update crds
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"description": "CiliumCIDRGroup is a list of external CIDRs (i.e: CIDRs selecting peers\noutside the clusters) that can be referenced as a single entity from\nCiliumNetworkPolicies.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"properties": {
|
||||
"externalCIDRs": {
|
||||
"description": "ExternalCIDRs is a list of CIDRs selecting peers outside the clusters.",
|
||||
"items": {
|
||||
"description": "CIDR specifies a block of IP addresses.\nExample: 192.0.2.1/32",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 0,
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"externalCIDRs"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"description": "CiliumCIDRGroup is a list of external CIDRs (i.e: CIDRs selecting peers\noutside the clusters) that can be referenced as a single entity from\nCiliumNetworkPolicies.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"properties": {
|
||||
"externalCIDRs": {
|
||||
"description": "ExternalCIDRs is a list of CIDRs selecting peers outside the clusters.",
|
||||
"items": {
|
||||
"description": "CIDR specifies a block of IP addresses.\nExample: 192.0.2.1/32",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 0,
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"externalCIDRs"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,550 @@
|
||||
{
|
||||
"description": "CiliumEndpoint is the status of a Cilium policy rule.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"status": {
|
||||
"description": "EndpointStatus is the status of a Cilium endpoint.",
|
||||
"properties": {
|
||||
"controllers": {
|
||||
"description": "Controllers is the list of failing controllers for this endpoint.",
|
||||
"items": {
|
||||
"description": "ControllerStatus is the status of a failing controller.",
|
||||
"properties": {
|
||||
"configuration": {
|
||||
"description": "Configuration is the controller configuration",
|
||||
"properties": {
|
||||
"error-retry": {
|
||||
"description": "Retry on error",
|
||||
"type": "boolean"
|
||||
},
|
||||
"error-retry-base": {
|
||||
"description": "Base error retry back-off time\nFormat: duration",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"interval": {
|
||||
"description": "Regular synchronization interval\nFormat: duration",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the name of the controller",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is the status of the controller",
|
||||
"properties": {
|
||||
"consecutive-failure-count": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"failure-count": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"last-failure-msg": {
|
||||
"type": "string"
|
||||
},
|
||||
"last-failure-timestamp": {
|
||||
"type": "string"
|
||||
},
|
||||
"last-success-timestamp": {
|
||||
"type": "string"
|
||||
},
|
||||
"success-count": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"uuid": {
|
||||
"description": "UUID is the UUID of the controller",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"encryption": {
|
||||
"description": "Encryption is the encryption configuration of the node",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "Key is the index to the key to use for encryption or 0 if encryption is\ndisabled.",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"external-identifiers": {
|
||||
"description": "ExternalIdentifiers is a set of identifiers to identify the endpoint\napart from the pod name. This includes container runtime IDs.",
|
||||
"properties": {
|
||||
"cni-attachment-id": {
|
||||
"description": "ID assigned to this attachment by container runtime",
|
||||
"type": "string"
|
||||
},
|
||||
"container-id": {
|
||||
"description": "ID assigned by container runtime (deprecated, may not be unique)",
|
||||
"type": "string"
|
||||
},
|
||||
"container-name": {
|
||||
"description": "Name assigned to container (deprecated, may not be unique)",
|
||||
"type": "string"
|
||||
},
|
||||
"docker-endpoint-id": {
|
||||
"description": "Docker endpoint ID",
|
||||
"type": "string"
|
||||
},
|
||||
"docker-network-id": {
|
||||
"description": "Docker network ID",
|
||||
"type": "string"
|
||||
},
|
||||
"k8s-namespace": {
|
||||
"description": "K8s namespace for this endpoint (deprecated, may not be unique)",
|
||||
"type": "string"
|
||||
},
|
||||
"k8s-pod-name": {
|
||||
"description": "K8s pod name for this endpoint (deprecated, may not be unique)",
|
||||
"type": "string"
|
||||
},
|
||||
"pod-name": {
|
||||
"description": "K8s pod for this endpoint (deprecated, may not be unique)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"health": {
|
||||
"description": "Health is the overall endpoint & subcomponent health.",
|
||||
"properties": {
|
||||
"bpf": {
|
||||
"description": "bpf",
|
||||
"type": "string"
|
||||
},
|
||||
"connected": {
|
||||
"description": "Is this endpoint reachable",
|
||||
"type": "boolean"
|
||||
},
|
||||
"overallHealth": {
|
||||
"description": "overall health",
|
||||
"type": "string"
|
||||
},
|
||||
"policy": {
|
||||
"description": "policy",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"id": {
|
||||
"description": "ID is the cilium-agent-local ID of the endpoint.",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"description": "Identity is the security identity associated with the endpoint",
|
||||
"properties": {
|
||||
"id": {
|
||||
"description": "ID is the numeric identity of the endpoint",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"labels": {
|
||||
"description": "Labels is the list of labels associated with the identity",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"log": {
|
||||
"description": "Log is the list of the last few warning and error log entries",
|
||||
"items": {
|
||||
"description": "EndpointStatusChange Indication of a change of status\n\nswagger:model EndpointStatusChange",
|
||||
"properties": {
|
||||
"code": {
|
||||
"description": "Code indicate type of status change\nEnum: [\"ok\",\"failed\"]",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Status message",
|
||||
"type": "string"
|
||||
},
|
||||
"state": {
|
||||
"description": "state",
|
||||
"type": "string"
|
||||
},
|
||||
"timestamp": {
|
||||
"description": "Timestamp when status change occurred",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"named-ports": {
|
||||
"description": "NamedPorts List of named Layer 4 port and protocol pairs which will be used in Network\nPolicy specs.\n\nswagger:model NamedPorts",
|
||||
"items": {
|
||||
"description": "Port Layer 4 port / protocol pair\n\nswagger:model Port",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Optional layer 4 port name",
|
||||
"type": "string"
|
||||
},
|
||||
"port": {
|
||||
"description": "Layer 4 port number",
|
||||
"type": "integer"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Layer 4 protocol\nEnum: [\"TCP\",\"UDP\",\"SCTP\",\"ICMP\",\"ICMPV6\",\"ANY\"]",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"networking": {
|
||||
"description": "Networking is the networking properties of the endpoint.",
|
||||
"properties": {
|
||||
"addressing": {
|
||||
"description": "IP4/6 addresses assigned to this Endpoint",
|
||||
"items": {
