`, all ParentRefs referencing the\n same object must also set `sectionName`.\n* If one ParentRef sets `port`, all ParentRefs referencing the same\n object must also set `port`.\n* If one ParentRef sets `sectionName` and `port`, all ParentRefs\n referencing the same object must also set `sectionName` and `port`.\n\nIt is possible to separately reference multiple distinct objects that may\nbe collapsed by an implementation. For example, some implementations may\nchoose to merge compatible Gateway Listeners together. If that is the\ncase, the list of routes attached to those resources should also be\nmerged.\n\nNote that for ParentRefs that cross namespace boundaries, there are specific\nrules. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example,\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable other kinds of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.",
+ "items": {
+ "description": "ParentReference identifies an API object (usually a Gateway) that can be considered\na parent of this resource (usually a route). There are two kinds of parent resources\nwith \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nThis API may be extended in the future to support additional kinds of parent\nresources.\n\nThe API object must be valid in the cluster; the Group and Kind must\nbe registered in the cluster for this reference to be valid.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))"
+ },
+ {
+ "message": "sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",
+ "rule": "self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))"
+ }
+ ]
+ },
+ "rules": {
+ "description": "Rules are a list of UDP matchers and actions.",
+ "items": {
+ "description": "UDPRouteRule is the configuration for a given rule.",
+ "properties": {
+ "backendRefs": {
+ "description": "BackendRefs defines the backend(s) where matching requests should be\nsent. If unspecified or invalid (refers to a nonexistent resource or a\nService with no endpoints), the underlying implementation MUST actively\nreject connection attempts to this backend. Packet drops must\nrespect weight; if an invalid backend is requested to have 80% of\nthe packets, then 80% of packets must be dropped instead.\n\nSupport: Core for Kubernetes Service\n\nSupport: Extended for Kubernetes ServiceImport\n\nSupport: Implementation-specific for any other resource\n\nSupport for weight: Extended",
+ "items": {
+ "description": "BackendRef defines how a Route should forward a request to a Kubernetes\nresource.\n\nNote that when a namespace different than the local namespace is specified, a\nReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\n\nWhen the BackendRef points to a Kubernetes Service, implementations SHOULD\nhonor the appProtocol field if it is set for the target Service Port.\n\nImplementations supporting appProtocol SHOULD recognize the Kubernetes\nStandard Application Protocols defined in KEP-3726.\n\nIf a Service appProtocol isn't specified, an implementation MAY infer the\nbackend protocol through its own means. Implementations MAY infer the\nprotocol from the Route type referring to the backend Service.\n\nIf a Route is not able to send traffic to the backend using the specified\nprotocol then the backend is considered invalid. Implementations MUST set the\n\"ResolvedRefs\" condition to \"False\" with the \"UnsupportedProtocol\" reason.\n\n\nNote that when the BackendTLSPolicy object is enabled by the implementation,\nthere are some extra rules about validity to consider here. See the fields\nwhere this struct is used for more information about the exact behavior.",
+ "properties": {
+ "group": {
+ "default": "",
+ "description": "Group is the group of the referent. For example, \"gateway.networking.k8s.io\".\nWhen unspecified or empty string, core API group is inferred.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Service",
+ "description": "Kind is the Kubernetes resource kind of the referent. For example\n\"Service\".\n\nDefaults to \"Service\" when not specified.\n\nExternalName services can refer to CNAME DNS records that may live\noutside of the cluster and as such are difficult to reason about in\nterms of conformance. They also may not be safe to forward to (see\nCVE-2021-25740 for more information). Implementations SHOULD NOT\nsupport ExternalName Services.\n\nSupport: Core (Services with a type other than ExternalName)\n\nSupport: Implementation-specific (Services with type ExternalName)",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the backend. When unspecified, the local\nnamespace is inferred.\n\nNote that when a namespace different than the local namespace is specified,\na ReferenceGrant object is required in the referent namespace to allow that\nnamespace's owner to accept the reference. See the ReferenceGrant\ndocumentation for details.\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port specifies the destination port number to use for this resource.\nPort is required when the referent is a Kubernetes Service. In this\ncase, the port number is the service port number, not the target port.\nFor other resources, destination port might be derived from the referent\nresource or this field.",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "weight": {
+ "default": 1,
+ "description": "Weight specifies the proportion of requests forwarded to the referenced\nbackend. This is computed as weight/(sum of all weights in this\nBackendRefs list). For non-zero values, there may be some epsilon from\nthe exact proportion defined here depending on the precision an\nimplementation supports. Weight is not a percentage and the sum of\nweights does not need to equal 100.\n\nIf only one backend is specified and it has a weight greater than 0, 100%\nof the traffic is forwarded to that backend. If weight is set to 0, no\ntraffic should be forwarded for this entry. If unspecified, weight\ndefaults to 1.\n\nSupport for this field varies based on the context where used.",
+ "format": "int32",
+ "maximum": 1000000,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "Must have port for Service reference",
+ "rule": "(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ },
+ "name": {
+ "description": "Name is the name of the route rule. This name MUST be unique within a Route if it is set.\n\nSupport: Extended",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "backendRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic",
+ "x-kubernetes-validations": [
+ {
+ "message": "Rule name must be unique within the route",
+ "rule": "self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))"
+ }
+ ]
+ },
+ "useDefaultGateways": {
+ "description": "UseDefaultGateways indicates the default Gateway scope to use for this\nRoute. If unset (the default) or set to None, the Route will not be\nattached to any default Gateway; if set, it will be attached to any\ndefault Gateway supporting the named scope, subject to the usual rules\nabout which Routes a Gateway is allowed to claim.\n\nThink carefully before using this functionality! The set of default\nGateways supporting the requested scope can change over time without\nany notice to the Route author, and in many situations it will not be\nappropriate to request a default Gateway for a given Route -- for\nexample, a Route with specific security requirements should almost\ncertainly not use a default Gateway.",
+ "enum": [
+ "All",
+ "None"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "rules"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of UDPRoute.",
+ "properties": {
+ "parents": {
+ "description": "Parents is a list of parent resources (usually Gateways) that are\nassociated with the route, and the status of the route with respect to\neach parent. When this route attaches to a parent, the controller that\nmanages the parent must add an entry to this list when the controller\nfirst sees the route and should update the entry as appropriate when the\nroute or gateway is modified.\n\nNote that parent references that cannot be resolved by an implementation\nof this API will not be added to this list. Implementations of this API\ncan only populate Route status for the Gateways/parent resources they are\nresponsible for.\n\nA maximum of 32 Gateways will be represented in this list. An empty list\nmeans the route has not been attached to any Gateway.",
+ "items": {
+ "description": "RouteParentStatus describes the status of a route with respect to an\nassociated Parent.",
+ "properties": {
+ "conditions": {
+ "description": "Conditions describes the status of the route with respect to the Gateway.\nNote that the route's availability is also subject to the Gateway's own\nstatus conditions and listener status.\n\nIf the Route's ParentRef specifies an existing Gateway that supports\nRoutes of this kind AND that Gateway's controller has sufficient access,\nthen that Gateway's controller MUST set the \"Accepted\" condition on the\nRoute, to indicate whether the route has been accepted or rejected by the\nGateway, and why.\n\nA Route MUST be considered \"Accepted\" if at least one of the Route's\nrules is implemented by the Gateway.\n\nThere are a number of cases where the \"Accepted\" condition may not be set\ndue to lack of controller visibility, that includes when:\n\n* The Route refers to a nonexistent parent.\n* The Route is of a type that the controller does not support.\n* The Route is in a namespace to which the controller does not have access.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ },
+ "parentRef": {
+ "description": "ParentRef corresponds with a ParentRef in the spec that this\nRouteParentStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "conditions",
+ "controllerName",
+ "parentRef"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 32,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "parents"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/xbackendtrafficpolicy-stable-v1alpha1.json b/crdSchemas/master-standalone/xbackendtrafficpolicy-stable-v1alpha1.json
new file mode 100644
index 0000000..f9cf262
--- /dev/null
+++ b/crdSchemas/master-standalone/xbackendtrafficpolicy-stable-v1alpha1.json
@@ -0,0 +1,344 @@
+{
+ "description": "XBackendTrafficPolicy defines the configuration for how traffic to a\ntarget backend should be handled.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of BackendTrafficPolicy.",
+ "properties": {
+ "retryConstraint": {
+ "description": "RetryConstraint defines the configuration for when to allow or prevent\nfurther retries to a target backend, by dynamically calculating a 'retry\nbudget'. This budget is calculated based on the percentage of incoming\ntraffic composed of retries over a given time interval. Once the budget\nis exceeded, additional retries will be rejected.\n\nFor example, if the retry budget interval is 10 seconds, there have been\n1000 active requests in the past 10 seconds, and the allowed percentage\nof requests that can be retried is 20% (the default), then 200 of those\nrequests may be composed of retries. Active requests will only be\nconsidered for the duration of the interval when calculating the retry\nbudget. Retrying the same original request multiple times within the\nretry budget interval will lead to each retry being counted towards\ncalculating the budget.\n\nConfiguring a RetryConstraint in BackendTrafficPolicy is compatible with\nHTTPRoute Retry settings for each HTTPRouteRule that targets the same\nbackend. While the HTTPRouteRule Retry stanza can specify whether a\nrequest will be retried, and the number of retry attempts each client\nmay perform, RetryConstraint helps prevent cascading failures such as\nretry storms during periods of consistent failures.\n\nAfter the retry budget has been exceeded, additional retries to the\nbackend MUST return a 503 response to the client.\n\nAdditional configurations for defining a constraint on retries MAY be\ndefined in the future.\n\nSupport: Extended",
