update crds

This commit is contained in:
2026-08-18 19:18:31 +01:00
parent 717d09d1f3
commit bb5fc11402
268 changed files with 88606 additions and 1644 deletions
@@ -0,0 +1,459 @@
{
"description": "AccessControlPolicy defines an access control policy.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "AccessControlPolicySpec configures an access control policy.",
"properties": {
"apiKey": {
"description": "AccessControlPolicyAPIKey configure an APIKey control policy.",
"properties": {
"forwardHeaders": {
"additionalProperties": {
"type": "string"
},
"description": "ForwardHeaders instructs the middleware to forward key metadata as header values upon successful authentication.",
"type": "object"
},
"keySource": {
"description": "KeySource defines how to extract API keys from requests.",
"properties": {
"cookie": {
"description": "Cookie is the name of a cookie.",
"type": "string"
},
"header": {
"description": "Header is the name of a header.",
"type": "string"
},
"headerAuthScheme": {
"description": "HeaderAuthScheme sets an optional auth scheme when Header is set to \"Authorization\".\nIf set, this scheme is removed from the token, and all requests not including it are dropped.",
"type": "string"
},
"query": {
"description": "Query is the name of a query parameter.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"keys": {
"description": "Keys define the set of authorized keys to access a protected resource.",
"items": {
"description": "AccessControlPolicyAPIKeyKey defines an API key.",
"properties": {
"id": {
"description": "ID is the unique identifier of the key.",
"type": "string"
},
"metadata": {
"additionalProperties": {
"type": "string"
},
"description": "Metadata holds arbitrary metadata for this key, can be used by ForwardHeaders.",
"type": "object"
},
"value": {
"description": "Value is the SHAKE-256 hash (using 64 bytes) of the API key.",
"type": "string"
}
},
"required": [
"id",
"value"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"keySource"
],
"type": "object",
"additionalProperties": false
},
"basicAuth": {
"description": "AccessControlPolicyBasicAuth holds the HTTP basic authentication configuration.",
"properties": {
"forwardUsernameHeader": {
"type": "string"
},
"realm": {
"type": "string"
},
"stripAuthorizationHeader": {
"type": "boolean"
},
"users": {
"items": {
"type": "string"
},
"type": "array"
}
},
"type": "object",
"additionalProperties": false
},
"jwt": {
"description": "AccessControlPolicyJWT configures a JWT access control policy.",
"properties": {
"claims": {
"type": "string"
},
"forwardHeaders": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"jwksFile": {
"type": "string"
},
"jwksUrl": {
"type": "string"
},
"publicKey": {
"type": "string"
},
"signingSecret": {
"type": "string"
},
"signingSecretBase64Encoded": {
"type": "boolean"
},
"stripAuthorizationHeader": {
"type": "boolean"
},
"tokenQueryKey": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"oAuthIntro": {
"description": "AccessControlOAuthIntro configures an OAuth 2.0 Token Introspection access control policy.",
"properties": {
"claims": {
"type": "string"
},
"clientConfig": {
"description": "AccessControlOAuthIntroClientConfig configures the OAuth 2.0 client for issuing token introspection requests.",
"properties": {
"headers": {
"additionalProperties": {
"type": "string"
},
"description": "Headers to set when sending requests to the Authorization Server.",
"type": "object"
},
"maxRetries": {
"default": 3,
"description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
"type": "integer"
},
"timeoutSeconds": {
"default": 5,
"description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
"type": "integer"
},
"tls": {
"description": "TLS configures TLS for the HTTP client.",
"properties": {
"ca": {
"description": "CA sets the CA bundle used to verify the server certificate.",
"type": "string"
},
"insecureSkipVerify": {
"description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"tokenTypeHint": {
"description": "TokenTypeHint is a hint to pass to the Authorization Server.\nSee https://tools.ietf.org/html/rfc7662#section-2.1 for more information.",
"type": "string"
},
"url": {
"description": "URL of the Authorization Server.",
"type": "string"
}
},
"required": [
"url"
],
"type": "object",
"additionalProperties": false
},
"forwardHeaders": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"tokenSource": {
"description": "TokenSource describes how to extract tokens from HTTP requests.\nIf multiple sources are set, the order is the following: header > query > cookie.",
"properties": {
"cookie": {
"description": "Cookie is the name of a cookie.",
"type": "string"
},
"header": {
"description": "Header is the name of a header.",
"type": "string"
},
"headerAuthScheme": {
"description": "HeaderAuthScheme sets an optional auth scheme when Header is set to \"Authorization\".\nIf set, this scheme is removed from the token, and all requests not including it are dropped.",