|
||||
"description": "AddressPair is a pair of IPv4 and/or IPv6 address.",
|
||||
"properties": {
|
||||
"ipv4": {
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"node": {
|
||||
"description": "NodeIP is the IP of the node the endpoint is running on. The IP must\nbe reachable between nodes.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"addressing"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"policy": {
|
||||
"description": "EndpointPolicy represents the endpoint's policy by listing all allowed\ningress and egress identities in combination with L4 port and protocol.",
|
||||
"properties": {
|
||||
"egress": {
|
||||
"description": "EndpointPolicyDirection is the list of allowed identities per direction.",
|
||||
"properties": {
|
||||
"adding": {
|
||||
"description": "Deprecated",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"allowed": {
|
||||
"description": "AllowedIdentityList is a list of IdentityTuples that species peers that are\nallowed.",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"denied": {
|
||||
"description": "DenyIdentityList is a list of IdentityTuples that species peers that are\ndenied.",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"enforcing": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"removing": {
|
||||
"description": "Deprecated",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"state": {
|
||||
"description": "EndpointPolicyState defines the state of the Policy mode: \"enforcing\", \"non-enforcing\", \"disabled\"",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enforcing"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ingress": {
|
||||
"description": "EndpointPolicyDirection is the list of allowed identities per direction.",
|
||||
"properties": {
|
||||
"adding": {
|
||||
"description": "Deprecated",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"allowed": {
|
||||
"description": "AllowedIdentityList is a list of IdentityTuples that species peers that are\nallowed.",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"denied": {
|
||||
"description": "DenyIdentityList is a list of IdentityTuples that species peers that are\ndenied.",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"enforcing": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"removing": {
|
||||
"description": "Deprecated",
|
||||
"items": {
|
||||
"description": "IdentityTuple specifies a peer by identity, destination port and protocol.",
|
||||
"properties": {
|
||||
"dest-port": {
|
||||
"type": "integer"
|
||||
},
|
||||
"identity": {
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"identity-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "object"
|
||||
},
|
||||
"protocol": {
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"state": {
|
||||
"description": "EndpointPolicyState defines the state of the Policy mode: \"enforcing\", \"non-enforcing\", \"disabled\"",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enforcing"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"service-account": {
|
||||
"description": "ServiceAccount is the service account associated with the endpoint",
|
||||
"type": "string"
|
||||
},
|
||||
"state": {
|
||||
"description": "State is the state of the endpoint.",
|
||||
"enum": [
|
||||
"creating",
|
||||
"waiting-for-identity",
|
||||
"not-ready",
|
||||
"waiting-to-regenerate",
|
||||
"regenerating",
|
||||
"restoring",
|
||||
"ready",
|
||||
"disconnecting",
|
||||
"disconnected",
|
||||
"invalid"
|
||||
],
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
{
|
||||
"description": "CiliumIdentity is a CRD that represents an identity managed by Cilium.\nIt is intended as a backing store for identity allocation, acting as the\nglobal coordination backend, and can be used in place of a KVStore (such as\netcd).\nThe name of the CRD is the numeric identity and the labels on the CRD object\nare the kubernetes sourced labels seen by cilium. This is currently the\nonly label source possible when running under kubernetes. Non-kubernetes\nlabels are filtered but all labels, from all sources, are places in the\nSecurityLabels field. These also include the source and are used to define\nthe identity.\nThe labels under metav1.ObjectMeta can be used when searching for\nCiliumIdentity instances that include particular labels. This can be done\nwith invocations such as:\n\n\tkubectl get ciliumid -l 'foo=bar'",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"security-labels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "SecurityLabels is the source-of-truth set of labels for this identity.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"security-labels"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,221 @@
|
||||
{
|
||||
"description": "CiliumL2AnnouncementPolicy is a Kubernetes third-party resource which\nis used to defined which nodes should announce what services on the\nL2 network.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "Spec is a human readable description of a L2 announcement policy",
|
||||
"properties": {
|
||||
"externalIPs": {
|
||||
"description": "If true, the external IPs of the services are announced",
|
||||
"type": "boolean"
|
||||
},
|
||||
"interfaces": {
|
||||
"description": "A list of regular expressions that express which network interface(s) should be used\nto announce the services over. If nil, all network interfaces are used.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"loadBalancerIPs": {
|
||||
"description": "If true, the loadbalancer IPs of the services are announced\n\nIf nil this policy applies to all services.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"nodeSelector": {
|
||||
"description": "NodeSelector selects a group of nodes which will announce the IPs for\nthe services selected by the service selector.\n\nIf nil this policy applies to all nodes.",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"serviceSelector": {
|
||||
"description": "ServiceSelector selects a set of services which will be announced over L2 networks.\nThe loadBalancerClass for a service must be nil or specify a supported class, e.g.\n\"io.cilium/l2-announcer\". Refer to the following document for additional details\nregarding load balancer classes:\n\n https://kubernetes.io/docs/concepts/services-networking/service/#load-balancer-class\n\nIf nil this policy applies to all services.",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is the status of the policy.",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Current service state",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-map-keys": [
|
||||
"type"
|
||||
],
|
||||
"x-kubernetes-list-type": "map"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,185 @@
|
||||
{
|
||||
"description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to allocate\nand advertise IPs for Services of type LoadBalancer.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "Spec is a human readable description for a BGP load balancer\nip pool.",
|
||||
"properties": {
|
||||
"allowFirstLastIPs": {
|
||||
"description": "AllowFirstLastIPs, if set to `Yes` or undefined means that the first and last IPs of each CIDR will be allocatable.\nIf `No`, these IPs will be reserved. This field is ignored for /{31,32} and /{127,128} CIDRs since\nreserving the first and last IPs would make the CIDRs unusable.",