+ "properties": {
+ "budget": {
+ "default": {
+ "interval": "10s",
+ "percent": 20
+ },
+ "description": "Budget holds the details of the retry budget configuration.",
+ "properties": {
+ "interval": {
+ "default": "10s",
+ "description": "Interval defines the duration in which requests will be considered\nfor calculating the budget for retries.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "interval cannot be greater than one hour or less than one second",
+ "rule": "!(duration(self) < duration('1s') || duration(self) > duration('1h'))"
+ }
+ ]
+ },
+ "percent": {
+ "default": 20,
+ "description": "Percent defines the maximum percentage of active requests that may\nbe made up of retries.\n\nSupport: Extended",
+ "maximum": 100,
+ "minimum": 0,
+ "type": "integer"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "minRetryRate": {
+ "default": {
+ "count": 10,
+ "interval": "1s"
+ },
+ "description": "MinRetryRate defines the minimum rate of retries that will be allowable\nover a specified duration of time.\n\nThe effective overall minimum rate of retries targeting the backend\nservice may be much higher, as there can be any number of clients which\nare applying this setting locally.\n\nThis ensures that requests can still be retried during periods of low\ntraffic, where the budget for retries may be calculated as a very low\nvalue.\n\nSupport: Extended",
+ "properties": {
+ "count": {
+ "description": "Count specifies the number of requests per time interval.\n\nSupport: Extended",
+ "maximum": 1000000,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "interval": {
+ "description": "Interval specifies the divisor of the rate of requests, the amount of\ntime during which the given count of requests occur.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "interval cannot be greater than one hour",
+ "rule": "!(duration(self) == duration('0s') || duration(self) > duration('1h'))"
+ }
+ ]
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "sessionPersistence": {
+ "description": "SessionPersistence defines and configures session persistence\nfor the backend.\n\nSupport: Extended",
+ "properties": {
+ "absoluteTimeout": {
+ "description": "AbsoluteTimeout defines the absolute timeout of the persistent\nsession. Once the AbsoluteTimeout duration has elapsed, the\nsession becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "cookieConfig": {
+ "description": "CookieConfig provides configuration settings that are specific\nto cookie-based session persistence.\n\nSupport: Core",
+ "properties": {
+ "lifetimeType": {
+ "default": "Session",
+ "description": "LifetimeType specifies whether the cookie has a permanent or\nsession-based lifetime. A permanent cookie persists until its\nspecified expiry time, defined by the Expires or Max-Age cookie\nattributes, while a session cookie is deleted when the current\nsession ends.\n\nWhen set to \"Permanent\", AbsoluteTimeout indicates the\ncookie's lifetime via the Expires or Max-Age cookie attributes\nand is required.\n\nWhen set to \"Session\", AbsoluteTimeout indicates the\nabsolute lifetime of the cookie tracked by the gateway and\nis optional.\n\nDefaults to \"Session\".\n\nSupport: Core for \"Session\" type\n\nSupport: Extended for \"Permanent\" type",
+ "enum": [
+ "Permanent",
+ "Session"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
+ "idleTimeout": {
+ "description": "IdleTimeout defines the idle timeout of the persistent session.\nOnce the session has been idle for more than the specified\nIdleTimeout duration, the session becomes invalid.\n\nSupport: Extended",
+ "pattern": "^([0-9]{1,5}(h|m|s|ms)){1,4}$",
+ "type": "string"
+ },
+ "sessionName": {
+ "description": "SessionName defines the name of the persistent session token\nwhich may be reflected in the cookie or the header. Users\nshould avoid reusing session names to prevent unintended\nconsequences, such as rejection or unpredictable behavior.\n\nSupport: Implementation-specific",
+ "maxLength": 128,
+ "type": "string"
+ },
+ "type": {
+ "default": "Cookie",
+ "description": "Type defines the type of session persistence such as through\nthe use of a header or cookie. Defaults to cookie based session\npersistence.\n\nSupport: Core for \"Cookie\" type\n\nSupport: Extended for \"Header\" type",
+ "enum": [
+ "Cookie",
+ "Header"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "x-kubernetes-validations": [
+ {
+ "message": "AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",
+ "rule": "!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
+ },
+ {
+ "message": "cookieConfig can only be set with type Cookie",
+ "rule": "!has(self.cookieConfig) || self.type == 'Cookie'"
+ }
+ ],
+ "additionalProperties": false
+ },
+ "targetRefs": {
+ "description": "TargetRefs identifies API object(s) to apply this policy to.\nCurrently, Backends (A grouping of like endpoints such as Service,\nServiceImport, or any implementation-specific backendRef) are the only\nvalid API target references.\n\nCurrently, a TargetRef cannot be scoped to a specific port on a\nService.",
+ "items": {
+ "description": "LocalPolicyTargetReference identifies an API object to apply a direct or\ninherited policy to. This should be used as part of Policy resources\nthat can target Gateway API resources. For more information on how this\npolicy attachment model works, and a sample Policy resource, refer to\nthe policy attachment documentation for Gateway API.",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the target resource.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the target resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the target resource.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "required": [
+ "targetRefs"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "description": "Status defines the current state of BackendTrafficPolicy.",
+ "properties": {
+ "ancestors": {
+ "description": "Ancestors is a list of ancestor resources (usually Gateways) that are\nassociated with the policy, and the status of the policy with respect to\neach ancestor. When this policy attaches to a parent, the controller that\nmanages the parent and the ancestors MUST add an entry to this list when\nthe controller first sees the policy and SHOULD update the entry as\nappropriate when the relevant ancestor is modified.\n\nNote that choosing the relevant ancestor is left to the Policy designers;\nan important part of Policy design is designing the right object level at\nwhich to namespace this status.\n\nNote also that implementations MUST ONLY populate ancestor status for\nthe Ancestor resources they are responsible for. Implementations MUST\nuse the ControllerName field to uniquely identify the entries in this list\nthat they are responsible for.\n\nNote that to achieve this, the list of PolicyAncestorStatus structs\nMUST be treated as a map with a composite key, made up of the AncestorRef\nand ControllerName fields combined.\n\nA maximum of 16 ancestors will be represented in this list. An empty list\nmeans the Policy is not relevant for any ancestors.\n\nIf this slice is full, implementations MUST NOT add further entries.\nInstead they MUST consider the policy unimplementable and signal that\non any related resources such as the ancestor that would be referenced\nhere. For example, if this list was full on BackendTLSPolicy, no\nadditional Gateways would be able to reference the Service targeted by\nthe BackendTLSPolicy.",
+ "items": {
+ "description": "PolicyAncestorStatus describes the status of a route with respect to an\nassociated Ancestor.\n\nAncestors refer to objects that are either the Target of a policy or above it\nin terms of object hierarchy. For example, if a policy targets a Service, the\nPolicy's Ancestors are, in order, the Service, the HTTPRoute, the Gateway, and\nthe GatewayClass. Almost always, in this hierarchy, the Gateway will be the most\nuseful object to place Policy status on, so we recommend that implementations\nSHOULD use Gateway as the PolicyAncestorStatus object unless the designers\nhave a _very_ good reason otherwise.\n\nIn the context of policy attachment, the Ancestor is used to distinguish which\nresource results in a distinct application of this policy. For example, if a policy\ntargets a Service, it may have a distinct result per attached Gateway.\n\nPolicies targeting the same resource may have different effects depending on the\nancestors of those resources. For example, different Gateways targeting the same\nService may have different capabilities, especially if they have different underlying\nimplementations.\n\nFor example, in BackendTLSPolicy, the Policy attaches to a Service that is\nused as a backend in a HTTPRoute that is itself attached to a Gateway.\nIn this case, the relevant object for status is the Gateway, and that is the\nancestor object referred to in this status.\n\nNote that a parent is also an ancestor, so for objects where the parent is the\nrelevant object for status, this struct SHOULD still be used.\n\nThis struct is intended to be used in a slice that's effectively a map,\nwith a composite key made up of the AncestorRef and the ControllerName.",
+ "properties": {
+ "ancestorRef": {
+ "description": "AncestorRef corresponds with a ParentRef in the spec that this\nPolicyAncestorStatus struct describes the status of.",
+ "properties": {
+ "group": {
+ "default": "gateway.networking.k8s.io",
+ "description": "Group is the group of the referent.\nWhen unspecified, \"gateway.networking.k8s.io\" is inferred.\nTo set the core API group (such as for a \"Service\" kind referent),\nGroup must be explicitly set to \"\" (empty string).\n\nSupport: Core",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "default": "Gateway",
+ "description": "Kind is kind of the referent.\n\nThere are two kinds of parent resources with \"Core\" support:\n\n* Gateway (Gateway conformance profile)\n* Service (Mesh conformance profile, ClusterIP Services only)\n\nSupport for other resources is Implementation-Specific.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent. When unspecified, this refers\nto the local namespace of the Route.\n\nNote that there are specific rules for ParentRefs which cross namespace\nboundaries. Cross-namespace references are only valid if they are explicitly\nallowed by something in the namespace they are referring to. For example:\nGateway has the AllowedRoutes field, and ReferenceGrant provides a\ngeneric way to enable any other kind of cross-namespace reference.\n\n\nParentRefs from a Route to a Service in the same namespace are \"producer\"\nroutes, which apply default routing rules to inbound connections from\nany namespace to the Service.\n\nParentRefs from a Route to a Service in a different namespace are\n\"consumer\" routes, and these routing rules are only applied to outbound\nconnections originating from the same namespace as the Route, for which\nthe intended destination of the connections are a Service targeted as a\nParentRef of the Route.\n\n\nSupport: Core",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ },
+ "port": {
+ "description": "Port is the network port this Route targets. It can be interpreted\ndifferently based on the type of parent resource.\n\nWhen the parent resource is a Gateway, this targets all listeners\nlistening on the specified port that also support this kind of Route(and\nselect this Route). It's not recommended to set `Port` unless the\nnetworking behaviors specified in a Route must apply to a specific port\nas opposed to a listener(s) whose port(s) may be changed. When both Port\nand SectionName are specified, the name and port of the selected listener\nmust match both specified values.\n\n\nWhen the parent resource is a Service, this targets a specific port in the\nService spec. When both Port (experimental) and SectionName are specified,\nthe name and port of the selected port must match both specified values.\n\n\nImplementations MAY choose to support other parent resources.\nImplementations supporting other types of parent resources MUST clearly\ndocument how/if Port is interpreted.\n\nFor the purpose of status, an attachment is considered successful as\nlong as the parent resource accepts it partially. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment\nfrom the referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route,\nthe Route MUST be considered detached from the Gateway.\n\nSupport: Extended",
+ "format": "int32",
+ "maximum": 65535,
+ "minimum": 1,
+ "type": "integer"
+ },
+ "sectionName": {
+ "description": "SectionName is the name of a section within the target resource. In the\nfollowing resources, SectionName is interpreted as the following:\n\n* Gateway: Listener name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n* Service: Port name. When both Port (experimental) and SectionName\nare specified, the name and port of the selected listener must match\nboth specified values.\n\nImplementations MAY choose to support attaching Routes to other resources.\nIf that is the case, they MUST clearly document how SectionName is\ninterpreted.\n\nWhen unspecified (empty string), this will reference the entire resource.\nFor the purpose of status, an attachment is considered successful if at\nleast one section in the parent resource accepts it. For example, Gateway\nlisteners can restrict which Routes can attach to them by Route kind,\nnamespace, or hostname. If 1 of 2 Gateway listeners accept attachment from\nthe referencing Route, the Route MUST be considered successfully\nattached. If no Gateway listeners accept attachment from this Route, the\nRoute MUST be considered detached from the Gateway.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "conditions": {
+ "description": "Conditions describes the status of the Policy with respect to the given Ancestor.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "minItems": 1,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "controllerName": {
+ "description": "ControllerName is a domain/path string that indicates the name of the\ncontroller that wrote this status. This corresponds with the\ncontrollerName field on GatewayClass.\n\nExample: \"example.net/gateway-controller\".\n\nThe format of this field is DOMAIN \"/\" PATH, where DOMAIN and PATH are\nvalid Kubernetes names\n(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).\n\nControllers MUST populate this field when writing status. Controllers should ensure that\nentries to status populated with their ControllerName are cleaned up when they are no\nlonger necessary.",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "ancestorRef",
+ "conditions",
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 16,
+ "type": "array",
+ "x-kubernetes-list-type": "atomic"
+ }
+ },
+ "required": [
+ "ancestors"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/master-standalone/xmesh-stable-v1alpha1.json b/crdSchemas/master-standalone/xmesh-stable-v1alpha1.json
new file mode 100644
index 0000000..168daab
--- /dev/null
+++ b/crdSchemas/master-standalone/xmesh-stable-v1alpha1.json
@@ -0,0 +1,203 @@
+{
+ "description": "XMesh defines mesh-wide characteristics of a GAMMA-compliant service mesh.",
+ "properties": {
+ "apiVersion": {
+ "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
+ "type": "string"
+ },
+ "metadata": {
+ "type": "object"
+ },
+ "spec": {
+ "description": "Spec defines the desired state of XMesh.",
+ "properties": {
+ "controllerName": {
+ "description": "ControllerName is the name of a controller that is managing Gateway API\nresources for mesh traffic management. The value of this field MUST be a\ndomain prefixed path.\n\nExample: \"example.com/awesome-mesh\".\n\nThis field is not mutable and cannot be empty.\n\nSupport: Core",
+ "maxLength": 253,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*\\/[A-Za-z0-9\\/\\-._~%!$&'()*+,;=:]+$",
+ "type": "string",
+ "x-kubernetes-validations": [
+ {
+ "message": "Value is immutable",
+ "rule": "self == oldSelf"
+ }
+ ]
+ },
+ "description": {
+ "description": "Description optionally provides a human-readable description of a Mesh.",
+ "maxLength": 64,
+ "type": "string"
+ },
+ "parametersRef": {
+ "description": "ParametersRef is an optional reference to a resource that contains\nimplementation-specific configuration for this Mesh. If no\nimplementation-specific parameters are needed, this field MUST be\nomitted.\n\nParametersRef can reference a standard Kubernetes resource, i.e.\nConfigMap, or an implementation-specific custom resource. The resource\ncan be cluster-scoped or namespace-scoped.\n\nIf the referent cannot be found, refers to an unsupported kind, or when\nthe data within that resource is malformed, the Mesh MUST be rejected\nwith the \"Accepted\" status condition set to \"False\" and an\n\"InvalidParameters\" reason.\n\nSupport: Implementation-specific",
+ "properties": {
+ "group": {
+ "description": "Group is the group of the referent.",
+ "maxLength": 253,
+ "pattern": "^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$",
+ "type": "string"
+ },
+ "kind": {
+ "description": "Kind is kind of the referent.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-zA-Z]([-a-zA-Z0-9]*[a-zA-Z0-9])?$",
+ "type": "string"
+ },
+ "name": {
+ "description": "Name is the name of the referent.",
+ "maxLength": 253,
+ "minLength": 1,
+ "type": "string"
+ },
+ "namespace": {
+ "description": "Namespace is the namespace of the referent.\nThis field is required when referring to a Namespace-scoped resource and\nMUST be unset when referring to a Cluster-scoped resource.",
+ "maxLength": 63,
+ "minLength": 1,
+ "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "group",
+ "kind",
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "controllerName"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "status": {
+ "default": {
+ "conditions": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ }
+ ]
+ },
+ "description": "Status defines the current state of XMesh.",
+ "properties": {
+ "conditions": {
+ "default": [
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Accepted"
+ },
+ {
+ "lastTransitionTime": "1970-01-01T00:00:00Z",
+ "message": "Waiting for controller",
+ "reason": "Pending",
+ "status": "Unknown",
+ "type": "Programmed"
+ }
+ ],
+ "description": "Conditions is the current status from the controller for\nthis Mesh.\n\nControllers should prefer to publish conditions using values\nof MeshConditionType for the type of each Condition.",
+ "items": {
+ "description": "Condition contains details for one aspect of the current state of this API Resource.",
+ "properties": {
+ "lastTransitionTime": {
+ "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
+ "format": "date-time",
+ "type": "string"
+ },
+ "message": {
+ "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
+ "maxLength": 32768,
+ "type": "string"
+ },
+ "observedGeneration": {
+ "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
+ "format": "int64",
+ "minimum": 0,
+ "type": "integer"
+ },
+ "reason": {
+ "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
+ "maxLength": 1024,
+ "minLength": 1,
+ "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
+ "type": "string"
+ },
+ "status": {
+ "description": "status of the condition, one of True, False, Unknown.",
+ "enum": [
+ "True",
+ "False",
+ "Unknown"
+ ],
+ "type": "string"
+ },
+ "type": {
+ "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
+ "maxLength": 316,
+ "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
+ "type": "string"
+ }
+ },
+ "required": [
+ "lastTransitionTime",
+ "message",
+ "reason",
+ "status",
+ "type"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 8,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "type"
+ ],
+ "x-kubernetes-list-type": "map"
+ },
+ "supportedFeatures": {
+ "description": "SupportedFeatures is the set of features the Mesh support.\nIt MUST be sorted in ascending alphabetical order by the Name key.",
+ "items": {
+ "properties": {
+ "name": {
+ "description": "FeatureName is used to describe distinct features that are covered by\nconformance tests.",
+ "type": "string"
+ }
+ },
+ "required": [
+ "name"
+ ],
+ "type": "object",
+ "additionalProperties": false
+ },
+ "maxItems": 64,
+ "type": "array",
+ "x-kubernetes-list-map-keys": [
+ "name"
+ ],
+ "x-kubernetes-list-type": "map"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ }
+ },
+ "required": [
+ "spec"
+ ],
+ "type": "object"
+}
diff --git a/crdSchemas/alertmanager_v1.json b/crdSchemas/monitoring.coreos.com/alertmanager_v1.json
similarity index 99%
rename from crdSchemas/alertmanager_v1.json
rename to crdSchemas/monitoring.coreos.com/alertmanager_v1.json
index 2d7d8f0..20cc906 100644
--- a/crdSchemas/alertmanager_v1.json
+++ b/crdSchemas/monitoring.coreos.com/alertmanager_v1.json
@@ -1392,7 +1392,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -3692,7 +3692,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -5236,7 +5236,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -7501,7 +7501,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -7650,7 +7650,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
@@ -8291,6 +8291,7 @@
"getConcurrency": {
"description": "getConcurrency defines the maximum number of GET requests processed concurrently. This corresponds to the\nAlertmanager's `--web.get-concurrency` flag.",
"format": "int32",
+ "minimum": 0,
"type": "integer"
},
"httpConfig": {
@@ -8343,6 +8344,7 @@
"timeout": {
"description": "timeout for HTTP requests. This corresponds to the Alertmanager's\n`--web.timeout` flag.",
"format": "int32",
+ "minimum": 0,
"type": "integer"
},
"tlsConfig": {
diff --git a/crdSchemas/alertmanagerconfig_v1alpha1.json b/crdSchemas/monitoring.coreos.com/alertmanagerconfig_v1alpha1.json
similarity index 99%
rename from crdSchemas/alertmanagerconfig_v1alpha1.json
rename to crdSchemas/monitoring.coreos.com/alertmanagerconfig_v1alpha1.json
index 13bc334..d8d0671 100644
--- a/crdSchemas/alertmanagerconfig_v1alpha1.json
+++ b/crdSchemas/monitoring.coreos.com/alertmanagerconfig_v1alpha1.json