"type": "string"
},
"query": {
"description": "Query is the name of a query parameter.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"clientConfig",
"tokenSource"
],
"type": "object",
"additionalProperties": false
},
"oidc": {
"description": "AccessControlPolicyOIDC holds the OIDC authentication configuration.",
"properties": {
"authParams": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"claims": {
"type": "string"
},
"clientId": {
"type": "string"
},
"disableAuthRedirectionPaths": {
"items": {
"type": "string"
},
"type": "array"
},
"forwardHeaders": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"issuer": {
"type": "string"
},
"logoutUrl": {
"type": "string"
},
"redirectUrl": {
"type": "string"
},
"scopes": {
"items": {
"type": "string"
},
"type": "array"
},
"secret": {
"description": "SecretReference represents a Secret Reference. It has enough information to retrieve secret\nin any namespace",
"properties": {
"name": {
"description": "name is unique within a namespace to reference a secret resource.",
"type": "string"
},
"namespace": {
"description": "namespace defines the space within which the secret name must be unique.",
"type": "string"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"session": {
"description": "Session holds session configuration.",
"properties": {
"domain": {
"type": "string"
},
"path": {
"type": "string"
},
"refresh": {
"type": "boolean"
},
"sameSite": {
"type": "string"
},
"secure": {
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"stateCookie": {
"description": "StateCookie holds state cookie configuration.",
"properties": {
"domain": {
"type": "string"
},
"path": {
"type": "string"
},
"sameSite": {
"type": "string"
},
"secure": {
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"oidcGoogle": {
"description": "AccessControlPolicyOIDCGoogle holds the Google OIDC authentication configuration.",
"properties": {
"authParams": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"clientId": {
"type": "string"
},
"emails": {
"description": "Emails are the allowed emails to connect.",
"items": {
"type": "string"
},
"minItems": 1,
"type": "array"
},
"forwardHeaders": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"logoutUrl": {
"type": "string"
},
"redirectUrl": {
"type": "string"
},
"secret": {
"description": "SecretReference represents a Secret Reference. It has enough information to retrieve secret\nin any namespace",
"properties": {
"name": {
"description": "name is unique within a namespace to reference a secret resource.",
"type": "string"
},
"namespace": {
"description": "namespace defines the space within which the secret name must be unique.",
"type": "string"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"session": {
"description": "Session holds session configuration.",
"properties": {
"domain": {
"type": "string"
},
"path": {
"type": "string"
},
"refresh": {
"type": "boolean"
},
"sameSite": {
"type": "string"
},
"secure": {
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"stateCookie": {
"description": "StateCookie holds state cookie configuration.",
"properties": {
"domain": {
"type": "string"
},
"path": {
"type": "string"
},
"sameSite": {
"type": "string"
},
"secure": {
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this access control policy.",
"properties": {
"specHash": {
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,487 @@
{
"description": "AIService is a Kubernetes-like Service to interact with a text-based LLM provider. It defines the parameters and credentials required to interact with various LLM providers.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this AIService.",
"properties": {
"anthropic": {
"description": "Anthropic configures Anthropic backend.",
"properties": {
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
},
"token": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"azureOpenai": {
"description": "AzureOpenAI configures AzureOpenAI.",
"properties": {
"apiKeySecret": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
},
"baseUrl": {
"type": "string"
},
"deploymentName": {
"type": "string"
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"baseUrl",
"deploymentName"
],
"type": "object",
"additionalProperties": false
},
"bedrock": {
"description": "Bedrock configures Bedrock backend.",
"properties": {
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
},
"region": {
"type": "string"
},
"systemMessage": {
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"cohere": {
"description": "Cohere configures Cohere backend.",
"properties": {
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
},
"token": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"deepSeek": {
"description": "DeepSeek configures DeepSeek.",
"properties": {
"baseUrl": {
"type": "string"
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
},