|
||||
"enum": [
|
||||
"Yes",
|
||||
"No"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"blocks": {
|
||||
"description": "Blocks is a list of CIDRs comprising this IP Pool",
|
||||
"items": {
|
||||
"description": "CiliumLoadBalancerIPPoolIPBlock describes a single IP block.",
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"start": {
|
||||
"type": "string"
|
||||
},
|
||||
"stop": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"disabled": {
|
||||
"default": false,
|
||||
"description": "Disabled, if set to true means that no new IPs will be allocated from this pool.\nExisting allocations will not be removed from services.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"serviceSelector": {
|
||||
"description": "ServiceSelector selects a set of services which are eligible to receive IPs from this",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is the status of the IP Pool.\n\nIt might be possible for users to define overlapping IP Pools, we can't validate or enforce non-overlapping pools\nduring object creation. The Cilium operator will do this validation and update the status to reflect the ability\nto allocate IPs from this pool.",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Current service state",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-map-keys": [
|
||||
"type"
|
||||
],
|
||||
"x-kubernetes-list-type": "map"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,185 @@
|
||||
{
|
||||
"description": "CiliumLoadBalancerIPPool is a Kubernetes third-party resource which\nis used to defined pools of IPs which the operator can use to allocate\nand advertise IPs for Services of type LoadBalancer.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "Spec is a human readable description for a BGP load balancer\nip pool.",
|
||||
"properties": {
|
||||
"allowFirstLastIPs": {
|
||||
"description": "AllowFirstLastIPs, if set to `Yes` or undefined means that the first and last IPs of each CIDR will be allocatable.\nIf `No`, these IPs will be reserved. This field is ignored for /{31,32} and /{127,128} CIDRs since\nreserving the first and last IPs would make the CIDRs unusable.",
|
||||
"enum": [
|
||||
"Yes",
|
||||
"No"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"blocks": {
|
||||
"description": "Blocks is a list of CIDRs comprising this IP Pool",
|
||||
"items": {
|
||||
"description": "CiliumLoadBalancerIPPoolIPBlock describes a single IP block.",
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"start": {
|
||||
"type": "string"
|
||||
},
|
||||
"stop": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"disabled": {
|
||||
"default": false,
|
||||
"description": "Disabled, if set to true means that no new IPs will be allocated from this pool.\nExisting allocations will not be removed from services.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"serviceSelector": {
|
||||
"description": "ServiceSelector selects a set of services which are eligible to receive IPs from this",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is the status of the IP Pool.\n\nIt might be possible for users to define overlapping IP Pools, we can't validate or enforce non-overlapping pools\nduring object creation. The Cilium operator will do this validation and update the status to reflect the ability\nto allocate IPs from this pool.",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Current service state",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-map-keys": [
|
||||
"type"
|
||||
],
|
||||
"x-kubernetes-list-type": "map"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,837 @@
|
||||
{
|
||||
"description": "CiliumNode represents a node managed by Cilium. It contains a specification\nto control various node specific configuration aspects and a status section\nto represent the status of the node.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "Spec defines the desired specification/configuration of the node.",
|
||||
"properties": {
|
||||
"addresses": {
|
||||
"description": "Addresses is the list of all node addresses.",
|
||||
"items": {
|
||||
"description": "NodeAddress is a node address.",
|
||||
"properties": {
|
||||
"ip": {
|
||||
"description": "IP is an IP of a node",
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "Type is the type of the node address",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"alibaba-cloud": {
|
||||
"description": "AlibabaCloud is the AlibabaCloud IPAM specific configuration.",
|
||||
"properties": {
|
||||
"availability-zone": {
|
||||
"description": "AvailabilityZone is the availability zone to use when allocating\nENIs.",
|
||||
"type": "string"
|
||||
},
|
||||
"cidr-block": {
|
||||
"description": "CIDRBlock is vpc ipv4 CIDR",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"instance-type": {
|
||||
"description": "InstanceType is the ECS instance type, e.g. \"ecs.g6.2xlarge\"",
|
||||
"type": "string"
|
||||
},
|
||||
"security-group-tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "SecurityGroupTags is the list of tags to use when evaluating which\nsecurity groups to use for the ENI.",
|
||||
"type": "object"
|
||||
},
|
||||
"security-groups": {
|
||||
"description": "SecurityGroups is the list of security groups to attach to any ENI\nthat is created and attached to the instance.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"vpc-id": {
|
||||
"description": "VPCID is the VPC ID to use when allocating ENIs.",
|
||||
"type": "string"
|
||||
},
|
||||
"vswitch-tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "VSwitchTags is the list of tags to use when evaluating which\nvSwitch to use for the ENI.",
|
||||
"type": "object"
|
||||
},
|
||||
"vswitches": {
|
||||
"description": "VSwitches is the ID of vSwitch available for ENI",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"azure": {
|
||||
"description": "Azure is the Azure IPAM specific configuration.",
|
||||
"properties": {
|
||||
"interface-name": {
|
||||
"description": "InterfaceName is the name of the interface the cilium-operator\nwill use to allocate all the IPs on",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"bootid": {
|
||||
"description": "BootID is a unique node identifier generated on boot",
|
||||
"type": "string"
|
||||
},
|
||||
"encryption": {
|
||||
"description": "Encryption is the encryption configuration of the node.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "Key is the index to the key to use for encryption or 0 if encryption is\ndisabled.",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"eni": {
|
||||
"description": "ENI is the AWS ENI specific configuration.",
|
||||
"properties": {
|
||||
"availability-zone": {
|
||||
"description": "AvailabilityZone is the availability zone to use when allocating\nENIs.",
|
||||
"type": "string"
|
||||
},
|
||||
"delete-on-termination": {
|
||||
"description": "DeleteOnTermination defines that the ENI should be deleted when the\nassociated instance is terminated. If the parameter is not set the\ndefault behavior is to delete the ENI on instance termination.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"disable-prefix-delegation": {