@@ -703,7 +703,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -1729,7 +1729,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -2455,7 +2455,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -3250,7 +3250,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -4062,7 +4062,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -4878,7 +4878,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5740,7 +5740,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6670,7 +6670,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6968,6 +6968,10 @@
"description": "titleLink defines the URL that the title will link to when clicked.",
"type": "string"
},
+ "updateMessage": {
+ "description": "updateMessage enables updating existing Slack messages instead of creating new ones\nwhen alert state changes. Please note that Webhook URLs do not support updates.\nIt requires Alertmanager >= v0.32.0.",
+ "type": "boolean"
+ },
"username": {
"description": "username defines the slack bot user name.",
"minLength": 1,
@@ -7437,7 +7441,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -7777,6 +7781,10 @@
"description": "topicARN defines the SNS topic ARN, e.g. arn:aws:sns:us-east-2:698519295917:My-Topic.\nIf you don't specify this value, you must specify a value for the PhoneNumber or TargetARN.",
"minLength": 1,
"type": "string"
+ },
+ "useAWSHTTPClient": {
+ "description": "useAWSHTTPClient forces the AWS SDK's BuildableClient instead of\nalertmanager's tracing-wrapped HTTP client. Auto-enabled when AWS_CA_BUNDLE\nis set; set explicitly when configuring ca_bundle via shared AWS config.\n\nIt requires Alertmanager >= 0.33.0.",
+ "type": "boolean"
}
},
"type": "object",
@@ -8273,7 +8281,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9040,7 +9048,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9755,7 +9763,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -10454,7 +10462,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -10690,6 +10698,11 @@
"minimum": 0,
"type": "integer"
},
+ "payload": {
+ "description": "payload define custom payload to be sent to the webhook endpoint.\nThis is an advanced configuration option that allows you\nto define a custom payload using Go templates.\nIt requires Alertmanager >= v0.32.0.",
+ "minLength": 1,
+ "type": "string"
+ },
"sendResolved": {
"description": "sendResolved defines whether or not to notify about resolved alerts.",
"type": "boolean"
@@ -11219,7 +11232,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
diff --git a/crdSchemas/podmonitor_v1.json b/crdSchemas/monitoring.coreos.com/podmonitor_v1.json
similarity index 99%
rename from crdSchemas/podmonitor_v1.json
rename to crdSchemas/monitoring.coreos.com/podmonitor_v1.json
index 402413d..8d6f5c2 100644
--- a/crdSchemas/podmonitor_v1.json
+++ b/crdSchemas/monitoring.coreos.com/podmonitor_v1.json
@@ -19,7 +19,7 @@
"description": "attachMetadata defines additional metadata which is added to the\ndiscovered targets.\n\nIt requires Prometheus >= v2.35.0.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -53,21 +53,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"namespaceSelector": {
@@ -91,6 +95,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -287,6 +292,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -635,7 +641,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -750,6 +756,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -998,6 +1005,7 @@
"sampleLimit": {
"description": "sampleLimit defines a per-scrape limit on the number of scraped samples\nthat will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scrapeClass": {
@@ -1087,6 +1095,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will\nbe accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
}
},
diff --git a/crdSchemas/probe_v1.json b/crdSchemas/monitoring.coreos.com/probe_v1.json
similarity index 99%
rename from crdSchemas/probe_v1.json
rename to crdSchemas/monitoring.coreos.com/probe_v1.json
index c8f33e4..73bb196 100644
--- a/crdSchemas/probe_v1.json
+++ b/crdSchemas/monitoring.coreos.com/probe_v1.json
@@ -164,21 +164,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"metricRelabelings": {
@@ -218,6 +222,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -257,6 +262,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -584,7 +590,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -707,6 +713,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scrapeClass": {
@@ -746,6 +753,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"targets": {
@@ -809,6 +817,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -939,6 +948,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
diff --git a/crdSchemas/prometheus_v1.json b/crdSchemas/monitoring.coreos.com/prometheus_v1.json
similarity index 99%
rename from crdSchemas/prometheus_v1.json
rename to crdSchemas/monitoring.coreos.com/prometheus_v1.json
index c679f5c..b28de5d 100644
--- a/crdSchemas/prometheus_v1.json
+++ b/crdSchemas/monitoring.coreos.com/prometheus_v1.json
@@ -944,6 +944,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -1193,6 +1194,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -2939,7 +2941,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -3296,7 +3298,7 @@
"type": "boolean"
},
"disableCompaction": {
- "description": "disableCompaction when true, the Prometheus compaction is disabled.\nWhen `spec.thanos.objectStorageConfig` or `spec.objectStorageConfigFile` are defined, the operator automatically\ndisables block compaction to avoid race conditions during block uploads (as the Thanos documentation recommends).",
+ "description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.41.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.41.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.",
"type": "boolean"
},
"dnsConfig": {
@@ -3394,21 +3396,25 @@
"enforcedKeepDroppedTargets": {
"description": "enforcedKeepDroppedTargets when defined specifies a global limit on the number of targets\ndropped by relabeling that will be kept in memory. The value overrides\nany `spec.keepDroppedTargets` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.keepDroppedTargets` is\ngreater than zero and less than `spec.enforcedKeepDroppedTargets`.\n\nIt requires Prometheus >= v2.47.0.\n\nWhen both `enforcedKeepDroppedTargets` and `keepDroppedTargets` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined keepDroppedTargets value will inherit the global keepDroppedTargets value (Prometheus >= 2.45.0) or the enforcedKeepDroppedTargets value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedKeepDroppedTargets` is greater than the `keepDroppedTargets`, the `keepDroppedTargets` will be set to `enforcedKeepDroppedTargets`.\n* Scrape objects with a keepDroppedTargets value less than or equal to enforcedKeepDroppedTargets keep their specific value.\n* Scrape objects with a keepDroppedTargets value greater than enforcedKeepDroppedTargets are set to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelLimit": {
"description": "enforcedLabelLimit when defined specifies a global limit on the number\nof labels per sample. The value overrides any `spec.labelLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelLimit` is\ngreater than zero and less than `spec.enforcedLabelLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelLimit` and `labelLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelLimit value will inherit the global labelLimit value (Prometheus >= 2.45.0) or the enforcedLabelLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelLimit` is greater than the `labelLimit`, the `labelLimit` will be set to `enforcedLabelLimit`.\n* Scrape objects with a labelLimit value less than or equal to enforcedLabelLimit keep their specific value.\n* Scrape objects with a labelLimit value greater than enforcedLabelLimit are set to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelNameLengthLimit": {
"description": "enforcedLabelNameLengthLimit when defined specifies a global limit on the length\nof labels name per sample. The value overrides any `spec.labelNameLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelNameLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelNameLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelNameLengthLimit` and `labelNameLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelNameLengthLimit value will inherit the global labelNameLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelNameLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelNameLengthLimit` is greater than the `labelNameLengthLimit`, the `labelNameLengthLimit` will be set to `enforcedLabelNameLengthLimit`.\n* Scrape objects with a labelNameLengthLimit value less than or equal to enforcedLabelNameLengthLimit keep their specific value.\n* Scrape objects with a labelNameLengthLimit value greater than enforcedLabelNameLengthLimit are set to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelValueLengthLimit": {
"description": "enforcedLabelValueLengthLimit when not null defines a global limit on the length\nof labels value per sample. The value overrides any `spec.labelValueLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelValueLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelValueLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelValueLengthLimit` and `labelValueLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelValueLengthLimit value will inherit the global labelValueLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelValueLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelValueLengthLimit` is greater than the `labelValueLengthLimit`, the `labelValueLengthLimit` will be set to `enforcedLabelValueLengthLimit`.\n* Scrape objects with a labelValueLengthLimit value less than or equal to enforcedLabelValueLengthLimit keep their specific value.\n* Scrape objects with a labelValueLengthLimit value greater than enforcedLabelValueLengthLimit are set to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedNamespaceLabel": {
@@ -3418,11 +3424,13 @@
"enforcedSampleLimit": {
"description": "enforcedSampleLimit when defined specifies a global limit on the number\nof scraped samples that will be accepted. This overrides any\n`spec.sampleLimit` set by ServiceMonitor, PodMonitor, Probe objects\nunless `spec.sampleLimit` is greater than zero and less than\n`spec.enforcedSampleLimit`.\n\nIt is meant to be used by admins to keep the overall number of\nsamples/series under a desired limit.\n\nWhen both `enforcedSampleLimit` and `sampleLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined sampleLimit value will inherit the global sampleLimit value (Prometheus >= 2.45.0) or the enforcedSampleLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedSampleLimit` is greater than the `sampleLimit`, the `sampleLimit` will be set to `enforcedSampleLimit`.\n* Scrape objects with a sampleLimit value less than or equal to enforcedSampleLimit keep their specific value.\n* Scrape objects with a sampleLimit value greater than enforcedSampleLimit are set to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedTargetLimit": {