"token": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"gemini": {
"description": "Gemini configures Gemini backend.",
"properties": {
"apiKey": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"mistral": {
"description": "Mistral configures Mistral AI backend.",
"properties": {
"apiKey": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"ollama": {
"description": "Ollama configures Ollama backend.",
"properties": {
"baseUrl": {
"type": "string"
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"baseUrl"
],
"type": "object",
"additionalProperties": false
},
"openai": {
"description": "OpenAI configures OpenAI.",
"properties": {
"baseUrl": {
"type": "string"
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
},
"token": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"qWen": {
"description": "QWen configures QWen.",
"properties": {
"baseUrl": {
"type": "string"
},
"model": {
"type": "string"
},
"params": {
"description": "Params holds the LLM hyperparameters.",
"properties": {
"frequencyPenalty": {
"type": "number"
},
"maxTokens": {
"type": "integer"
},
"presencePenalty": {
"type": "number"
},
"temperature": {
"type": "number"
},
"topP": {
"type": "number"
}
},
"type": "object",
"additionalProperties": false
},
"token": {
"description": "SecretReference references a kubernetes secret.",
"properties": {
"secretName": {
"maxLength": 253,
"type": "string"
}
},
"required": [
"secretName"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
+349
View File
@@ -0,0 +1,349 @@
{
"description": "API defines an HTTP interface that is exposed to external clients. It specifies the supported versions\nand provides instructions for accessing its documentation. Once instantiated, an API object is associated\nwith an Ingress, IngressRoute, or HTTPRoute resource, enabling the exposure of the described API to the outside world.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "APISpec describes the API.",
"properties": {
"cors": {
"description": "Cors defines the Cross-Origin Resource Sharing configuration.",
"properties": {
"addVaryHeader": {
"description": "AddVaryHeader defines whether the Vary header is automatically added/updated when the AllowOriginsList is set.",
"type": "boolean"
},
"allowCredentials": {
"description": "AllowCredentials defines whether the request can include user credentials.",
"type": "boolean"
},
"allowHeadersList": {
"description": "AllowHeadersList defines the Access-Control-Request-Headers values sent in preflight response.",
"items": {
"type": "string"
},
"type": "array"
},
"allowMethodsList": {
"description": "AllowMethodsList defines the Access-Control-Request-Method values sent in preflight response.",
"items": {
"type": "string"
},
"type": "array"
},
"allowOriginListRegex": {
"description": "AllowOriginListRegex is a list of allowable origins written following the Regular Expression syntax (https://golang.org/pkg/regexp/).",
"items": {
"type": "string"
},
"type": "array"
},
"allowOriginsList": {
"description": "AllowOriginsList is a list of allowable origins. Can also be a wildcard origin \"*\".",
"items": {
"type": "string"
},
"type": "array"
},
"exposeHeadersList": {
"description": "ExposeHeadersList defines the Access-Control-Expose-Headers values sent in preflight response.",
"items": {
"type": "string"
},
"type": "array"
},
"maxAge": {
"description": "MaxAge defines the time that a preflight request may be cached.",
"format": "int64",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"description": {
"description": "Description explains what the API does.",
"type": "string"
},
"openApiSpec": {
"description": "OpenAPISpec defines the API contract as an OpenAPI specification.",
"properties": {
"operationSets": {
"description": "OperationSets defines the sets of operations to be referenced for granular filtering in APICatalogItems or ManagedSubscriptions.",
"items": {
"description": "OperationSet gives a name to a set of matching OpenAPI operations.\nThis set of operations can then be referenced for granular filtering in APICatalogItems or ManagedSubscriptions.",
"properties": {
"matchers": {
"description": "Matchers defines a list of alternative rules for matching OpenAPI operations.",
"items": {
"description": "OperationMatcher defines criteria for matching an OpenAPI operation.",
"minProperties": 1,
"properties": {
"methods": {
"description": "Methods specifies the HTTP methods to be included for selection.",
"items": {
"type": "string"
},
"maxItems": 10,
"type": "array"
},
"path": {
"description": "Path specifies the exact path of the operations to select.",
"maxLength": 255,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must start with a '/'",
"rule": "self.startsWith('/')"
},
{
"message": "cannot contains '../'",
"rule": "!self.matches(r\"\"\"(\\/\\.\\.\\/)|(\\/\\.\\.$)\"\"\")"
}
]
},
"pathPrefix": {
"description": "PathPrefix specifies the path prefix of the operations to select.",
