update crds

This commit is contained in:
2026-08-18 19:18:31 +01:00
parent 717d09d1f3
commit bb5fc11402
268 changed files with 88606 additions and 1644 deletions
@@ -0,0 +1,586 @@
{
"description": "FluxInstance is the Schema for the fluxinstances API",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "FluxInstanceSpec defines the desired state of FluxInstance",
"properties": {
"cluster": {
"description": "Cluster holds the specification of the Kubernetes cluster.",
"properties": {
"domain": {
"default": "cluster.local",
"description": "Domain is the cluster domain used for generating the FQDN of services.\nDefaults to 'cluster.local'.",
"type": "string"
},
"multitenant": {
"default": false,
"description": "Multitenant enables the multitenancy lockdown. Defaults to false.",
"type": "boolean"
},
"multitenantWorkloadIdentity": {
"default": false,
"description": "MultitenantWorkloadIdentity enables the multitenancy lockdown for\nworkload identity. Defaults to false.",
"type": "boolean"
},
"networkPolicy": {
"default": true,
"description": "NetworkPolicy restricts network access to the current namespace.\nDefaults to true.",
"type": "boolean"
},
"objectLevelWorkloadIdentity": {
"description": "ObjectLevelWorkloadIdentity enables the feature gate\nrequired for object-level workload identity.\nThis feature is only available in Flux v2.6.0 and later.",
"type": "boolean"
},
"size": {
"description": "Size defines the vertical scaling profile of the Flux controllers.\nThe size is used to determine the concurrency and CPU/Memory limits for the Flux controllers.\nAccepted values are: 'small', 'medium' and 'large'.",
"enum": [
"small",
"medium",
"large"
],
"type": "string"
},
"tenantDefaultDecryptionServiceAccount": {
"description": "TenantDefaultDecryptionServiceAccount is the name of the service account\nto use as default for kustomize-controller SOPS decryption when the\nmultitenant lockdown for workload identity is enabled. Defaults to the\n'default' service account from the tenant namespace.",
"type": "string"
},
"tenantDefaultKubeConfigServiceAccount": {
"description": "TenantDefaultKubeConfigServiceAccount is the name of the service account\nto use as default for kustomize-controller and helm-controller remote\ncluster access via spec.kubeConfig.configMapRef when the multitenant\nlockdown for workload identity is enabled. Defaults to the 'default'\nservice account from the tenant namespace.",
"type": "string"
},
"tenantDefaultServiceAccount": {
"description": "TenantDefaultServiceAccount is the name of the service account\nto use as default when the multitenant lockdown is enabled, for\nkustomize-controller and helm-controller.\nThis field will also be used for multitenant workload identity\nlockdown for source-controller, notification-controller,\nimage-reflector-controller and image-automation-controller.\nDefaults to the 'default' service account from the tenant namespace.",
"type": "string"
},
"type": {
"default": "kubernetes",
"description": "Type specifies the distro of the Kubernetes cluster.\nDefaults to 'kubernetes'.",
"enum": [
"kubernetes",
"openshift",
"aws",
"azure",
"gcp"
],
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": ".objectLevelWorkloadIdentity must be set to true when .multitenantWorkloadIdentity is set to true",
"rule": "(has(self.objectLevelWorkloadIdentity) && self.objectLevelWorkloadIdentity) || !has(self.multitenantWorkloadIdentity) || !self.multitenantWorkloadIdentity"
}
],
"additionalProperties": false
},
"commonMetadata": {
"description": "CommonMetadata specifies the common labels and annotations that are\napplied to all resources. Any existing label or annotation will be\noverridden if its key matches a common one.",
"properties": {
"annotations": {
"additionalProperties": {
"type": "string"
},
"description": "Annotations to be added to the object's metadata.",
"type": "object"
},
"labels": {
"additionalProperties": {
"type": "string"
},
"description": "Labels to be added to the object's metadata.",
"type": "object"
}
},
"type": "object",
"additionalProperties": false
},
"components": {
"description": "Components is the list of controllers to install.\nDefaults to the core Flux controllers:\n - source-controller\n - kustomize-controller\n - helm-controller\n - notification-controller",
"items": {
"description": "Component is the name of a controller to install.",
"enum": [
"source-controller",
"kustomize-controller",
"helm-controller",
"notification-controller",
"image-reflector-controller",
"image-automation-controller",
"source-watcher"
],
"type": "string"
},
"type": "array"
},
"distribution": {
"description": "Distribution specifies the version and container registry to pull images from.",
"properties": {
"artifact": {
"description": "Artifact is the URL to the OCI artifact containing\nthe latest Kubernetes manifests for the distribution,\ne.g. 'oci://ghcr.io/controlplaneio-fluxcd/flux-operator-manifests:latest'.",
"pattern": "^oci://.*$",
"type": "string"
},
"artifactPullSecret": {
"description": "ArtifactPullSecret is the name of the Kubernetes secret\nto use for pulling the Kubernetes manifests for the distribution specified in the Artifact field.",
"type": "string"
},
"imagePullSecret": {
"description": "ImagePullSecret is the name of the Kubernetes secret\nto use for pulling images.",
"type": "string"
},
"registry": {
"description": "Registry address to pull the distribution images from\ne.g. 'ghcr.io/fluxcd'.",
"type": "string"
},
"variant": {
"description": "Variant specifies the Flux distribution flavor stored\nin the registry.",
"enum": [
"upstream-alpine",
"enterprise-alpine",
"enterprise-distroless",