"description": "enforcedTargetLimit when defined specifies a global limit on the number\nof scraped targets. The value overrides any `spec.targetLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.targetLimit` is\ngreater than zero and less than `spec.enforcedTargetLimit`.\n\nIt is meant to be used by admins to to keep the overall number of\ntargets under a desired limit.\n\nWhen both `enforcedTargetLimit` and `targetLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined targetLimit value will inherit the global targetLimit value (Prometheus >= 2.45.0) or the enforcedTargetLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedTargetLimit` is greater than the `targetLimit`, the `targetLimit` will be set to `enforcedTargetLimit`.\n* Scrape objects with a targetLimit value less than or equal to enforcedTargetLimit keep their specific value.\n* Scrape objects with a targetLimit value greater than enforcedTargetLimit are set to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"evaluationInterval": {
@@ -4612,7 +4620,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -4967,21 +4975,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"listenLocal": {
@@ -5066,6 +5078,14 @@
"description": "keepIdentifyingResourceAttributes enables adding `service.name`, `service.namespace` and `service.instance.id`\nresource attributes to the `target_info` metric, on top of converting them into the `instance` and `job` labels.\n\nIt requires Prometheus >= v3.1.0.",
"type": "boolean"
},
+ "labelNamePreserveMultipleUnderscores": {
+ "description": "labelNamePreserveMultipleUnderscores enables preserving of multiple consecutive underscores in label names when translation_strategy uses\nunderscore escaping.\nWhen true (default), multiple consecutive underscores are preserved during label name sanitization.\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
+ "labelNameUnderscoreSanitization": {
+ "description": "labelNameUnderscoreSanitization controls whether to enable prepending of 'key_' to labels starting with '_'.\nReserved labels starting with '__' are not modified.\nThis is only relevant when translation_strategy uses underscore escaping (e.g., \"UnderscoreEscapingWithSuffixes\" or \"UnderscoreEscapingWithoutSuffixes\").\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
"promoteAllResourceAttributes": {
"description": "promoteAllResourceAttributes promotes all resource attributes to metric labels except the ones defined in `ignoreResourceAttributes`.\n\nCannot be true when `promoteResourceAttributes` is defined.\nIt requires Prometheus >= v3.5.0.",
"type": "boolean"
@@ -5870,7 +5890,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6121,7 +6141,8 @@
"additionalProperties": false
},
"url": {
- "description": "url defines the URL of the endpoint to query from.",
+ "description": "url defines the URL of the endpoint to query from.\n\nIt must use the HTTP or HTTPS scheme.",
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6386,7 +6407,7 @@
"type": "integer"
},
"send": {
- "description": "send defines whether metric metadata is sent to the remote storage or not.",
+ "description": "send defines whether metric metadata is sent to the remote storage or not.\n\nThe setting is ignored when Remote Write message's version 2.0 is used.",
"type": "boolean"
},
"sendInterval": {
@@ -6718,7 +6739,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -7144,6 +7165,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -7427,6 +7449,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"schedulerName": {
@@ -7442,7 +7465,7 @@
"description": "attachMetadata defines additional metadata to the discovered targets.\nWhen the scrape object defines its own configuration, it takes\nprecedence over the scrape class configuration.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -7540,6 +7563,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -7614,6 +7638,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -8251,7 +8276,7 @@
"type": "string"
},
"shardRetentionPolicy": {
- "description": "shardRetentionPolicy defines the retention policy for the Prometheus shards.\n(Alpha) Using this field requires the 'PrometheusShardRetentionPolicy' feature gate to be enabled.\n\nThe final goals for this feature can be seen at https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/proposals/202310-shard-autoscaling.md#graceful-scale-down-of-prometheus-servers,\nhowever, the feature is not yet fully implemented in this PR. The limitation being:\n* Retention duration is not settable, for now, shards are retained forever.",
+ "description": "shardRetentionPolicy defines the retention policy for the Prometheus shards.\n\n(Beta) Using this mode requires the `PrometheusShardRetentionPolicy` feature gate (enabled by default).",
"properties": {
"retain": {
"description": "retain defines the config for retention when the retention policy is set\nto `Retain`.\n\nIf not defined, the operator will use the retention duration configured\nfor the Prometheus data. If the resource uses size-based retention, the\nshard(s) are kept forever (unless manually deleted).",
@@ -8321,7 +8346,8 @@
"additionalProperties": false
},
"shards": {
- "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.",
+ "default": 1,
+ "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.\n\nDefault: 1",
"format": "int32",
"type": "integer"
},
@@ -8891,6 +8917,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"terminationGracePeriodSeconds": {
@@ -9751,10 +9778,38 @@
"tsdb": {
"description": "tsdb defines the runtime reloadable configuration of the timeseries database(TSDB).\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"properties": {
+ "chunkEncoding": {
+ "description": "chunkEncoding configures per-chunk-type encoding overrides.\n\nIt requires Prometheus >= v3.13.0.\n\nNotice: Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).",
+ "properties": {
+ "floats": {
+ "description": "floats selects the encoding used for float chunks.\nValid values are \"Xor\" and \"Xor2\".\n\nNotice:\n * Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).\n * Setting \"Xor2\" automatically adds the `xor2-encoding` feature flag.\n\nIt requires Prometheus >= v3.13.0.",
+ "enum": [
+ "Xor",
+ "Xor2"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"outOfOrderTimeWindow": {
"description": "outOfOrderTimeWindow defines how old an out-of-order/out-of-bounds sample can be with\nrespect to the TSDB max time.\n\nAn out-of-order/out-of-bounds sample is ingested into the TSDB as long as\nthe timestamp of the sample is >= (TSDB.MaxTime - outOfOrderTimeWindow).\n\nThis is an *experimental feature*, it may change in any upcoming release\nin a breaking way.\n\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string"
+ },
+ "staleSeriesCompactionThreshold": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "staleSeriesCompactionThreshold configures the trigger point for compacting\nstale series from memory into persistent blocks and removing those stale\nseries from memory.\n\nThe threshold is a number between 0.0 and 1.0. It represents the ratio of\nstale series in memory to the total series in memory. The stale series\ncompaction is triggered when this ratio crosses the configured threshold.\nIt may not trigger the stale series compaction if the usual head compaction\nis about to happen soon.\n\nIf set to 0, stale series compaction is disabled.\n\nIt requires Prometheus >= v3.10.0.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
}
},
"type": "object",
@@ -10601,7 +10656,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -10750,7 +10805,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
diff --git a/crdSchemas/prometheusagent_v1alpha1.json b/crdSchemas/monitoring.coreos.com/prometheusagent_v1alpha1.json
similarity index 99%
rename from crdSchemas/prometheusagent_v1alpha1.json
rename to crdSchemas/monitoring.coreos.com/prometheusagent_v1alpha1.json
index 62f5ac3..2a6f001 100644
--- a/crdSchemas/prometheusagent_v1alpha1.json
+++ b/crdSchemas/monitoring.coreos.com/prometheusagent_v1alpha1.json
@@ -2262,7 +2262,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -2709,21 +2709,25 @@
"enforcedKeepDroppedTargets": {
"description": "enforcedKeepDroppedTargets when defined specifies a global limit on the number of targets\ndropped by relabeling that will be kept in memory. The value overrides\nany `spec.keepDroppedTargets` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.keepDroppedTargets` is\ngreater than zero and less than `spec.enforcedKeepDroppedTargets`.\n\nIt requires Prometheus >= v2.47.0.\n\nWhen both `enforcedKeepDroppedTargets` and `keepDroppedTargets` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined keepDroppedTargets value will inherit the global keepDroppedTargets value (Prometheus >= 2.45.0) or the enforcedKeepDroppedTargets value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedKeepDroppedTargets` is greater than the `keepDroppedTargets`, the `keepDroppedTargets` will be set to `enforcedKeepDroppedTargets`.\n* Scrape objects with a keepDroppedTargets value less than or equal to enforcedKeepDroppedTargets keep their specific value.\n* Scrape objects with a keepDroppedTargets value greater than enforcedKeepDroppedTargets are set to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelLimit": {
"description": "enforcedLabelLimit when defined specifies a global limit on the number\nof labels per sample. The value overrides any `spec.labelLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelLimit` is\ngreater than zero and less than `spec.enforcedLabelLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelLimit` and `labelLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelLimit value will inherit the global labelLimit value (Prometheus >= 2.45.0) or the enforcedLabelLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelLimit` is greater than the `labelLimit`, the `labelLimit` will be set to `enforcedLabelLimit`.\n* Scrape objects with a labelLimit value less than or equal to enforcedLabelLimit keep their specific value.\n* Scrape objects with a labelLimit value greater than enforcedLabelLimit are set to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelNameLengthLimit": {
"description": "enforcedLabelNameLengthLimit when defined specifies a global limit on the length\nof labels name per sample. The value overrides any `spec.labelNameLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelNameLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelNameLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelNameLengthLimit` and `labelNameLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelNameLengthLimit value will inherit the global labelNameLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelNameLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelNameLengthLimit` is greater than the `labelNameLengthLimit`, the `labelNameLengthLimit` will be set to `enforcedLabelNameLengthLimit`.\n* Scrape objects with a labelNameLengthLimit value less than or equal to enforcedLabelNameLengthLimit keep their specific value.\n* Scrape objects with a labelNameLengthLimit value greater than enforcedLabelNameLengthLimit are set to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedLabelValueLengthLimit": {