"maxLength": 255,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must start with a '/'",
"rule": "self.startsWith('/')"
},
{
"message": "cannot contains '../'",
"rule": "!self.matches(r\"\"\"(\\/\\.\\.\\/)|(\\/\\.\\.$)\"\"\")"
}
]
},
"pathRegex": {
"description": "PathRegex specifies a regular expression pattern for matching operations based on their paths.",
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "path, pathPrefix and pathRegex are mutually exclusive",
"rule": "[has(self.path), has(self.pathPrefix), has(self.pathRegex)].filter(x, x).size() <= 1"
}
],
"additionalProperties": false
},
"maxItems": 100,
"minItems": 1,
"type": "array"
},
"name": {
"description": "Name is the name of the OperationSet to reference in APICatalogItems or ManagedSubscriptions.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"matchers",
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array"
},
"override": {
"description": "Override holds data used to override OpenAPI specification.",
"properties": {
"servers": {
"items": {
"properties": {
"url": {
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid URL",
"rule": "isURL(self)"
}
]
}
},
"required": [
"url"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"minItems": 1,
"type": "array"
}
},
"required": [
"servers"
],
"type": "object",
"additionalProperties": false
},
"path": {
"description": "Path specifies the endpoint path within the Kubernetes Service where the OpenAPI specification can be obtained.\nThe Service queried is determined by the associated Ingress, IngressRoute, or HTTPRoute resource to which the API is attached.\nIt's important to note that this option is incompatible if the Ingress or IngressRoute specifies multiple backend services.\nThe Path must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"maxLength": 255,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must start with a '/'",
"rule": "self.startsWith('/')"
},
{
"message": "cannot contains '../'",
"rule": "!self.matches(r\"\"\"(\\/\\.\\.\\/)|(\\/\\.\\.$)\"\"\")"
}
]
},
"refreshInterval": {
"description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
"format": "duration",
"type": "string"
},
"url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid URL",
"rule": "isURL(self)"
}
]
},
"validateRequestBodySchema": {
"description": "ValidateRequestBodySchema validates the request body against the OpenAPI specification.\nThis option overrides the default behavior configured in the static configuration.",
"type": "boolean"
},
"validateRequestMethodAndPath": {
"description": "ValidateRequestMethodAndPath validates that the path and method matches an operation defined in the OpenAPI specification.\nThis option overrides the default behavior configured in the static configuration.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "path or url must be defined",
"rule": "has(self.path) || has(self.url)"
}
],
"additionalProperties": false
},
"title": {
"description": "Title is the human-readable name of the API that will be used on the portal.",
"maxLength": 253,
"type": "string"
},
"versions": {
"description": "Versions are the different APIVersions available.",
"items": {
"description": "APIVersionRef references an APIVersion.",
"properties": {
"name": {
"description": "Name of the APIVersion.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"minItems": 1,
"type": "array"
}
},
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this API.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the API.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,330 @@
{
"description": "APIAuth defines the authentication configuration for APIs.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIAuth.",
"properties": {
"apiKey": {
"description": "APIKey configures API key authentication.",
"properties": {
"keySource": {
"description": "KeySource defines where to extract the API key from requests.\nWhen not specified, defaults to \"Authorization\" header with \"Bearer\" scheme and \"api_key\" query parameter.\nWhen specified, it completely overrides defaults - fields left empty will disable that extraction method.",
"minProperties": 1,
"properties": {
"header": {
"description": "Header is the name of the header containing the API key.",
"type": "string"
},
"headerAuthScheme": {
"description": "HeaderAuthScheme is the authentication scheme prefix in the header value.\nThe scheme is used to parse headers in the format \"<scheme> <token>\".\nOnly applies when header is \"Authorization\".",
"type": "string"
},
"query": {
"description": "Query is the name of the query parameter containing the API key.",
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "headerAuthScheme can only be used when header is 'Authorization'",
"rule": "!has(self.headerAuthScheme) || self.header == 'Authorization'"
}
],
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"isDefault": {