"enterprise-distroless-fips"
],
"type": "string"
},
"version": {
"description": "Version semver expression e.g. '2.x', '2.3.x'.",
"type": "string"
}
},
"required": [
"registry",
"version"
],
"type": "object",
"additionalProperties": false
},
"kustomize": {
"description": "Kustomize holds a set of patches that can be applied to the\nFlux installation, to customize the way Flux operates.",
"properties": {
"patches": {
"description": "Strategic merge and JSON patches, defined as inline YAML objects,\ncapable of targeting objects based on kind, label and annotation selectors.",
"items": {
"description": "Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should\nbe applied to.",
"properties": {
"patch": {
"description": "Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with\nan array of operation objects.",
"type": "string"
},
"target": {
"description": "Target points to the resources that the patch document should be applied to.",
"properties": {
"annotationSelector": {
"description": "AnnotationSelector is a string that follows the label selection expression\nhttps://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api\nIt matches with the resource annotations.",
"type": "string"
},
"group": {
"description": "Group is the API group to select resources from.\nTogether with Version and Kind it is capable of unambiguously identifying and/or selecting resources.\nhttps://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md",
"type": "string"
},
"kind": {
"description": "Kind of the API Group to select resources from.\nTogether with Group and Version it is capable of unambiguously\nidentifying and/or selecting resources.\nhttps://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md",
"type": "string"
},
"labelSelector": {
"description": "LabelSelector is a string that follows the label selection expression\nhttps://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api\nIt matches with the resource labels.",
"type": "string"
},
"name": {
"description": "Name to match resources with.",
"type": "string"
},
"namespace": {
"description": "Namespace to select resources from.",
"type": "string"
},
"version": {
"description": "Version of the API Group to select resources from.\nTogether with Group and Kind it is capable of unambiguously identifying and/or selecting resources.\nhttps://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"patch"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"type": "object",
"additionalProperties": false
},
"migrateResources": {
"default": true,
"description": "MigrateResources instructs the controller to migrate the Flux custom resources\nfrom the previous version to the latest API version specified in the CRD.\nDefaults to true.",
"type": "boolean"
},
"sharding": {
"description": "Sharding holds the specification of the sharding configuration.",
"properties": {
"key": {
"default": "sharding.fluxcd.io/key",
"description": "Key is the label key used to shard the resources.",
"type": "string"
},
"shards": {
"description": "Shards is the list of shard names.",
"items": {
"type": "string"
},
"minItems": 1,
"type": "array"
},
"storage": {
"description": "Storage defines if the source-controller shards\nshould use an emptyDir or a persistent volume claim for storage.\nAccepted values are 'ephemeral' or 'persistent', defaults to 'ephemeral'.\nWhen set to 'persistent', the '.spec.storage' field must be set.",
"enum": [
"ephemeral",
"persistent"
],
"type": "string"
}
},
"required": [
"shards"
],
"type": "object",
"additionalProperties": false
},
"storage": {
"description": "Storage holds the specification of the source-controller\npersistent volume claim.",
"properties": {
"class": {
"description": "Class is the storage class to use for the PVC.",
"type": "string"
},
"size": {
"description": "Size is the size of the PVC.",
"type": "string"
}
},
"required": [
"class",
"size"
],
"type": "object",
"additionalProperties": false
},
"sync": {
"description": "Sync specifies the source for the cluster sync operation.\nWhen set, a Flux source (GitRepository, OCIRepository or Bucket)\nand Flux Kustomization are created to sync the cluster state\nwith the source repository.",
"properties": {
"interval": {
"default": "1m",
"description": "Interval is the time between syncs.",
"pattern": "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$",
"type": "string"
},
"kind": {
"description": "Kind is the kind of the source.",
"enum": [
"OCIRepository",
"GitRepository",
"Bucket"
],
"type": "string"
},
"name": {
"description": "Name is the name of the Flux source and kustomization resources.\nWhen not specified, the name is set to the namespace name of the FluxInstance.",
"maxLength": 63,
"type": "string",
"x-kubernetes-validations": [
{
"message": "Sync name is immutable",
"rule": "self == oldSelf"
}
]
},
"path": {
"description": "Path is the path to the source directory containing\nthe kustomize overlay or plain Kubernetes manifests.",
"type": "string"
},
"provider": {
"description": "Provider specifies OIDC provider for source authentication.\nFor OCIRepository and Bucket the provider can be set to 'aws', 'azure' or 'gcp'.\nFor GitRepository the provider can be set to 'aws' (requires Flux 2.9 or later),\n'azure' or 'github'.\nTo disable OIDC authentication the provider can be set to 'generic' or left empty.",
"enum": [
"generic",
"aws",
"azure",
"gcp",
"github"
],
"type": "string"
},
"pullSecret": {
"description": "PullSecret specifies the Kubernetes Secret containing the\nauthentication credentials for the source.\nFor Git over HTTP/S sources, the secret must contain username and password fields.\nFor Git over SSH sources, the secret must contain known_hosts and identity fields.\nFor OCI sources, the secret must be of type kubernetes.io/dockerconfigjson.\nFor Bucket sources, the secret must contain accesskey and secretkey fields.",