"description": "enforcedLabelValueLengthLimit when not null defines a global limit on the length\nof labels value per sample. The value overrides any `spec.labelValueLengthLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.labelValueLengthLimit` is\ngreater than zero and less than `spec.enforcedLabelValueLengthLimit`.\n\nIt requires Prometheus >= v2.27.0.\n\nWhen both `enforcedLabelValueLengthLimit` and `labelValueLengthLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined labelValueLengthLimit value will inherit the global labelValueLengthLimit value (Prometheus >= 2.45.0) or the enforcedLabelValueLengthLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedLabelValueLengthLimit` is greater than the `labelValueLengthLimit`, the `labelValueLengthLimit` will be set to `enforcedLabelValueLengthLimit`.\n* Scrape objects with a labelValueLengthLimit value less than or equal to enforcedLabelValueLengthLimit keep their specific value.\n* Scrape objects with a labelValueLengthLimit value greater than enforcedLabelValueLengthLimit are set to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedNamespaceLabel": {
@@ -2733,11 +2737,13 @@
"enforcedSampleLimit": {
"description": "enforcedSampleLimit when defined specifies a global limit on the number\nof scraped samples that will be accepted. This overrides any\n`spec.sampleLimit` set by ServiceMonitor, PodMonitor, Probe objects\nunless `spec.sampleLimit` is greater than zero and less than\n`spec.enforcedSampleLimit`.\n\nIt is meant to be used by admins to keep the overall number of\nsamples/series under a desired limit.\n\nWhen both `enforcedSampleLimit` and `sampleLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined sampleLimit value will inherit the global sampleLimit value (Prometheus >= 2.45.0) or the enforcedSampleLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedSampleLimit` is greater than the `sampleLimit`, the `sampleLimit` will be set to `enforcedSampleLimit`.\n* Scrape objects with a sampleLimit value less than or equal to enforcedSampleLimit keep their specific value.\n* Scrape objects with a sampleLimit value greater than enforcedSampleLimit are set to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"enforcedTargetLimit": {
"description": "enforcedTargetLimit when defined specifies a global limit on the number\nof scraped targets. The value overrides any `spec.targetLimit` set by\nServiceMonitor, PodMonitor, Probe objects unless `spec.targetLimit` is\ngreater than zero and less than `spec.enforcedTargetLimit`.\n\nIt is meant to be used by admins to to keep the overall number of\ntargets under a desired limit.\n\nWhen both `enforcedTargetLimit` and `targetLimit` are defined and greater than zero, the following rules apply:\n* Scrape objects without a defined targetLimit value will inherit the global targetLimit value (Prometheus >= 2.45.0) or the enforcedTargetLimit value (Prometheus < v2.45.0).\n If Prometheus version is >= 2.45.0 and the `enforcedTargetLimit` is greater than the `targetLimit`, the `targetLimit` will be set to `enforcedTargetLimit`.\n* Scrape objects with a targetLimit value less than or equal to enforcedTargetLimit keep their specific value.\n* Scrape objects with a targetLimit value greater than enforcedTargetLimit are set to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"excludedFromEnforcement": {
@@ -3909,7 +3915,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -4264,21 +4270,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedKeepDroppedTargets.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelNameLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedLabelValueLengthLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"listenLocal": {
@@ -4371,6 +4381,14 @@
"description": "keepIdentifyingResourceAttributes enables adding `service.name`, `service.namespace` and `service.instance.id`\nresource attributes to the `target_info` metric, on top of converting them into the `instance` and `job` labels.\n\nIt requires Prometheus >= v3.1.0.",
"type": "boolean"
},
+ "labelNamePreserveMultipleUnderscores": {
+ "description": "labelNamePreserveMultipleUnderscores enables preserving of multiple consecutive underscores in label names when translation_strategy uses\nunderscore escaping.\nWhen true (default), multiple consecutive underscores are preserved during label name sanitization.\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
+ "labelNameUnderscoreSanitization": {
+ "description": "labelNameUnderscoreSanitization controls whether to enable prepending of 'key_' to labels starting with '_'.\nReserved labels starting with '__' are not modified.\nThis is only relevant when translation_strategy uses underscore escaping (e.g., \"UnderscoreEscapingWithSuffixes\" or \"UnderscoreEscapingWithoutSuffixes\").\n\nNotice: This one has no impact if `nameEscapingScheme` is `AllowUTF8`.\n\nIt requires Prometheus >= v3.8.0.",
+ "type": "boolean"
+ },
"promoteAllResourceAttributes": {
"description": "promoteAllResourceAttributes promotes all resource attributes to metric labels except the ones defined in `ignoreResourceAttributes`.\n\nCannot be true when `promoteResourceAttributes` is defined.\nIt requires Prometheus >= v3.5.0.",
"type": "boolean"
@@ -4932,7 +4950,7 @@
"type": "integer"
},
"send": {
- "description": "send defines whether metric metadata is sent to the remote storage or not.",
+ "description": "send defines whether metric metadata is sent to the remote storage or not.\n\nThe setting is ignored when Remote Write message's version 2.0 is used.",
"type": "boolean"
},
"sendInterval": {
@@ -5264,7 +5282,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5690,6 +5708,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -5838,6 +5857,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedSampleLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"schedulerName": {
@@ -5853,7 +5873,7 @@
"description": "attachMetadata defines additional metadata to the discovered targets.\nWhen the scrape object defines its own configuration, it takes\nprecedence over the scrape class configuration.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -5951,6 +5971,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -6025,6 +6046,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -6698,7 +6720,8 @@
"additionalProperties": false
},
"shards": {
- "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.",
+ "default": 1,
+ "description": "shards defines the number of shards to distribute the scraped targets onto.\n\n`spec.replicas` multiplied by `spec.shards` is the total number of Pods\nbeing created.\n\nWhen not defined, the operator assumes only one shard.\n\nNote that scaling down shards will not reshard data onto the remaining\ninstances, it must be manually moved. Increasing shards will not reshard\ndata either but it will continue to be available from the same\ninstances. To query globally, use either\n* Thanos sidecar + querier for query federation and Thanos Ruler for rules.\n* Remote-write to send metrics to a central location.\n\nBy default, the sharding of targets is performed on:\n* The `__address__` target's metadata label for PodMonitor,\nServiceMonitor and ScrapeConfig resources.\n* The `__param_target__` label for Probe resources.\n\nUsers can define their own sharding implementation by setting the\n`__tmp_hash` label during the target discovery with relabeling\nconfiguration (either in the monitoring resources or via scrape class).\n\nYou can also disable sharding on a specific target by setting the\n`__tmp_disable_sharding` label with relabeling configuration. When\nthe label value isn't empty, all Prometheus shards will scrape the target.\n\nDefault: 1",
"format": "int32",
"type": "integer"
},
@@ -7264,6 +7287,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.\nOnly valid in Prometheus versions 2.45.0 and newer.\n\nNote that the global limit only applies to scrape objects that don't specify an explicit limit value.\nIf you want to enforce a maximum limit for all scrape objects, refer to enforcedTargetLimit.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"terminationGracePeriodSeconds": {
@@ -7654,10 +7678,38 @@
"tsdb": {
"description": "tsdb defines the runtime reloadable configuration of the timeseries database(TSDB).\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"properties": {
+ "chunkEncoding": {
+ "description": "chunkEncoding configures per-chunk-type encoding overrides.\n\nIt requires Prometheus >= v3.13.0.\n\nNotice: Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).",
+ "properties": {
+ "floats": {
+ "description": "floats selects the encoding used for float chunks.\nValid values are \"Xor\" and \"Xor2\".\n\nNotice:\n * Setting \"Xor\" is incompatible with --enable-feature=st-storage\n(XOR chunks do not store start timestamps).\n * Setting \"Xor2\" automatically adds the `xor2-encoding` feature flag.\n\nIt requires Prometheus >= v3.13.0.",
+ "enum": [
+ "Xor",
+ "Xor2"
+ ],
+ "type": "string"
+ }
+ },
+ "type": "object",
+ "additionalProperties": false
+ },
"outOfOrderTimeWindow": {
"description": "outOfOrderTimeWindow defines how old an out-of-order/out-of-bounds sample can be with\nrespect to the TSDB max time.\n\nAn out-of-order/out-of-bounds sample is ingested into the TSDB as long as\nthe timestamp of the sample is >= (TSDB.MaxTime - outOfOrderTimeWindow).\n\nThis is an *experimental feature*, it may change in any upcoming release\nin a breaking way.\n\nIt requires Prometheus >= v2.39.0 or PrometheusAgent >= v2.54.0.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string"
+ },
+ "staleSeriesCompactionThreshold": {
+ "anyOf": [
+ {
+ "type": "integer"
+ },
+ {
+ "type": "string"
+ }
+ ],
+ "description": "staleSeriesCompactionThreshold configures the trigger point for compacting\nstale series from memory into persistent blocks and removing those stale\nseries from memory.\n\nThe threshold is a number between 0.0 and 1.0. It represents the ratio of\nstale series in memory to the total series in memory. The stale series\ncompaction is triggered when this ratio crosses the configured threshold.\nIt may not trigger the stale series compaction if the usual head compaction\nis about to happen soon.\n\nIf set to 0, stale series compaction is disabled.\n\nIt requires Prometheus >= v3.10.0.",
+ "pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
+ "x-kubernetes-int-or-string": true
}
},
"type": "object",
@@ -8504,7 +8556,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -8653,7 +8705,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
diff --git a/crdSchemas/prometheusrule_v1.json b/crdSchemas/monitoring.coreos.com/prometheusrule_v1.json
similarity index 100%
rename from crdSchemas/prometheusrule_v1.json
rename to crdSchemas/monitoring.coreos.com/prometheusrule_v1.json
diff --git a/crdSchemas/scrapeconfig_v1alpha1.json b/crdSchemas/monitoring.coreos.com/scrapeconfig_v1alpha1.json
similarity index 99%
rename from crdSchemas/scrapeconfig_v1alpha1.json
rename to crdSchemas/monitoring.coreos.com/scrapeconfig_v1alpha1.json
index 75a7ec3..0734c3f 100644
--- a/crdSchemas/scrapeconfig_v1alpha1.json
+++ b/crdSchemas/monitoring.coreos.com/scrapeconfig_v1alpha1.json
@@ -513,7 +513,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -1282,7 +1282,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -1956,7 +1956,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -2710,7 +2710,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -3411,7 +3411,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -4428,7 +4428,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5181,7 +5181,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5861,7 +5861,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6471,7 +6471,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -6723,6 +6723,7 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"kubernetesSDConfigs": {