|
||||
"description": "DisablePrefixDelegation determines whether ENI prefix delegation should be\ndisabled on this node.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"exclude-interface-tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "ExcludeInterfaceTags is the list of tags to use when excluding ENIs for\nCilium IP allocation. Any interface matching this set of tags will not\nbe managed by Cilium.",
|
||||
"type": "object"
|
||||
},
|
||||
"first-interface-index": {
|
||||
"description": "FirstInterfaceIndex is the index of the first ENI to use for IP\nallocation, e.g. if the node has eth0, eth1, eth2 and\nFirstInterfaceIndex is set to 1, then only eth1 and eth2 will be\nused for IP allocation, eth0 will be ignored for PodIP allocation.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"instance-type": {
|
||||
"description": "InstanceType is the AWS EC2 instance type, e.g. \"m5.large\"",
|
||||
"type": "string"
|
||||
},
|
||||
"node-subnet-id": {
|
||||
"description": "NodeSubnetID is the subnet of the primary ENI the instance was brought up\nwith. It is used as a sensible default subnet to create ENIs in.",
|
||||
"type": "string"
|
||||
},
|
||||
"security-group-tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "SecurityGroupTags is the list of tags to use when evaliating what\nAWS security groups to use for the ENI.",
|
||||
"type": "object"
|
||||
},
|
||||
"security-groups": {
|
||||
"description": "SecurityGroups is the list of security groups to attach to any ENI\nthat is created and attached to the instance.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"subnet-ids": {
|
||||
"description": "SubnetIDs is the list of subnet ids to use when evaluating what AWS\nsubnets to use for ENI and IP allocation.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"subnet-tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "SubnetTags is the list of tags to use when evaluating what AWS\nsubnets to use for ENI and IP allocation.",
|
||||
"type": "object"
|
||||
},
|
||||
"use-primary-address": {
|
||||
"description": "UsePrimaryAddress determines whether an ENI's primary address\nshould be available for allocations on the node",
|
||||
"type": "boolean"
|
||||
},
|
||||
"vpc-id": {
|
||||
"description": "VpcID is the VPC ID to use when allocating ENIs.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"health": {
|
||||
"description": "HealthAddressing is the addressing information for health connectivity\nchecking.",
|
||||
"properties": {
|
||||
"ipv4": {
|
||||
"description": "IPv4 is the IPv4 address of the IPv4 health endpoint.",
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6": {
|
||||
"description": "IPv6 is the IPv6 address of the IPv4 health endpoint.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ingress": {
|
||||
"description": "IngressAddressing is the addressing information for Ingress listener.",
|
||||
"properties": {
|
||||
"ipv4": {
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"instance-id": {
|
||||
"description": "InstanceID is the identifier of the node. This is different from the\nnode name which is typically the FQDN of the node. The InstanceID\ntypically refers to the identifier used by the cloud provider or\nsome other means of identification.",
|
||||
"type": "string"
|
||||
},
|
||||
"ipam": {
|
||||
"description": "IPAM is the address management specification. This section can be\npopulated by a user or it can be automatically populated by an IPAM\noperator.",
|
||||
"properties": {
|
||||
"ipv6-pool": {
|
||||
"additionalProperties": {
|
||||
"description": "AllocationIP is an IP which is available for allocation, or already\nhas been allocated",
|
||||
"properties": {
|
||||
"owner": {
|
||||
"description": "Owner is the owner of the IP. This field is set if the IP has been\nallocated. It will be set to the pod name or another identifier\nrepresenting the usage of the IP\n\nThe owner field is left blank for an entry in Spec.IPAM.Pool and\nfilled out as the IP is used and also added to Status.IPAM.Used.",
|
||||
"type": "string"
|
||||
},
|
||||
"resource": {
|
||||
"description": "Resource is set for both available and allocated IPs, it represents\nwhat resource the IP is associated with, e.g. in combination with\nAWS ENI, this will refer to the ID of the ENI",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "IPv6Pool is the list of IPv6 addresses available to the node for allocation.\nWhen an IPv6 address is used, it will remain on this list but will be added to\nStatus.IPAM.IPv6Used",
|
||||
"type": "object"
|
||||
},
|
||||
"max-above-watermark": {
|
||||
"description": "MaxAboveWatermark is the maximum number of addresses to allocate\nbeyond the addresses needed to reach the PreAllocate watermark.\nGoing above the watermark can help reduce the number of API calls to\nallocate IPs, e.g. when a new ENI is allocated, as many secondary\nIPs as possible are allocated. Limiting the amount can help reduce\nwaste of IPs.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"max-allocate": {
|
||||
"description": "MaxAllocate is the maximum number of IPs that can be allocated to the\nnode. When the current amount of allocated IPs will approach this value,\nthe considered value for PreAllocate will decrease down to 0 in order to\nnot attempt to allocate more addresses than defined.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"min-allocate": {
|
||||
"description": "MinAllocate is the minimum number of IPs that must be allocated when\nthe node is first bootstrapped. It defines the minimum base socket\nof addresses that must be available. After reaching this watermark,\nthe PreAllocate and MaxAboveWatermark logic takes over to continue\nallocating IPs.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"podCIDRs": {
|
||||
"description": "PodCIDRs is the list of CIDRs available to the node for allocation.\nWhen an IP is used, the IP will be added to Status.IPAM.Used",
|
||||
"items": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"pool": {
|
||||
"additionalProperties": {
|
||||
"description": "AllocationIP is an IP which is available for allocation, or already\nhas been allocated",
|
||||
"properties": {
|
||||
"owner": {
|
||||
"description": "Owner is the owner of the IP. This field is set if the IP has been\nallocated. It will be set to the pod name or another identifier\nrepresenting the usage of the IP\n\nThe owner field is left blank for an entry in Spec.IPAM.Pool and\nfilled out as the IP is used and also added to Status.IPAM.Used.",
|
||||
"type": "string"
|
||||
},
|
||||
"resource": {
|
||||
"description": "Resource is set for both available and allocated IPs, it represents\nwhat resource the IP is associated with, e.g. in combination with\nAWS ENI, this will refer to the ID of the ENI",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "Pool is the list of IPv4 addresses available to the node for allocation.\nWhen an IPv4 address is used, it will remain on this list but will be added to\nStatus.IPAM.Used",
|
||||
"type": "object"
|
||||
},
|
||||
"pools": {
|
||||
"description": "Pools contains the list of assigned IPAM pools for this node.",
|
||||
"properties": {
|
||||
"allocated": {
|
||||