"type": "string"
},
"ref": {
"description": "Ref is the source reference, can be a Git ref name e.g. 'refs/heads/main',\nan OCI tag e.g. 'latest' or a bucket name e.g. 'flux'.",
"type": "string"
},
"url": {
"description": "URL is the source URL, can be a Git repository HTTP/S or SSH address,\nan OCI repository address or a Bucket endpoint.",
"type": "string"
}
},
"required": [
"kind",
"path",
"ref",
"url"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "sync.provider 'gcp' is only supported for OCIRepository and Bucket",
"rule": "!has(self.provider) || self.provider != 'gcp' || self.kind == 'OCIRepository' || self.kind == 'Bucket'"
},
{
"message": "sync.provider 'github' is only supported for GitRepository",
"rule": "!has(self.provider) || self.provider != 'github' || self.kind == 'GitRepository'"
}
],
"additionalProperties": false
},
"wait": {
"default": true,
"description": "Wait instructs the controller to check the health of all the reconciled\nresources. Defaults to true.",
"type": "boolean"
}
},
"required": [
"distribution"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": ".spec.storage must be set when .spec.sharding.storage is 'persistent'",
"rule": "!has(self.sharding) || !has(self.sharding.storage) || self.sharding.storage != 'persistent' || has(self.storage)"
}
],
"additionalProperties": false
},
"status": {
"description": "FluxInstanceStatus defines the observed state of FluxInstance",
"properties": {
"components": {
"description": "Components contains the container images used by the components.",
"items": {
"description": "ComponentImage represents a container image used by a component.",
"properties": {
"digest": {
"description": "Digest of the container image.",
"type": "string"
},
"name": {
"description": "Name of the component.",
"type": "string"
},
"repository": {
"description": "Repository address of the container image.",
"type": "string"
},
"tag": {
"description": "Tag of the container image.",
"type": "string"
}
},
"required": [
"name",
"repository",
"tag"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"conditions": {
"description": "Conditions contains the readiness conditions of the object.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"history": {
"description": "History contains the reconciliation history of the FluxInstance\nas a list of snapshots ordered by the last reconciled time.",
"items": {
"description": "Snapshot represents a point-in-time record of a group of resources reconciliation,\nincluding timing information, status, and a unique digest identifier.",
"properties": {
"digest": {
"description": "Digest is the checksum in the format `<algo>:<hex>` of the resources in this snapshot.",
"type": "string"
},
"firstReconciled": {
"description": "FirstReconciled is the time when this revision was first reconciled to the cluster.",
"format": "date-time",
"type": "string"
},
"lastReconciled": {
"description": "LastReconciled is the time when this revision was last reconciled to the cluster.",
"format": "date-time",
"type": "string"
},
"lastReconciledDuration": {
"description": "LastReconciledDuration is time it took to reconcile the resources in this revision.",
"type": "string"
},
"lastReconciledStatus": {
"description": "LastReconciledStatus is the status of the last reconciliation.",
"type": "string"
},
"metadata": {
"additionalProperties": {
"type": "string"
},
"description": "Metadata contains additional information about the snapshot.",
"type": "object"
},
"totalReconciliations": {
"description": "TotalReconciliations is the total number of reconciliations that have occurred for this snapshot.",
"format": "int64",
"type": "integer"
}
},
"required": [
"digest",
"firstReconciled",
"lastReconciled",
"lastReconciledDuration",
"lastReconciledStatus",
"totalReconciliations"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"inventory": {
"description": "Inventory contains a list of Kubernetes resource object references\nlast applied on the cluster.",
"properties": {
"entries": {
"description": "Entries of Kubernetes resource object references.",
"items": {
"description": "ResourceRef contains the information necessary to locate a resource within a cluster.",
"properties": {
"id": {
"description": "ID is the string representation of the Kubernetes resource object's metadata,\nin the format '<namespace>_<name>_<group>_<kind>'.",
"type": "string"
},
"v": {
"description": "Version is the API version of the Kubernetes resource object's kind.",
"type": "string"
}
},
"required": [
"id",
"v"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"entries"
],
"type": "object",
"additionalProperties": false
},
"lastAppliedRevision": {
"description": "LastAppliedRevision is the version and digest of the\ndistribution config that was last reconcile.",
"type": "string"
},
"lastArtifactRevision": {
"description": "LastArtifactRevision is the digest of the last pulled\ndistribution artifact.",
"type": "string"
},
"lastAttemptedRevision": {
"description": "LastAttemptedRevision is the version and digest of the\ndistribution config that was last attempted to reconcile.",
"type": "string"
},
"lastHandledForceAt": {
"description": "LastHandledForceAt holds the value of the most recent\nforce request value, so a change of the annotation value\ncan be detected.",
"type": "string"
},
"lastHandledReconcileAt": {
"description": "LastHandledReconcileAt holds the value of the most recent\nreconcile request value, so a change of the annotation value\ncan be detected.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "the only accepted name for a FluxInstance is 'flux'",