"description": "IsDefault specifies if this APIAuth should be used as the default API authentication method for the namespace.\nOnly one APIAuth per namespace should have isDefault set to true.",
"type": "boolean"
},
"jwt": {
"description": "JWT configures JWT authentication.",
"properties": {
"appIdClaim": {
"description": "AppIDClaim is the name of the claim holding the identifier of the application.\nThis field is sometimes named `client_id`.",
"type": "string"
},
"clientConfig": {
"description": "ClientConfig configures the HTTP client used to fetch the JWKS from the JWKS URL or the trusted issuers.",
"properties": {
"maxRetries": {
"default": 3,
"description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
"type": "integer"
},
"timeoutSeconds": {
"default": 5,
"description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
"type": "integer"
},
"tls": {
"description": "TLS configures TLS for the HTTP client.",
"properties": {
"ca": {
"description": "CA sets the CA bundle used to verify the server certificate.",
"type": "string"
},
"insecureSkipVerify": {
"description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"forwardHeaders": {
"additionalProperties": {
"type": "string"
},
"description": "ForwardHeaders specifies additional headers to forward with the request.",
"type": "object"
},
"jwksFile": {
"description": "JWKSFile contains the JWKS file content for JWT verification.\nMutually exclusive with SigningSecretName, PublicKey, JWKSURL, and TrustedIssuers.",
"type": "string"
},
"jwksUrl": {
"description": "JWKSURL is the URL to fetch the JWKS for JWT verification.\nMutually exclusive with SigningSecretName, PublicKey, JWKSFile, and TrustedIssuers.\n\nDeprecated: Use TrustedIssuers instead for more flexible JWKS configuration with issuer validation.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid HTTPS URL",
"rule": "isURL(self) && self.startsWith('https://')"
}
]
},
"publicKey": {
"description": "PublicKey is the PEM-encoded public key for JWT verification.\nMutually exclusive with SigningSecretName, JWKSFile, JWKSURL, and TrustedIssuers.",
"type": "string"
},
"signingSecretName": {
"description": "SigningSecretName is the name of the Kubernetes Secret containing the signing secret.\nThe secret must be of type Opaque and contain a key named 'value'.\nMutually exclusive with PublicKey, JWKSFile, JWKSURL, and TrustedIssuers.",
"maxLength": 253,
"type": "string"
},
"stripAuthorizationHeader": {
"description": "StripAuthorizationHeader determines whether to strip the Authorization header before forwarding the request.",
"type": "boolean"
},
"tokenNameClaim": {
"description": "TokenNameClaim is the name of the claim holding the name of the token.\nThis name, if provided, will be used in the metrics.",
"type": "string"
},
"tokenQueryKey": {
"description": "TokenQueryKey specifies the query parameter name for the JWT token.",
"type": "string"
},
"trustedIssuers": {
"description": "TrustedIssuers defines multiple JWKS providers with optional issuer validation.\nMutually exclusive with SigningSecretName, PublicKey, JWKSFile, and JWKSURL.",
"items": {
"description": "TrustedIssuer represents a trusted JWT issuer with its associated JWKS endpoint for token verification.",
"properties": {
"issuer": {
"description": "Issuer is the expected value of the \"iss\" claim.\nIf specified, tokens must have this exact issuer to be validated against this JWKS.\nThe issuer value must match exactly, including trailing slashes and URL encoding.\nIf omitted, this JWKS acts as a fallback for any issuer.",
"type": "string"
},
"jwksUrl": {
"description": "JWKSURL is the URL to fetch the JWKS from.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid HTTPS URL",
"rule": "isURL(self) && self.startsWith('https://')"
}
]
}
},
"required": [
"jwksUrl"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"minItems": 1,
"type": "array"
}
},
"required": [
"appIdClaim"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of signingSecretName, publicKey, jwksFile, jwksUrl, or trustedIssuers must be specified",
"rule": "[has(self.signingSecretName), has(self.publicKey), has(self.jwksFile), has(self.jwksUrl), has(self.trustedIssuers)].filter(x, x).size() == 1"
},
{
"message": "trustedIssuers must not be empty when specified",
"rule": "!has(self.trustedIssuers) || size(self.trustedIssuers) > 0"
},
{
"message": "only one entry in trustedIssuers may omit the issuer field",
"rule": "!has(self.trustedIssuers) || self.trustedIssuers.filter(x, !has(x.issuer) || x.issuer == \"\").size() <= 1"
}
],
"additionalProperties": false
},
"ldap": {
"description": "LDAP configures LDAP authentication.",
"properties": {
"attribute": {
"default": "cn",
"description": "Attribute is the LDAP object attribute used to form a bind DN when sending bind queries.\nThe bind DN is formed as <Attribute>=<Username>,<BaseDN>.",
"type": "string"
},
"baseDn": {
"description": "BaseDN is the base domain name that should be used for bind and search queries.",