"description": "Allocated contains the list of pooled CIDR assigned to this node. The\noperator will add new pod CIDRs to this field, whereas the agent will\nremove CIDRs it has released.",
|
||||
"items": {
|
||||
"description": "IPAMPoolAllocation describes an allocation of an IPAM pool from the operator to the\nnode. It contains the assigned PodCIDRs allocated from this pool",
|
||||
"properties": {
|
||||
"allowFirstIP": {
|
||||
"description": "AllowFirstIP allows the first IP of each allocated CIDR to be used.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"allowLastIP": {
|
||||
"description": "AllowLastIP allows the last IP of each allocated CIDR to be used.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"cidrs": {
|
||||
"description": "CIDRs contains a list of pod CIDRs currently allocated from this pool",
|
||||
"items": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"pool": {
|
||||
"description": "Pool is the name of the IPAM pool backing this allocation",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"pool"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"requested": {
|
||||
"description": "Requested contains a list of IPAM pool requests, i.e. indicates how many\naddresses this node requests out of each pool listed here. This field\nis owned and written to by cilium-agent and read by the operator.",
|
||||
"items": {
|
||||
"properties": {
|
||||
"needed": {
|
||||
"description": "Needed indicates how many IPs out of the above Pool this node requests\nfrom the operator. The operator runs a reconciliation loop to ensure each\nnode always has enough PodCIDRs allocated in each pool to fulfill the\nrequested number of IPs here.",
|
||||
"properties": {
|
||||
"ipv4-addrs": {
|
||||
"description": "IPv4Addrs contains the number of requested IPv4 addresses out of a given\npool",
|
||||
"type": "integer"
|
||||
},
|
||||
"ipv6-addrs": {
|
||||
"description": "IPv6Addrs contains the number of requested IPv6 addresses out of a given\npool",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"pool": {
|
||||
"description": "Pool is the name of the IPAM pool backing this request",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"pool"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"pre-allocate": {
|
||||
"description": "PreAllocate defines the number of IP addresses that must be\navailable for allocation in the IPAMSpec. It defines the buffer of\naddresses available immediately without requiring cilium-operator to\nget involved.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"static-ip-tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "StaticIPTags are used to determine the pool of IPs from which to\nattribute a static IP to the node. For example in AWS this is used to\nfilter Elastic IP Addresses.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "Status defines the realized specification/configuration and status\nof the node.",
|
||||
"properties": {
|
||||
"alibaba-cloud": {
|
||||
"description": "AlibabaCloud is the AlibabaCloud specific status of the node.",
|
||||
"properties": {
|
||||
"enis": {
|
||||
"additionalProperties": {
|
||||
"description": "ENI represents an AlibabaCloud Elastic Network Interface",
|
||||
"properties": {
|
||||
"instance-id": {
|
||||
"description": "InstanceID is the InstanceID using this ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"mac-address": {
|
||||
"description": "MACAddress is the mac address of the ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"network-interface-id": {
|
||||
"description": "NetworkInterfaceID is the ENI id",
|
||||
"type": "string"
|
||||
},
|
||||
"primary-ip-address": {
|
||||
"description": "PrimaryIPAddress is the primary IP on ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"private-ipsets": {
|
||||
"description": "PrivateIPSets is the list of all IPs on the ENI, including PrimaryIPAddress",
|
||||
"items": {
|
||||
"description": "PrivateIPSet is a nested struct in ecs response",
|
||||
"properties": {
|
||||
"primary": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"private-ip-address": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"security-groupids": {
|
||||
"description": "SecurityGroupIDs is the security group ids used by this ENI",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Tags is the tags on this ENI",
|
||||
"type": "object"
|
||||
},
|
||||
"type": {
|
||||
"description": "Type is the ENI type Primary or Secondary",
|
||||
"type": "string"
|
||||
},
|
||||
"vpc": {
|
||||
"description": "VPC is the vpc to which the ENI belongs",
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"description": "CIDRBlock is the VPC IPv4 CIDR",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6-cidr": {
|
||||
"description": "IPv6CIDRBlock is the VPC IPv6 CIDR",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"secondary-cidrs": {
|
||||
"description": "SecondaryCIDRs is the list of Secondary CIDRs associated with the VPC",
|
||||
"items": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"vpc-id": {
|
||||
"description": "VPCID is the vpc to which the ENI belongs",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"vswitch": {
|
||||
"description": "VSwitch is the vSwitch the ENI is using",
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"description": "CIDRBlock is the vSwitch IPv4 CIDR",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6-cidr": {
|
||||
"description": "IPv6CIDRBlock is the vSwitch IPv6 CIDR",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"vswitch-id": {
|
||||
"description": "VSwitchID is the vSwitch to which the ENI belongs",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"zone-id": {
|
||||
"description": "ZoneID is the zone to which the ENI belongs",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "ENIs is the list of ENIs on the node",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"azure": {
|
||||
"description": "Azure is the Azure specific status of the node.",
|
||||
"properties": {
|
||||
"interfaces": {
|
||||
"description": "Interfaces is the list of interfaces on the node",
|
||||
"items": {
|
||||
"description": "AzureInterface represents an Azure Interface",
|
||||
"properties": {
|
||||
"addresses": {
|
||||
"description": "Addresses is the list of secondary IPs associated with the interface.\nThe primary IP is tracked separately in the IP field, but is also\nincluded here when the operator is configured to expose it for\nallocation.",
|
||||
"items": {
|
||||
"description": "AzureAddress is an IP address assigned to an AzureInterface",
|
||||
"properties": {
|
||||
"ip": {
|
||||
"description": "IP is the ip address of the address",
|
||||
"type": "string"
|
||||
},
|
||||
"state": {
|
||||
"description": "State is the provisioning state of the address",
|
||||
"type": "string"
|
||||
},
|
||||
"subnet": {
|
||||
"description": "Subnet is the subnet the address belongs to.\n\nDeprecated: use AzureInterface.Subnet.ID. Populated as a mirror for one\nrelease so external consumers of CiliumNode.Status.Azure can migrate.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"cidr": {
|
||||
"description": "CIDR is the range that the interface belongs to.\n\nDeprecated: use Subnet.CIDR. Retained for one release so agent/operator\nrolling upgrades work in either order.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"gateway": {