"rule": "self.metadata.name == 'flux'"
}
]
}
@@ -0,0 +1,290 @@
{
"description": "FluxReport is the Schema for the fluxreports API.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "FluxReportSpec defines the observed state of a Flux installation.",
"properties": {
"cluster": {
"description": "Cluster is the version information of the Kubernetes cluster.",
"properties": {
"nodes": {
"description": "Nodes is the number of nodes in the Kubernetes cluster.",
"type": "integer"
},
"platform": {
"description": "Platform is the os/arch of the Kubernetes control plane.",
"type": "string"
},
"serverVersion": {
"description": "ServerVersion is the version of the Kubernetes API server.",
"type": "string"
}
},
"required": [
"platform",
"serverVersion"
],
"type": "object",
"additionalProperties": false
},
"components": {
"description": "ComponentsStatus is the status of the Flux controller deployments.",
"items": {
"description": "FluxComponentStatus defines the observed state of a Flux component.",
"properties": {
"image": {
"description": "Image is the container image of the Flux component.",
"type": "string"
},
"name": {
"description": "Name is the name of the Flux component.",
"type": "string"
},
"ready": {
"description": "Ready is the readiness status of the Flux component.",
"type": "boolean"
},
"status": {
"description": "Status is a human-readable message indicating details\nabout the Flux component observed state.",
"type": "string"
}
},
"required": [
"image",
"name",
"ready",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"distribution": {
"description": "Distribution is the version information of the Flux installation.",
"properties": {
"entitlement": {
"description": "Entitlement is the entitlement verification status.",
"type": "string"
},
"managedBy": {
"description": "ManagedBy is the name of the operator managing the Flux instance.",
"type": "string"
},
"status": {
"description": "Status is a human-readable message indicating details\nabout the distribution observed state.",
"type": "string"
},
"version": {
"description": "Version is the version of the Flux instance.",
"type": "string"
}
},
"required": [
"entitlement",
"status"
],
"type": "object",
"additionalProperties": false
},
"operator": {
"description": "Operator is the version information of the Flux Operator.",
"properties": {
"apiVersion": {
"description": "APIVersion is the API version of the Flux Operator.",
"type": "string"
},
"platform": {
"description": "Platform is the os/arch of Flux Operator.",
"type": "string"
},
"version": {
"description": "Version is the version number of Flux Operator.",
"type": "string"
}
},
"required": [
"apiVersion",
"platform",
"version"
],
"type": "object",
"additionalProperties": false
},
"reconcilers": {
"description": "ReconcilersStatus is the list of Flux reconcilers and\ntheir statistics grouped by API kind.",
"items": {
"description": "FluxReconcilerStatus defines the observed state of a Flux reconciler.",
"properties": {
"apiVersion": {
"description": "APIVersion is the API version of the Flux resource.",
"type": "string"
},
"kind": {
"description": "Kind is the kind of the Flux resource.",
"type": "string"
},
"stats": {
"description": "Stats is the reconcile statics of the Flux resource kind.",
"properties": {
"failing": {
"description": "Failing is the number of reconciled\nresources in the Failing state and not Suspended.",
"type": "integer"
},
"running": {
"description": "Running is the number of reconciled\nresources in the Running state.",
"type": "integer"
},
"suspended": {
"description": "Suspended is the number of reconciled\nresources in the Suspended state.",
"type": "integer"
},
"totalSize": {
"description": "TotalSize is the total size of the artifacts in storage.",
"type": "string"
}
},
"required": [
"failing",
"running",
"suspended"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"apiVersion",
"kind"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"sync": {
"description": "SyncStatus is the status of the cluster sync\nSource and Kustomization resources.",
"properties": {
"id": {
"description": "ID is the identifier of the sync.",
"type": "string"
},
"path": {
"description": "Path is the kustomize path of the sync.",
"type": "string"
},
"ready": {
"description": "Ready is the readiness status of the sync.",
"type": "boolean"
},
"source": {
"description": "Source is the URL of the source repository.",
"type": "string"
},
"status": {
"description": "Status is a human-readable message indicating details\nabout the sync observed state.",
"type": "string"
}
},
"required": [
"id",
"ready",
"status"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"distribution"
],
"type": "object",
"additionalProperties": false
},
"status": {
"description": "FluxReportStatus defines the readiness of a FluxReport.",
"properties": {
"conditions": {
"description": "Conditions contains the readiness conditions of the object.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"lastHandledReconcileAt": {
"description": "LastHandledReconcileAt holds the value of the most recent\nreconcile request value, so a change of the annotation value\ncan be detected.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "the only accepted name for a FluxReport is 'flux'",
"rule": "self.metadata.name == 'flux'"
}
]
}
@@ -0,0 +1,455 @@
{
"description": "ResourceSet is the Schema for the ResourceSets API.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "ResourceSetSpec defines the desired state of ResourceSet",
"properties": {
"commonMetadata": {