@@ -7179,7 +7180,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -7891,7 +7892,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -8135,16 +8136,19 @@
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\nOnly valid in Prometheus versions 2.27.0 and newer.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"lightSailSDConfigs": {
@@ -8595,7 +8599,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9233,7 +9237,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -9520,6 +9524,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -9579,6 +9584,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -10026,7 +10032,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -10589,7 +10595,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -11483,7 +11489,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -11774,6 +11780,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -11810,6 +11817,7 @@
"sampleLimit": {
"description": "sampleLimit defines per-scrape limit on number of scraped samples that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scalewaySDConfigs": {
@@ -12216,6 +12224,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"tlsConfig": {
diff --git a/crdSchemas/servicemonitor_v1.json b/crdSchemas/monitoring.coreos.com/servicemonitor_v1.json
similarity index 98%
rename from crdSchemas/servicemonitor_v1.json
rename to crdSchemas/monitoring.coreos.com/servicemonitor_v1.json
index fb6852a..077d44c 100644
--- a/crdSchemas/servicemonitor_v1.json
+++ b/crdSchemas/monitoring.coreos.com/servicemonitor_v1.json
@@ -19,7 +19,7 @@
"description": "attachMetadata defines additional metadata which is added to the\ndiscovered targets.\n\nIt requires Prometheus >= v2.37.0.",
"properties": {
"node": {
- "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.",
+ "description": "node when set to true, Prometheus attaches node metadata to the discovered\ntargets.\n\nThe Prometheus service account must have the `list` and `watch`\npermissions on the `Nodes` objects.\n\nNode metadata labels are not automatically added to scraped metrics. They are\nexposed as `__meta_kubernetes_node_*` labels and can be copied to timeseries\nwith relabeling configuration.",
"type": "boolean"
}
},
@@ -220,6 +220,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -568,7 +569,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -595,7 +596,7 @@
"type": "string"
},
"port": {
- "description": "port defines the name of the Service port which this endpoint refers to.\n\nIt takes precedence over `targetPort`.",
+ "description": "port defines the name of the Service port which this endpoint refers to\n(e.g. `.spec.ports[].name`).\n\nIt takes precedence over `targetPort`.",
"type": "string"
},
"proxyConnectHeader": {
@@ -676,6 +677,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -732,7 +734,7 @@
"type": "string"
}
],
- "description": "targetPort defines the name or number of the target port of the `Pod` object behind the\nService. The port must be specified with the container's port property.",
+ "description": "targetPort defines the name or number of a container port on Pods selected\nby the Service.\nIf a name, it matches against `.spec.containers[].ports[].name` of the Pods.\nIf a number, it matches against `.spec.containers[].ports[].containerPort` of the Pods.",
"x-kubernetes-int-or-string": true
},
"tlsConfig": {
@@ -944,21 +946,25 @@
"keepDroppedTargets": {
"description": "keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling\nthat will be kept in memory. 0 means no limit.\n\nIt requires Prometheus >= v2.47.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelLimit": {
"description": "labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelNameLengthLimit": {
"description": "labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"labelValueLengthLimit": {
"description": "labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.\n\nIt requires Prometheus >= v2.27.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"namespaceSelector": {
@@ -982,6 +988,7 @@
"nativeHistogramBucketLimit": {
"description": "nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram,\nbuckets will be merged to stay within the limit.\nIt requires Prometheus >= v2.45.0.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"nativeHistogramMinBucketFactor": {
@@ -1007,6 +1014,7 @@
"sampleLimit": {
"description": "sampleLimit defines a per-scrape limit on the number of scraped samples\nthat will be accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"scrapeClass": {
@@ -1111,6 +1119,7 @@
"targetLimit": {
"description": "targetLimit defines a limit on the number of scraped targets that will\nbe accepted.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
}
},
diff --git a/crdSchemas/thanosruler_v1.json b/crdSchemas/monitoring.coreos.com/thanosruler_v1.json
similarity index 99%
rename from crdSchemas/thanosruler_v1.json
rename to crdSchemas/monitoring.coreos.com/thanosruler_v1.json
index c42d27b..c06a62c 100644
--- a/crdSchemas/thanosruler_v1.json
+++ b/crdSchemas/monitoring.coreos.com/thanosruler_v1.json
@@ -1939,7 +1939,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -3729,7 +3729,7 @@
"type": "boolean"
},
"procMount": {
- "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nThis requires the ProcMountType feature flag to be enabled.\nNote that this field cannot be set when spec.os.name is windows.",
+ "description": "procMount denotes the type of proc mount to use for the containers.\nThe default value is Default which uses the container runtime defaults for\nreadonly paths and masked paths.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"readOnlyRootFilesystem": {
@@ -4506,7 +4506,7 @@
"type": "integer"
},
"send": {
- "description": "send defines whether metric metadata is sent to the remote storage or not.",
+ "description": "send defines whether metric metadata is sent to the remote storage or not.\n\nThe setting is ignored when Remote Write message's version 2.0 is used.",
"type": "boolean"
},
"sendInterval": {
@@ -4838,7 +4838,7 @@
},
"tokenUrl": {
"description": "tokenUrl defines the URL to fetch the token from.",
- "minLength": 1,
+ "pattern": "^(http|https)://.+$",
"type": "string"
}
},
@@ -5264,6 +5264,7 @@
"modulus": {
"description": "modulus to take of the hash of the source label values.\n\nOnly applicable when the action is `HashMod`.",
"format": "int64",
+ "minimum": 0,
"type": "integer"
},
"regex": {
@@ -7235,7 +7236,7 @@
"additionalProperties": false
},
"image": {
- "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro) and non-executable files (noexec).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
+ "description": "image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.\nThe volume is resolved at pod startup depending on which PullPolicy value is provided:\n\n- Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\n- Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\n- IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\n\nThe volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.\nA failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.\nThe types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.\nThe OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.\nThe volume will be mounted read-only (ro).\nSub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.\nThe field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.",
"properties": {
"pullPolicy": {
"description": "Policy for pulling OCI objects. Possible values are:\nAlways: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.\nNever: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.\nIfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.\nDefaults to Always if :latest tag is specified, or IfNotPresent otherwise.",
@@ -7384,7 +7385,7 @@
"additionalProperties": false
},
"portworxVolume": {
- "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate\nis on.",
+ "description": "portworxVolume represents a portworx volume attached and mounted on kubelets host machine.\nDeprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type\nare redirected to the pxd.portworx.com CSI driver.",
"properties": {
"fsType": {
"description": "fSType represents the filesystem type to mount\nMust be a filesystem type supported by the host operating system.\nEx. \"ext4\", \"xfs\". Implicitly inferred to be \"ext4\" if unspecified.",
diff --git a/crdSchemas/podlogs_v1alpha2.json b/crdSchemas/monitoring.grafana.com/podlogs_v1alpha2.json
similarity index 100%
rename from crdSchemas/podlogs_v1alpha2.json
rename to crdSchemas/monitoring.grafana.com/podlogs_v1alpha2.json
diff --git a/crdSchemas/alert_v1beta2.json b/crdSchemas/notification.toolkit.fluxcd.io/alert_v1beta2.json
similarity index 100%
rename from crdSchemas/alert_v1beta2.json
rename to crdSchemas/notification.toolkit.fluxcd.io/alert_v1beta2.json
diff --git a/crdSchemas/alert_v1beta3.json b/crdSchemas/notification.toolkit.fluxcd.io/alert_v1beta3.json
similarity index 100%
rename from crdSchemas/alert_v1beta3.json
rename to crdSchemas/notification.toolkit.fluxcd.io/alert_v1beta3.json
diff --git a/crdSchemas/provider_v1beta2.json b/crdSchemas/notification.toolkit.fluxcd.io/provider_v1beta2.json
similarity index 100%
rename from crdSchemas/provider_v1beta2.json
rename to crdSchemas/notification.toolkit.fluxcd.io/provider_v1beta2.json
diff --git a/crdSchemas/provider_v1beta3.json b/crdSchemas/notification.toolkit.fluxcd.io/provider_v1beta3.json
similarity index 100%
rename from crdSchemas/provider_v1beta3.json
rename to crdSchemas/notification.toolkit.fluxcd.io/provider_v1beta3.json
diff --git a/crdSchemas/receiver_v1.json b/crdSchemas/notification.toolkit.fluxcd.io/receiver_v1.json
similarity index 100%
rename from crdSchemas/receiver_v1.json
rename to crdSchemas/notification.toolkit.fluxcd.io/receiver_v1.json
diff --git a/crdSchemas/receiver_v1beta2.json b/crdSchemas/notification.toolkit.fluxcd.io/receiver_v1beta2.json
similarity index 100%
rename from crdSchemas/receiver_v1beta2.json
rename to crdSchemas/notification.toolkit.fluxcd.io/receiver_v1beta2.json
diff --git a/crdSchemas/backup_v1.json b/crdSchemas/postgresql.cnpg.io/backup_v1.json
similarity index 100%
rename from crdSchemas/backup_v1.json
rename to crdSchemas/postgresql.cnpg.io/backup_v1.json
diff --git a/crdSchemas/backup_v1beta2.json b/crdSchemas/postgresql.cnpg.io/backup_v1beta2.json
similarity index 100%
rename from crdSchemas/backup_v1beta2.json
rename to crdSchemas/postgresql.cnpg.io/backup_v1beta2.json
diff --git a/crdSchemas/cluster_v1.json b/crdSchemas/postgresql.cnpg.io/cluster_v1.json
similarity index 100%
rename from crdSchemas/cluster_v1.json
rename to crdSchemas/postgresql.cnpg.io/cluster_v1.json
diff --git a/crdSchemas/clusterimagecatalog_v1.json b/crdSchemas/postgresql.cnpg.io/clusterimagecatalog_v1.json
similarity index 100%
rename from crdSchemas/clusterimagecatalog_v1.json
rename to crdSchemas/postgresql.cnpg.io/clusterimagecatalog_v1.json
diff --git a/crdSchemas/database_v1.json b/crdSchemas/postgresql.cnpg.io/database_v1.json
similarity index 100%
rename from crdSchemas/database_v1.json
rename to crdSchemas/postgresql.cnpg.io/database_v1.json
diff --git a/crdSchemas/failoverquorum_v1.json b/crdSchemas/postgresql.cnpg.io/failoverquorum_v1.json
similarity index 100%
rename from crdSchemas/failoverquorum_v1.json
rename to crdSchemas/postgresql.cnpg.io/failoverquorum_v1.json