|
||||
"description": "Gateway is the interface's subnet's default route",
|
||||
"type": "string"
|
||||
},
|
||||
"id": {
|
||||
"description": "ID is the identifier",
|
||||
"type": "string"
|
||||
},
|
||||
"ip": {
|
||||
"description": "IP is the primary IP of the interface",
|
||||
"type": "string"
|
||||
},
|
||||
"mac": {
|
||||
"description": "MAC is the mac address",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the name of the interface",
|
||||
"type": "string"
|
||||
},
|
||||
"security-group": {
|
||||
"description": "SecurityGroup is the security group associated with the interface",
|
||||
"type": "string"
|
||||
},
|
||||
"state": {
|
||||
"description": "State is the provisioning state",
|
||||
"type": "string"
|
||||
},
|
||||
"subnet": {
|
||||
"description": "Subnet is the subnet the interface is attached to.",
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"description": "CIDR is the CIDR range associated with the subnet",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"id": {
|
||||
"description": "ID is the resource ID of the subnet",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"eni": {
|
||||
"description": "ENI is the AWS ENI specific status of the node.",
|
||||
"properties": {
|
||||
"enis": {
|
||||
"additionalProperties": {
|
||||
"description": "ENI represents an AWS Elastic Network Interface\n\nMore details:\nhttps://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html",
|
||||
"properties": {
|
||||
"addresses": {
|
||||
"description": "Addresses is the list of all secondary IPs associated with the ENI",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"availability-zone": {
|
||||
"description": "AvailabilityZone is the availability zone of the ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"description": {
|
||||
"description": "Description is the description field of the ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"id": {
|
||||
"description": "ID is the ENI ID",
|
||||
"type": "string"
|
||||
},
|
||||
"ip": {
|
||||
"description": "IP is the primary IP of the ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6-prefixes": {
|
||||
"description": "IPv6Prefixes is the list of all IPv6 /80 delegated prefixes associated with the ENI",
|
||||
"items": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"mac": {
|
||||
"description": "MAC is the mac address of the ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"number": {
|
||||
"description": "Number is the interface index, it used in combination with\nFirstInterfaceIndex",
|
||||
"type": "integer"
|
||||
},
|
||||
"prefixes": {
|
||||
"description": "Prefixes is the list of all IPv4 /28 delegated prefixes associated with the ENI",
|
||||
"items": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"public-ip": {
|
||||
"description": "PublicIP is the public IP associated with the ENI",
|
||||
"type": "string"
|
||||
},
|
||||
"security-groups": {
|
||||
"description": "SecurityGroups are the security groups associated with the ENI",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"subnet": {
|
||||
"description": "Subnet is the subnet the ENI is associated with",
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"description": "CIDR is the CIDR range associated with the subnet",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"id": {
|
||||
"description": "ID is the ID of the subnet",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"tags": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Tags is the set of tags of the ENI. Used to detect ENIs which should\nnot be managed by Cilium",
|
||||
"type": "object"
|
||||
},
|
||||
"vpc": {
|
||||
"description": "VPC is the VPC information to which the ENI is attached to",
|
||||
"properties": {
|
||||
"cidrs": {
|
||||
"description": "CIDRs is the list of CIDR ranges associated with the VPC",
|
||||
"items": {
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"id": {
|
||||
"description": "/ ID is the ID of a VPC",
|
||||
"type": "string"
|
||||
},
|
||||
"primary-cidr": {
|
||||
"description": "PrimaryCIDR is the primary CIDR of the VPC",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "ENIs is the list of ENIs on the node",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ipam": {
|
||||
"description": "IPAM is the IPAM status of the node.",
|
||||
"properties": {
|
||||
"assigned-static-ip": {
|
||||
"description": "AssignedStaticIP is the static IP assigned to the node (ex: public Elastic IP address in AWS)",
|
||||
"type": "string"
|
||||
},
|
||||
"ipv6-used": {
|
||||
"additionalProperties": {
|
||||
"description": "AllocationIP is an IP which is available for allocation, or already\nhas been allocated",
|
||||
"properties": {
|
||||
"owner": {
|
||||
"description": "Owner is the owner of the IP. This field is set if the IP has been\nallocated. It will be set to the pod name or another identifier\nrepresenting the usage of the IP\n\nThe owner field is left blank for an entry in Spec.IPAM.Pool and\nfilled out as the IP is used and also added to Status.IPAM.Used.",
|
||||
"type": "string"
|
||||
},
|
||||
"resource": {
|
||||
"description": "Resource is set for both available and allocated IPs, it represents\nwhat resource the IP is associated with, e.g. in combination with\nAWS ENI, this will refer to the ID of the ENI",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "IPv6Used lists all IPv6 addresses out of Spec.IPAM.IPv6Pool which have been\nallocated and are in use.",
|
||||
"type": "object"
|
||||
},
|
||||
"operator-status": {
|
||||
"description": "Operator is the Operator status of the node",
|
||||
"properties": {
|
||||
"error": {
|
||||
"description": "Error is the error message set by cilium-operator.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"pod-cidrs": {
|
||||
"additionalProperties": {
|
||||
"properties": {
|
||||
"status": {
|
||||
"description": "Status describes the status of a pod CIDR",
|
||||
"enum": [
|
||||
"released",
|
||||
"depleted",
|
||||
"in-use"
|
||||
],
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "PodCIDRs lists the status of each pod CIDR allocated to this node.",
|
||||
"type": "object"
|
||||
},
|
||||
"release-ips": {
|
||||
"additionalProperties": {
|
||||
"description": "IPReleaseStatus defines the valid states in IP release handshake",
|
||||
"enum": [
|
||||
"marked-for-release",
|
||||
"ready-for-release",
|
||||
"do-not-release",
|
||||
"released"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"description": "ReleaseIPs tracks the state for every IPv4 address considered for release.\nThe value can be one of the following strings:\n* marked-for-release : Set by operator as possible candidate for IP\n* ready-for-release : Acknowledged as safe to release by agent\n* do-not-release : IP already in use / not owned by the node. Set by agent\n* released : IP successfully released. Set by operator",
|
||||
"type": "object"
|
||||
},
|
||||
"release-ipv6s": {
|
||||
"additionalProperties": {
|
||||
"description": "IPReleaseStatus defines the valid states in IP release handshake",
|
||||
"enum": [
|
||||
"marked-for-release",
|
||||