"description": "CommonMetadata specifies the common labels and annotations that are\napplied to all resources. Any existing label or annotation will be\noverridden if its key matches a common one.",
"properties": {
"annotations": {
"additionalProperties": {
"type": "string"
},
"description": "Annotations to be added to the object's metadata.",
"type": "object"
},
"labels": {
"additionalProperties": {
"type": "string"
},
"description": "Labels to be added to the object's metadata.",
"type": "object"
}
},
"type": "object",
"additionalProperties": false
},
"dependsOn": {
"description": "DependsOn specifies the list of Kubernetes resources that must\nexist on the cluster before the reconciliation process starts.",
"items": {
"description": "Dependency defines a ResourceSet dependency on a Kubernetes resource.",
"properties": {
"apiVersion": {
"description": "APIVersion of the resource to depend on.",
"type": "string"
},
"kind": {
"description": "Kind of the resource to depend on.",
"type": "string"
},
"name": {
"description": "Name of the resource to depend on.",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource to depend on.",
"type": "string"
},
"ready": {
"description": "Ready checks if the resource Ready status condition is true.",
"type": "boolean"
},
"readyExpr": {
"description": "ReadyExpr checks if the resource satisfies the given CEL expression.\nThe expression replaces the default readiness check and\nis only evaluated if Ready is set to 'true'.",
"type": "string"
}
},
"required": [
"apiVersion",
"kind",
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"inputStrategy": {
"description": "InputStrategy defines how the inputs are combined when multiple\ninput provider objects are used. Defaults to flattening all inputs\nfrom all providers into a single list of input sets.",
"properties": {
"includeEmptyProviders": {
"description": "IncludeEmptyProviders controls how input providers that export no\ninputs are treated. Only applies when Name is Permute. When true, if\nany provider has zero inputs the resulting permutation set is empty\n(mathematically correct Cartesian product behavior). When false or\nunset (default), providers with zero inputs are silently skipped and\nthe remaining providers still permute among themselves.",
"type": "boolean"
},
"name": {
"description": "Name defines how the inputs are combined when multiple\ninput provider objects are used. Supported values are:\n- Flatten: all inputs sets from all input provider objects are\n flattened into a single list of input sets.\n- Permute: all inputs sets from all input provider objects are\n combined using a Cartesian product, resulting in a list of input sets\n that contains every possible combination of input values.\n For example, if provider A has inputs [{x: 1}, {x: 2}] and provider B has\n inputs [{y: \"a\"}, {y: \"b\"}], the resulting input sets will be:\n [{x: 1, y: \"a\"}, {x: 1, y: \"b\"}, {x: 2, y: \"a\"}, {x: 2, y: \"b\"}].\n This strategy can lead to a large number of input sets and should be\n used with caution. Users should use filtering features from\n ResourceSetInputProvider to limit the amount of exported inputs.",
"enum": [
"Flatten",
"Permute"
],
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "includeEmptyProviders only applies when name is Permute",
"rule": "!has(self.includeEmptyProviders) || self.name == 'Permute'"
}
],
"additionalProperties": false
},
"inputs": {
"description": "Inputs contains the list of ResourceSet inputs.",
"items": {
"additionalProperties": {
"x-kubernetes-preserve-unknown-fields": true
},
"description": "ResourceSetInput defines the key-value pairs of the ResourceSet input.",
"type": "object"
},
"type": "array"
},
"inputsFrom": {
"description": "InputsFrom contains the list of references to input providers.\nWhen set, the inputs are fetched from the providers and concatenated\nwith the in-line inputs defined in the ResourceSet.",
"items": {
"description": "InputProviderReference defines a reference to an input provider resource\nin the same namespace as the ResourceSet.",
"properties": {
"apiVersion": {
"description": "APIVersion of the input provider resource.\nWhen not set, the APIVersion of the ResourceSet is used.",
"enum": [
"fluxcd.controlplane.io/v1"
],
"type": "string"
},
"kind": {
"description": "Kind of the input provider resource.",
"enum": [
"ResourceSetInputProvider"
],
"type": "string"
},
"name": {
"description": "Name of the input provider resource. Cannot be set\nwhen the Selector field is set.",
"type": "string"
},
"selector": {
"description": "Selector is a label selector to filter the input provider resources\nas an alternative to the Name field.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one of name or selector must be set for input provider references",
"rule": "has(self.name) || has(self.selector)"
},
{
"message": "cannot set both name and selector for input provider references",
"rule": "!has(self.name) || !has(self.selector)"
}
],
"additionalProperties": false
},
"type": "array"
},
"resources": {
"description": "Resources contains the list of Kubernetes resources to reconcile.",
"items": {
"type": "object",
"x-kubernetes-preserve-unknown-fields": true
},
"type": "array"
},
"resourcesTemplate": {
"description": "ResourcesTemplate is a Go template that generates the list of\nKubernetes resources to reconcile. The template is rendered\nas multi-document YAML, the resources should be separated by '---'.\nWhen both Resources and ResourcesTemplate are set, the resulting\nobjects are merged and deduplicated, with the ones from Resources taking precedence.",
"type": "string"
},
"serviceAccountName": {