diff --git a/crdSchemas/imagecatalog_v1.json b/crdSchemas/postgresql.cnpg.io/imagecatalog_v1.json
similarity index 100%
rename from crdSchemas/imagecatalog_v1.json
rename to crdSchemas/postgresql.cnpg.io/imagecatalog_v1.json
diff --git a/crdSchemas/pooler_v1.json b/crdSchemas/postgresql.cnpg.io/pooler_v1.json
similarity index 100%
rename from crdSchemas/pooler_v1.json
rename to crdSchemas/postgresql.cnpg.io/pooler_v1.json
diff --git a/crdSchemas/publication_v1.json b/crdSchemas/postgresql.cnpg.io/publication_v1.json
similarity index 100%
rename from crdSchemas/publication_v1.json
rename to crdSchemas/postgresql.cnpg.io/publication_v1.json
diff --git a/crdSchemas/scheduledbackup_v1.json b/crdSchemas/postgresql.cnpg.io/scheduledbackup_v1.json
similarity index 100%
rename from crdSchemas/scheduledbackup_v1.json
rename to crdSchemas/postgresql.cnpg.io/scheduledbackup_v1.json
diff --git a/crdSchemas/subscription_v1.json b/crdSchemas/postgresql.cnpg.io/subscription_v1.json
similarity index 100%
rename from crdSchemas/subscription_v1.json
rename to crdSchemas/postgresql.cnpg.io/subscription_v1.json
diff --git a/crdSchemas/bucket_v1.json b/crdSchemas/source.toolkit.fluxcd.io/bucket_v1.json
similarity index 100%
rename from crdSchemas/bucket_v1.json
rename to crdSchemas/source.toolkit.fluxcd.io/bucket_v1.json
diff --git a/crdSchemas/externalartifact_v1.json b/crdSchemas/source.toolkit.fluxcd.io/externalartifact_v1.json
similarity index 100%
rename from crdSchemas/externalartifact_v1.json
rename to crdSchemas/source.toolkit.fluxcd.io/externalartifact_v1.json
diff --git a/crdSchemas/gitrepository_v1.json b/crdSchemas/source.toolkit.fluxcd.io/gitrepository_v1.json
similarity index 100%
rename from crdSchemas/gitrepository_v1.json
rename to crdSchemas/source.toolkit.fluxcd.io/gitrepository_v1.json
diff --git a/crdSchemas/helmchart_v1.json b/crdSchemas/source.toolkit.fluxcd.io/helmchart_v1.json
similarity index 100%
rename from crdSchemas/helmchart_v1.json
rename to crdSchemas/source.toolkit.fluxcd.io/helmchart_v1.json
diff --git a/crdSchemas/helmrepository_v1.json b/crdSchemas/source.toolkit.fluxcd.io/helmrepository_v1.json
similarity index 100%
rename from crdSchemas/helmrepository_v1.json
rename to crdSchemas/source.toolkit.fluxcd.io/helmrepository_v1.json
diff --git a/crdSchemas/ocirepository_v1.json b/crdSchemas/source.toolkit.fluxcd.io/ocirepository_v1.json
similarity index 100%
rename from crdSchemas/ocirepository_v1.json
rename to crdSchemas/source.toolkit.fluxcd.io/ocirepository_v1.json
diff --git a/crdSchemas/embeddingserver_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/embeddingserver_v1alpha1.json
similarity index 100%
rename from crdSchemas/embeddingserver_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/embeddingserver_v1alpha1.json
diff --git a/crdSchemas/embeddingserver_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/embeddingserver_v1beta1.json
similarity index 100%
rename from crdSchemas/embeddingserver_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/embeddingserver_v1beta1.json
diff --git a/crdSchemas/mcpexternalauthconfig_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpexternalauthconfig_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpexternalauthconfig_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpexternalauthconfig_v1alpha1.json
diff --git a/crdSchemas/mcpexternalauthconfig_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpexternalauthconfig_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpexternalauthconfig_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpexternalauthconfig_v1beta1.json
diff --git a/crdSchemas/mcpgroup_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpgroup_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpgroup_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpgroup_v1alpha1.json
diff --git a/crdSchemas/mcpgroup_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpgroup_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpgroup_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpgroup_v1beta1.json
diff --git a/crdSchemas/mcpoidcconfig_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpoidcconfig_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpoidcconfig_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpoidcconfig_v1alpha1.json
diff --git a/crdSchemas/mcpoidcconfig_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpoidcconfig_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpoidcconfig_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpoidcconfig_v1beta1.json
diff --git a/crdSchemas/mcpregistry_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpregistry_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpregistry_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpregistry_v1alpha1.json
diff --git a/crdSchemas/mcpregistry_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpregistry_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpregistry_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpregistry_v1beta1.json
diff --git a/crdSchemas/mcpremoteproxy_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpremoteproxy_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpremoteproxy_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpremoteproxy_v1alpha1.json
diff --git a/crdSchemas/mcpremoteproxy_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpremoteproxy_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpremoteproxy_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpremoteproxy_v1beta1.json
diff --git a/crdSchemas/mcpserver_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpserver_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpserver_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpserver_v1alpha1.json
diff --git a/crdSchemas/mcpserver_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpserver_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpserver_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpserver_v1beta1.json
diff --git a/crdSchemas/mcpserverentry_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpserverentry_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpserverentry_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpserverentry_v1alpha1.json
diff --git a/crdSchemas/mcpserverentry_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcpserverentry_v1beta1.json
similarity index 100%
rename from crdSchemas/mcpserverentry_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpserverentry_v1beta1.json
diff --git a/crdSchemas/mcptelemetryconfig_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcptelemetryconfig_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcptelemetryconfig_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcptelemetryconfig_v1alpha1.json
diff --git a/crdSchemas/mcptelemetryconfig_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcptelemetryconfig_v1beta1.json
similarity index 100%
rename from crdSchemas/mcptelemetryconfig_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcptelemetryconfig_v1beta1.json
diff --git a/crdSchemas/mcptoolconfig_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcptoolconfig_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcptoolconfig_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcptoolconfig_v1alpha1.json
diff --git a/crdSchemas/mcptoolconfig_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/mcptoolconfig_v1beta1.json
similarity index 100%
rename from crdSchemas/mcptoolconfig_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/mcptoolconfig_v1beta1.json
diff --git a/crdSchemas/mcpwebhookconfig_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/mcpwebhookconfig_v1alpha1.json
similarity index 100%
rename from crdSchemas/mcpwebhookconfig_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/mcpwebhookconfig_v1alpha1.json
diff --git a/crdSchemas/virtualmcpcompositetooldefinition_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/virtualmcpcompositetooldefinition_v1alpha1.json
similarity index 100%
rename from crdSchemas/virtualmcpcompositetooldefinition_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/virtualmcpcompositetooldefinition_v1alpha1.json
diff --git a/crdSchemas/virtualmcpcompositetooldefinition_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/virtualmcpcompositetooldefinition_v1beta1.json
similarity index 100%
rename from crdSchemas/virtualmcpcompositetooldefinition_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/virtualmcpcompositetooldefinition_v1beta1.json
diff --git a/crdSchemas/virtualmcpserver_v1alpha1.json b/crdSchemas/toolhive.stacklok.dev/virtualmcpserver_v1alpha1.json
similarity index 100%
rename from crdSchemas/virtualmcpserver_v1alpha1.json
rename to crdSchemas/toolhive.stacklok.dev/virtualmcpserver_v1alpha1.json
diff --git a/crdSchemas/virtualmcpserver_v1beta1.json b/crdSchemas/toolhive.stacklok.dev/virtualmcpserver_v1beta1.json
similarity index 100%
rename from crdSchemas/virtualmcpserver_v1beta1.json
rename to crdSchemas/toolhive.stacklok.dev/virtualmcpserver_v1beta1.json
diff --git a/crdSchemas/ingressroute_v1alpha1.json b/crdSchemas/traefik.io/ingressroute_v1alpha1.json
similarity index 100%
rename from crdSchemas/ingressroute_v1alpha1.json
rename to crdSchemas/traefik.io/ingressroute_v1alpha1.json
diff --git a/crdSchemas/ingressroutetcp_v1alpha1.json b/crdSchemas/traefik.io/ingressroutetcp_v1alpha1.json
similarity index 100%
rename from crdSchemas/ingressroutetcp_v1alpha1.json
rename to crdSchemas/traefik.io/ingressroutetcp_v1alpha1.json
diff --git a/crdSchemas/ingressrouteudp_v1alpha1.json b/crdSchemas/traefik.io/ingressrouteudp_v1alpha1.json
similarity index 100%
rename from crdSchemas/ingressrouteudp_v1alpha1.json
rename to crdSchemas/traefik.io/ingressrouteudp_v1alpha1.json
diff --git a/crdSchemas/middleware_v1alpha1.json b/crdSchemas/traefik.io/middleware_v1alpha1.json
similarity index 100%
rename from crdSchemas/middleware_v1alpha1.json
rename to crdSchemas/traefik.io/middleware_v1alpha1.json
diff --git a/crdSchemas/middlewaretcp_v1alpha1.json b/crdSchemas/traefik.io/middlewaretcp_v1alpha1.json
similarity index 100%
rename from crdSchemas/middlewaretcp_v1alpha1.json
rename to crdSchemas/traefik.io/middlewaretcp_v1alpha1.json
diff --git a/crdSchemas/serverstransport_v1alpha1.json b/crdSchemas/traefik.io/serverstransport_v1alpha1.json
similarity index 100%
rename from crdSchemas/serverstransport_v1alpha1.json
rename to crdSchemas/traefik.io/serverstransport_v1alpha1.json
diff --git a/crdSchemas/serverstransporttcp_v1alpha1.json b/crdSchemas/traefik.io/serverstransporttcp_v1alpha1.json
similarity index 100%
rename from crdSchemas/serverstransporttcp_v1alpha1.json
rename to crdSchemas/traefik.io/serverstransporttcp_v1alpha1.json
diff --git a/crdSchemas/tlsoption_v1alpha1.json b/crdSchemas/traefik.io/tlsoption_v1alpha1.json
similarity index 100%
rename from crdSchemas/tlsoption_v1alpha1.json
rename to crdSchemas/traefik.io/tlsoption_v1alpha1.json
diff --git a/crdSchemas/tlsstore_v1alpha1.json b/crdSchemas/traefik.io/tlsstore_v1alpha1.json
similarity index 100%
rename from crdSchemas/tlsstore_v1alpha1.json
rename to crdSchemas/traefik.io/tlsstore_v1alpha1.json
diff --git a/crdSchemas/traefikservice_v1alpha1.json b/crdSchemas/traefik.io/traefikservice_v1alpha1.json
similarity index 100%
rename from crdSchemas/traefikservice_v1alpha1.json
rename to crdSchemas/traefik.io/traefikservice_v1alpha1.json