"ready-for-release",
|
||||
"do-not-release",
|
||||
"released"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"description": "ReleaseIPv6s tracks the state for every IPv6 address considered for release.\nThe value can be one of the following strings:\n* marked-for-release : Set by operator as possible candidate for IP\n* ready-for-release : Acknowledged as safe to release by agent\n* do-not-release : IP already in use / not owned by the node. Set by agent\n* released : IP successfully released. Set by operator",
|
||||
"type": "object"
|
||||
},
|
||||
"used": {
|
||||
"additionalProperties": {
|
||||
"description": "AllocationIP is an IP which is available for allocation, or already\nhas been allocated",
|
||||
"properties": {
|
||||
"owner": {
|
||||
"description": "Owner is the owner of the IP. This field is set if the IP has been\nallocated. It will be set to the pod name or another identifier\nrepresenting the usage of the IP\n\nThe owner field is left blank for an entry in Spec.IPAM.Pool and\nfilled out as the IP is used and also added to Status.IPAM.Used.",
|
||||
"type": "string"
|
||||
},
|
||||
"resource": {
|
||||
"description": "Resource is set for both available and allocated IPs, it represents\nwhat resource the IP is associated with, e.g. in combination with\nAWS ENI, this will refer to the ID of the ENI",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "Used lists all IPv4 addresses out of Spec.IPAM.Pool which have been allocated\nand are in use.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,85 @@
|
||||
{
|
||||
"description": "CiliumNodeConfig is a list of configuration key-value pairs. It is applied to\nnodes indicated by a label selector.\n\nIf multiple overrides apply to the same node, they will be ordered by name\nwith later Overrides overwriting any conflicting keys.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "Spec is the desired Cilium configuration overrides for a given node",
|
||||
"properties": {
|
||||
"defaults": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Defaults is treated the same as the cilium-config ConfigMap - a set\nof key-value pairs parsed by the agent and operator processes.\nEach key must be a valid config-map data field (i.e. a-z, A-Z, -, _, and .)",
|
||||
"type": "object"
|
||||
},
|
||||
"nodeSelector": {
|
||||
"description": "NodeSelector is a label selector that determines to which nodes\nthis configuration applies.\nIf not supplied, then this config applies to no nodes. If\nempty, then it applies to all nodes.",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"defaults",
|
||||
"nodeSelector"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,85 @@
|
||||
{
|
||||
"description": "CiliumNodeConfig is a list of configuration key-value pairs. It is applied to\nnodes indicated by a label selector.\n\nIf multiple overrides apply to the same node, they will be ordered by name\nwith later Overrides overwriting any conflicting keys.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "Spec is the desired Cilium configuration overrides for a given node",
|
||||
"properties": {
|
||||
"defaults": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Defaults is treated the same as the cilium-config ConfigMap - a set\nof key-value pairs parsed by the agent and operator processes.\nEach key must be a valid config-map data field (i.e. a-z, A-Z, -, _, and .)",
|
||||
"type": "object"
|
||||
},
|
||||
"nodeSelector": {
|
||||
"description": "NodeSelector is a label selector that determines to which nodes\nthis configuration applies.\nIf not supplied, then this config applies to no nodes. If\nempty, then it applies to all nodes.",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"defaults",
|
||||
"nodeSelector"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,330 @@
|
||||
{
|
||||
"description": "CiliumPodIPPool defines an IP pool that can be used for pooled IPAM (i.e. the multi-pool IPAM\nmode).",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"properties": {
|
||||
"allowFirstIP": {
|
||||
"default": false,
|
||||
"description": "AllowFirstIP allows the first IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
|
||||
"type": "boolean",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "allowFirstIP is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
},
|
||||
"allowLastIP": {
|
||||
"default": false,
|
||||
"description": "AllowLastIP allows the last IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
|
||||
"type": "boolean",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "allowLastIP is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
},
|
||||
"ipv4": {
|
||||
"description": "IPv4 specifies the IPv4 CIDRs and mask sizes of the pool",
|
||||
"properties": {
|
||||
"cidrs": {
|
||||
"description": "CIDRs is a list of IPv4 CIDRs that are part of the pool.",
|
||||
"items": {
|
||||
"description": "PoolCIDR is an IP pool CIDR.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"maxItems": 32,
|
||||
"minItems": 1,
|
||||
"type": "array"
|
||||
},
|
||||
"maskSize": {
|
||||
"description": "MaskSize is the mask size of the pool.",
|
||||
"maximum": 32,
|
||||
"minimum": 1,
|
||||
"type": "integer",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "maskSize is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
},
|
||||
"pool": {
|
||||
"description": "Pool contains per-CIDR configuration for a subset of CIDRs listed in CIDRs.\nEach entry must reference a CIDR in CIDRs.",
|
||||
"items": {
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"description": "CIDR references one of the CIDRs listed in the parent pool spec.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"reservedRanges": {
|
||||
"description": "ReservedRanges is a list of IP ranges within CIDR that must not be allocated.",
|
||||
"items": {
|
||||
"properties": {
|
||||
"end": {
|
||||
"description": "The last IP in the reserved range.",
|
||||
"type": "string"
|
||||
},
|
||||
"start": {
|
||||
"description": "The first IP in the reserved range.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"end",
|
||||
"start"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"cidr"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"maxItems": 32,
|
||||
"type": "array",
|
||||
"x-kubernetes-list-map-keys": [
|
||||
"cidr"
|
||||
],
|
||||
"x-kubernetes-list-type": "map"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"cidrs",
|
||||
"maskSize"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "If pool is set, each pool entry must reference a CIDR from cidrs",
|
||||
"rule": "!has(self.pool) || self.pool.all(p, p.cidr in self.cidrs)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ipv6": {
|
||||
"description": "IPv6 specifies the IPv6 CIDRs and mask sizes of the pool",
|
||||
"properties": {
|
||||
"cidrs": {
|
||||
"description": "CIDRs is a list of IPv6 CIDRs that are part of the pool.",
|
||||
"items": {
|
||||
"description": "PoolCIDR is an IP pool CIDR.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"maxItems": 32,
|
||||
"minItems": 1,
|
||||
"type": "array"
|
||||
},
|
||||
"maskSize": {
|
||||
"description": "MaskSize is the mask size of the pool.",
|
||||
"maximum": 128,
|
||||
"minimum": 1,
|
||||