"description": "The name of the Kubernetes service account to impersonate\nwhen reconciling the generated resources.",
"type": "string"
},
"steps": {
"description": "Steps contains an ordered list of named steps to reconcile in sequence.\nEach step's resources are applied and health-checked before the next\nstep starts. Mutually exclusive with Resources and ResourcesTemplate.",
"items": {
"description": "ResourceSetStep defines a named step in the ResourceSet reconciliation\nsequence. The step's resources are applied and health-checked before\nthe next step starts.",
"properties": {
"name": {
"description": "Name of the step, must be unique within the ResourceSet.",
"maxLength": 63,
"pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?$",
"type": "string"
},
"resources": {
"description": "Resources contains the list of Kubernetes resources to reconcile.",
"items": {
"type": "object",
"x-kubernetes-preserve-unknown-fields": true
},
"type": "array"
},
"resourcesTemplate": {
"description": "ResourcesTemplate is a Go template that generates the list of\nKubernetes resources to reconcile. The template is rendered\nas multi-document YAML, the resources should be separated by '---'.\nWhen both Resources and ResourcesTemplate are set, the resulting\nobjects are merged and deduplicated, with the ones from Resources taking precedence.",
"type": "string"
},
"timeout": {
"description": "Timeout is the maximum time to wait for the step's resources to\nbecome ready. When not set, the ResourceSet reconciliation\ntimeout is used.",
"pattern": "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one of resources or resourcesTemplate must be set",
"rule": "has(self.resources) || has(self.resourcesTemplate)"
}
],
"additionalProperties": false
},
"maxItems": 20,
"minItems": 1,
"type": "array",
"x-kubernetes-validations": [
{
"message": "step names must be unique",
"rule": "self.all(s, self.exists_one(t, t.name == s.name))"
}
]
},
"wait": {
"description": "Wait instructs the controller to check the health\nof all the reconciled resources.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "steps is mutually exclusive with resources and resourcesTemplate",
"rule": "!has(self.steps) || (!has(self.resources) && !has(self.resourcesTemplate))"
},
{
"message": "at least one of steps, resources or resourcesTemplate must be set",
"rule": "has(self.steps) || has(self.resources) || has(self.resourcesTemplate)"
}
],
"additionalProperties": false
},
"status": {
"description": "ResourceSetStatus defines the observed state of ResourceSet.",
"properties": {
"conditions": {
"description": "Conditions contains the readiness conditions of the object.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"externalChecksumRefs": {
"description": "ExternalChecksumRefs lists the ConfigMap and Secret references\ndiscovered in checksumFrom annotations on the last reconciliation\nthat point to objects not rendered by this ResourceSet. Each entry\nhas the form \"Kind/namespace/name\". It is used to trigger a\nreconciliation when one of the referenced objects changes.",
"items": {
"type": "string"
},
"type": "array"
},
"history": {
"description": "History contains the reconciliation history of the ResourceSet\nas a list of snapshots ordered by the last reconciled time.",
"items": {
"description": "Snapshot represents a point-in-time record of a group of resources reconciliation,\nincluding timing information, status, and a unique digest identifier.",
"properties": {
"digest": {
"description": "Digest is the checksum in the format `<algo>:<hex>` of the resources in this snapshot.",
"type": "string"
},
"firstReconciled": {
"description": "FirstReconciled is the time when this revision was first reconciled to the cluster.",
"format": "date-time",
"type": "string"
},
"lastReconciled": {
"description": "LastReconciled is the time when this revision was last reconciled to the cluster.",
"format": "date-time",
"type": "string"
},
"lastReconciledDuration": {
"description": "LastReconciledDuration is time it took to reconcile the resources in this revision.",
"type": "string"
},
"lastReconciledStatus": {
"description": "LastReconciledStatus is the status of the last reconciliation.",
"type": "string"
},
"metadata": {
"additionalProperties": {
"type": "string"
},
"description": "Metadata contains additional information about the snapshot.",
"type": "object"
},
"totalReconciliations": {
"description": "TotalReconciliations is the total number of reconciliations that have occurred for this snapshot.",
"format": "int64",
"type": "integer"
}
},
"required": [
"digest",
"firstReconciled",
"lastReconciled",
"lastReconciledDuration",
"lastReconciledStatus",
"totalReconciliations"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"inventory": {
"description": "Inventory contains a list of Kubernetes resource object references\nlast applied on the cluster.",
"properties": {
"entries": {
"description": "Entries of Kubernetes resource object references.",
"items": {
"description": "ResourceRef contains the information necessary to locate a resource within a cluster.",
"properties": {
"id": {
"description": "ID is the string representation of the Kubernetes resource object's metadata,\nin the format '<namespace>_<name>_<group>_<kind>'.",
"type": "string"
},
"v": {
"description": "Version is the API version of the Kubernetes resource object's kind.",
"type": "string"
}
},
"required": [
"id",
"v"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"entries"
],
"type": "object",
"additionalProperties": false
},
"lastAppliedRevision": {
"description": "LastAppliedRevision is the digest of the\ngenerated resources that were last reconcile.",