"type": "integer",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "maskSize is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
},
|
||||
"pool": {
|
||||
"description": "Pool contains per-CIDR configuration for a subset of CIDRs listed in CIDRs.\nEach entry must reference a CIDR in CIDRs.",
|
||||
"items": {
|
||||
"properties": {
|
||||
"cidr": {
|
||||
"description": "CIDR references one of the CIDRs listed in the parent pool spec.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"reservedRanges": {
|
||||
"description": "ReservedRanges is a list of IP ranges within CIDR that must not be allocated.",
|
||||
"items": {
|
||||
"properties": {
|
||||
"end": {
|
||||
"description": "The last IP in the reserved range.",
|
||||
"type": "string"
|
||||
},
|
||||
"start": {
|
||||
"description": "The first IP in the reserved range.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"end",
|
||||
"start"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"cidr"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"maxItems": 32,
|
||||
"type": "array",
|
||||
"x-kubernetes-list-map-keys": [
|
||||
"cidr"
|
||||
],
|
||||
"x-kubernetes-list-type": "map"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"cidrs",
|
||||
"maskSize"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "If pool is set, each pool entry must reference a CIDR from cidrs",
|
||||
"rule": "!has(self.pool) || self.pool.all(p, p.cidr in self.cidrs)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"namespaceSelector": {
|
||||
"description": "NamespaceSelector selects the set of Namespaces that are eligible to use\nthis pool. If both PodSelector and NamespaceSelector are specified, a Pod\nmust match both selectors to be eligible for IP allocation from this pool.\n\nIf NamespaceSelector is empty, the pool can be used by Pods in any namespace\n(subject to PodSelector constraints).",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"podSelector": {
|
||||
"description": "PodSelector selects the set of Pods that are eligible to receive IPs from\nthis pool when neither the Pod nor its Namespace specify an explicit\n`ipam.cilium.io/*` annotation.\n\nThe selector can match on regular Pod labels and on the following synthetic\nlabels that Cilium adds for convenience:\n\nio.kubernetes.pod.namespace \u2013 the Pod's namespace\nio.kubernetes.pod.name \u2013 the Pod's name\n\nA single Pod must not match more than one pool for the same IP family.\nIf multiple pools match, IP allocation fails for that Pod and a warning event\nis emitted in the namespace of the Pod.",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,226 @@
|
||||
{
|
||||
"description": "CiliumPodIPPool defines an IP pool that can be used for pooled IPAM (i.e. the multi-pool IPAM\nmode).",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"properties": {
|
||||
"allowFirstIP": {
|
||||
"default": false,
|
||||
"description": "AllowFirstIP allows the first IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
|
||||
"type": "boolean",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "allowFirstIP is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
},
|
||||
"allowLastIP": {
|
||||
"default": false,
|
||||
"description": "AllowLastIP allows the last IP of each allocated CIDR to be used. If\nunset or false, this IP is reserved. This field is ignored for /{31,32}\nand /{127,128} CIDRs since reserving the first and last IPs would make\nthe CIDRs unusable. This field is immutable.",
|
||||
"type": "boolean",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "allowLastIP is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
},
|
||||
"ipv4": {
|
||||
"description": "IPv4 specifies the IPv4 CIDRs and mask sizes of the pool",
|
||||
"properties": {
|
||||
"cidrs": {
|
||||
"description": "CIDRs is a list of IPv4 CIDRs that are part of the pool.",
|
||||
"items": {
|
||||
"description": "PoolCIDR is an IP pool CIDR.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 1,
|
||||
"type": "array"
|
||||
},
|
||||
"maskSize": {
|
||||
"description": "MaskSize is the mask size of the pool.",
|
||||
"maximum": 32,
|
||||
"minimum": 1,
|
||||
"type": "integer",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "maskSize is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"cidrs",
|
||||
"maskSize"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ipv6": {
|
||||
"description": "IPv6 specifies the IPv6 CIDRs and mask sizes of the pool",
|
||||
"properties": {
|
||||
"cidrs": {
|
||||
"description": "CIDRs is a list of IPv6 CIDRs that are part of the pool.",
|
||||
"items": {
|
||||
"description": "PoolCIDR is an IP pool CIDR.",
|
||||
"format": "cidr",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 1,
|
||||
"type": "array"
|
||||
},
|
||||
"maskSize": {
|
||||
"description": "MaskSize is the mask size of the pool.",
|
||||
"maximum": 128,
|
||||
"minimum": 1,
|
||||
"type": "integer",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "maskSize is immutable",
|
||||
"rule": "self == oldSelf"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"cidrs",
|
||||
"maskSize"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"namespaceSelector": {
|
||||
"description": "NamespaceSelector selects the set of Namespaces that are eligible to use\nthis pool. If both PodSelector and NamespaceSelector are specified, a Pod\nmust match both selectors to be eligible for IP allocation from this pool.\n\nIf NamespaceSelector is empty, the pool can be used by Pods in any namespace\n(subject to PodSelector constraints).",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"podSelector": {
|
||||
"description": "PodSelector selects the set of Pods that are eligible to receive IPs from\nthis pool when neither the Pod nor its Namespace specify an explicit\n`ipam.cilium.io/*` annotation.\n\nThe selector can match on regular Pod labels and on the following synthetic\nlabels that Cilium adds for convenience:\n\nio.kubernetes.pod.namespace \u2013 the Pod's namespace\nio.kubernetes.pod.name \u2013 the Pod's name\n\nA single Pod must not match more than one pool for the same IP family.\nIf multiple pools match, IP allocation fails for that Pod and a warning event\nis emitted in the namespace of the Pod.",
|
||||
"properties": {
|
||||
"matchExpressions": {
|
||||
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
|
||||
"items": {
|
||||
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"description": "key is the label key that the selector applies to.",
|
||||
"type": "string"
|
||||
},
|
||||
"operator": {
|
||||
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
|
||||
"enum": [
|
||||
"In",
|
||||
"NotIn",
|
||||
"Exists",
|
||||
"DoesNotExist"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"values": {
|
||||
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"key",
|
||||
"operator"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array",
|
||||
"x-kubernetes-list-type": "atomic"
|
||||
},
|
||||
"matchLabels": {
|
||||
"additionalProperties": {
|
||||
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
|
||||
"maxLength": 63,
|
||||
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-map-type": "atomic",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
Reference in New Issue
Block a user