"type": "string"
},
"lastHandledReconcileAt": {
"description": "LastHandledReconcileAt holds the value of the most recent\nreconcile request value, so a change of the annotation value\ncan be detected.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,360 @@
{
"description": "ResourceSetInputProvider is the Schema for the ResourceSetInputProviders API.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "ResourceSetInputProviderSpec defines the desired state of ResourceSetInputProvider",
"properties": {
"certSecretRef": {
"description": "CertSecretRef specifies the Kubernetes Secret containing either or both of\n\n- a PEM-encoded CA certificate (`ca.crt`)\n- a PEM-encoded client certificate (`tls.crt`) and private key (`tls.key`)\n\nWhen connecting to a Git, OCI, or ExternalService provider that uses self-signed certificates,\nthe CA certificate must be set in the Secret under the 'ca.crt' key to establish the trust relationship.\nWhen connecting to a provider that supports client certificates (mTLS), the client certificate\nand private key must be set in the Secret under the 'tls.crt' and 'tls.key' keys, respectively.",
"properties": {
"name": {
"description": "Name of the referent.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"defaultValues": {
"additionalProperties": {
"x-kubernetes-preserve-unknown-fields": true
},
"description": "DefaultValues contains the default values for the inputs.\nThese values are used to populate the inputs when the provider\nresponse does not contain them.",
"type": "object"
},
"filter": {
"description": "Filter defines the filter to apply to the input provider response.",
"properties": {
"excludeBranch": {
"description": "ExcludeBranch specifies the regular expression to filter the branches\nthat the input provider should exclude.",
"type": "string"
},
"excludeEnvironment": {
"description": "ExcludeEnvironment specifies the regular expression to filter the environments\nthat the input provider should exclude.",
"type": "string"
},
"excludeTag": {
"description": "ExcludeTag specifies the regular expression to filter the tags\nthat the input provider should exclude.",
"type": "string"
},
"includeBranch": {
"description": "IncludeBranch specifies the regular expression to filter the branches\nthat the input provider should include.",
"type": "string"
},
"includeEnvironment": {
"description": "IncludeEnvironment specifies the regular expression to filter the environments\nthat the input provider should include.",
"type": "string"
},
"includeTag": {
"description": "IncludeTag specifies the regular expression to filter the tags\nthat the input provider should include.",
"type": "string"
},
"labels": {
"description": "Labels specifies the list of labels to filter the input provider response.",
"items": {
"type": "string"
},
"type": "array"
},
"limit": {
"default": 100,
"description": "Limit specifies the maximum number of input sets to return.\nWhen not set, the default limit is 100.",
"type": "integer"
},
"semver": {
"description": "Semver specifies a semantic version range to filter and sort the tags.\nIf this field is not specified, the tags will be sorted in reverse\nalphabetical order.\nSupported only for tags at the moment.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"insecure": {
"description": "Insecure allows connecting to an ExternalService or OCIArtifactTag provider\nover plain HTTP without TLS. When not set, the URL must use HTTPS.",
"type": "boolean"
},
"schedule": {
"description": "Schedule defines the schedules for the input provider to run.",
"items": {
"description": "Schedule defines a schedule for something to run.",
"properties": {
"cron": {
"description": "Cron specifies the cron expression for the schedule.",
"type": "string"
},
"timeZone": {
"default": "UTC",
"description": "TimeZone specifies the time zone for the cron schedule. Defaults to UTC.",
"type": "string"
},
"window": {
"default": "0s",
"description": "Window defines the time window during which the execution is allowed.\nDefaults to 0s, meaning no window is applied.",
"pattern": "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$",
"type": "string"
}
},
"required": [
"cron"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"secretRef": {
"description": "SecretRef specifies the Kubernetes Secret containing the credentials\nto access the input provider.\nWhen connecting to a Git provider, the secret must contain the keys\n'username' and 'password', and the password should be a personal access token\nthat grants read-only access to the repository.\nWhen connecting to an OCI provider, the secret must contain a Kubernetes\nImage Pull Secret, as if created by `kubectl create secret docker-registry`.\nWhen connecting to an ExternalService provider, the secret must contain either\na 'token' key for bearer token authentication, or 'username' and 'password'\nkeys for basic authentication.",
"properties": {
"name": {
"description": "Name of the referent.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"serviceAccountName": {
"description": "ServiceAccountName specifies the name of the Kubernetes ServiceAccount\nused for authentication with AWS, Azure or GCP services through\nworkload identity federation features. If not specified, the\nauthentication for these cloud providers will use the ServiceAccount\nof the operator (or any other environment authentication configuration).",
"type": "string"
},
"skip": {
"description": "Skip defines whether we need to skip input provider response updates.",
"properties": {
"labels": {
"description": "Labels specifies list of labels to skip input provider response when any of the label conditions matched.\nWhen prefixed with !, input provider response will be skipped if it does not have this label.",
"items": {
"type": "string"
},
"type": "array"
}
},
"type": "object",
"additionalProperties": false
},
"type": {
"description": "Type specifies the type of the input provider.",
"enum": [
"Static",
"GitHubBranch",
"GitHubTag",
"GitHubPullRequest",
"GitLabBranch",
"GitLabTag",
"GitLabMergeRequest",
"GitLabEnvironment",
"AzureDevOpsBranch",
"AzureDevOpsTag",
"AzureDevOpsPullRequest",
"AWSCodeCommitBranch",
"AWSCodeCommitTag",
"AWSCodeCommitPullRequest",
"GiteaBranch",
"GiteaTag",
"GiteaPullRequest",
"OCIArtifactTag",
"ACRArtifactTag",
"ECRArtifactTag",
"GARArtifactTag",
"ExternalService"
],
"type": "string"
},
"url": {
"description": "URL specifies the HTTP/S or OCI address of the input provider API.\nWhen connecting to a Git provider, the URL should point to the repository address.\nWhen connecting to an OCI provider, the URL should point to the OCI repository address.",
"pattern": "^((http|https|oci)://.*){0,1}$",
"type": "string"
}
},
"required": [
"type"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "spec.url must be empty when spec.type is 'Static'",
"rule": "self.type != 'Static' || !has(self.url)"
},
{
"message": "spec.url must not be empty when spec.type is not 'Static'",
"rule": "self.type == 'Static' || has(self.url)"
},
{
"message": "spec.url must start with 'http://' or 'https://' when spec.type is a Git provider",
"rule": "!self.type.startsWith('Git') || self.url.startsWith('http')"
},
{
"message": "spec.url must start with 'http://' or 'https://' when spec.type is an AzureDevOps provider",
"rule": "!self.type.startsWith('AzureDevOps') || self.url.startsWith('http://') || self.url.startsWith('https://')"
},
{
"message": "spec.url must start with 'https://' when spec.type is a AWSCodeCommit provider",
"rule": "!self.type.startsWith('AWSCodeCommit') || self.url.startsWith('https://')"
},
{
"message": "spec.url must start with 'oci://' when spec.type is an OCI provider",
"rule": "!self.type.endsWith('ArtifactTag') || self.url.startsWith('oci')"
},
{
"message": "spec.url must start with 'http://' or 'https://' when spec.type is 'ExternalService'",
"rule": "self.type != 'ExternalService' || self.url.startsWith('http')"
},
{
"message": "spec.insecure can only be set when spec.type is 'ExternalService' or 'OCIArtifactTag'",
"rule": "!has(self.insecure) || !self.insecure || self.type == 'ExternalService' || self.type == 'OCIArtifactTag'"
},
{
"message": "spec.url must use 'https://' unless spec.insecure is true",
"rule": "self.type != 'ExternalService' || !self.url.startsWith('http://') || (has(self.insecure) && self.insecure)"
},
{
"message": "cannot specify spec.serviceAccountName when spec.type is not one of AzureDevOps*, AWSCodeCommit* or *ArtifactTag",
"rule": "!has(self.serviceAccountName) || self.type.startsWith('AzureDevOps') || self.type.startsWith('AWSCodeCommit') || self.type.endsWith('ArtifactTag')"
},
{
"message": "cannot specify spec.certSecretRef when spec.type is one of Static, AzureDevOps*, AWSCodeCommit*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
"rule": "!has(self.certSecretRef) || !(self.type == 'Static' || self.type.startsWith('AzureDevOps') || self.type.startsWith('AWSCodeCommit') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
},
{
"message": "cannot specify spec.secretRef when spec.type is one of Static, AWSCodeCommit*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag",
"rule": "!has(self.secretRef) || !(self.type == 'Static' || self.type.startsWith('AWSCodeCommit') || (self.type.endsWith('ArtifactTag') && self.type != 'OCIArtifactTag'))"
}
],
"additionalProperties": false
},
"status": {
"description": "ResourceSetInputProviderStatus defines the observed state of ResourceSetInputProvider.",
"properties": {
"conditions": {
"description": "Conditions contains the readiness conditions of the object.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"exportedInputs": {
"description": "ExportedInputs contains the list of inputs exported by the provider.",
"items": {
"additionalProperties": {
"x-kubernetes-preserve-unknown-fields": true
},
"description": "ResourceSetInput defines the key-value pairs of the ResourceSet input.",
"type": "object"
},
"type": "array"
},
"lastExportedRevision": {
"description": "LastExportedRevision is the digest of the\ninputs that were last reconcile.",
"type": "string"
},
"lastHandledForceAt": {
"description": "LastHandledForceAt holds the value of the most recent\nforce request value, so a change of the annotation value\ncan be detected.",
"type": "string"
},
"lastHandledReconcileAt": {
"description": "LastHandledReconcileAt holds the value of the most recent\nreconcile request value, so a change of the annotation value\ncan be detected.",
"type": "string"
},
"nextSchedule": {
"description": "NextSchedule is the next schedule when the input provider will run.",
"properties": {
"cron": {
"description": "Cron specifies the cron expression for the schedule.",
"type": "string"
},
"timeZone": {
"default": "UTC",
"description": "TimeZone specifies the time zone for the cron schedule. Defaults to UTC.",
"type": "string"
},
"when": {
"description": "When is the next time the schedule will run.",
"format": "date-time",
"type": "string"
},
"window": {
"default": "0s",
"description": "Window defines the time window during which the execution is allowed.\nDefaults to 0s, meaning no window is applied.",
"pattern": "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$",
"type": "string"
}
},
"required": [
"cron",
"when"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}