"type": "string"
},
"bindDn": {
"description": "BindDN is the domain name to bind to in order to authenticate to the LDAP server when running in search mode.\nIf empty, an anonymous bind will be done.",
"type": "string"
},
"bindPasswordSecretName": {
"description": "BindPasswordSecretName is the name of the Kubernetes Secret containing the password for the bind DN.\nThe secret must contain a key named 'password'.",
"maxLength": 253,
"type": "string"
},
"certificateAuthority": {
"description": "CertificateAuthority is a PEM-encoded certificate to use to establish a connection with the LDAP server if the\nconnection uses TLS but that the certificate was signed by a custom Certificate Authority.",
"type": "string"
},
"insecureSkipVerify": {
"description": "InsecureSkipVerify controls whether the server's certificate chain and host name is verified.",
"type": "boolean"
},
"searchFilter": {
"description": "SearchFilter is used to filter LDAP search queries.\nExample: (&(objectClass=inetOrgPerson)(gidNumber=500)(uid=%s))\n%s can be used as a placeholder for the username.",
"type": "string"
},
"startTls": {
"description": "StartTLS instructs the middleware to issue a StartTLS request when initializing the connection with the LDAP server.",
"type": "boolean"
},
"url": {
"description": "URL is the URL of the LDAP server, including the protocol (ldap or ldaps) and the port.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid LDAP URL",
"rule": "isURL(self) && (self.startsWith('ldap://') || self.startsWith('ldaps://'))"
}
]
}
},
"required": [
"baseDn",
"url"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"isDefault"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one authentication method must be specified",
"rule": "[has(self.apiKey), has(self.jwt), has(self.ldap)].filter(x, x).size() == 1"
}
],
"additionalProperties": false
},
"status": {
"description": "The current status of this APIAuth.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APIAuth.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,212 @@
{
"description": "APIBundle defines a set of APIs.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIBundle.",
"properties": {
"apiSelector": {
"description": "APISelector selects the APIs that will be accessible to the configured audience.\nMultiple APIBundles can select the same set of APIs.\nThis field is optional and follows standard label selector semantics.\nAn empty APISelector matches any API.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"apis": {
"description": "APIs defines a set of APIs that will be accessible to the configured audience.\nMultiple APIBundles can select the same APIs.\nWhen combined with APISelector, this set of APIs is appended to the matching APIs.",
"items": {
"description": "APIReference references an API.",
"properties": {
"name": {
"description": "Name of the API.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated apis",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"title": {
"description": "Title is the human-readable name of the APIBundle that will be used on the portal.",
"maxLength": 253,
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this APIBundle.",
"properties": {
"conditions": {
"description": "Conditions is the list of status conditions.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APIBundle.",
"type": "string"
},
"resolvedApis": {
"description": "ResolvedAPIs is the list of APIs that were successfully resolved.",
"items": {
"description": "ResolvedAPIReference references a resolved API.",
"properties": {
"name": {
"description": "Name of the API.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"unresolvedApis": {
"description": "UnresolvedAPIs is the list of APIs that could not be resolved.",
"items": {
"description": "ResolvedAPIReference references a resolved API.",
"properties": {
"name": {
"description": "Name of the API.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,284 @@
{
"description": "APICatalogItem defines APIs that will be part of the API catalog on the portal.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APICatalogItem.",
"properties": {
"apiBundles": {
"description": "APIBundles defines a set of APIBundle that will be visible to the configured audience.\nMultiple APICatalogItem can select the same APIBundles.",
"items": {
"description": "APIBundleReference references an APIBundle.",
"properties": {
"name": {
"description": "Name of the APIBundle.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated apiBundles",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"apiPlan": {
"description": "APIPlan defines which APIPlan will be available.\nIf multiple APICatalogItem specify the same API with different APIPlan, the API consumer will be able to pick\na plan from this list.",
"properties": {
"name": {
"description": "Name of the APIPlan.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"apiSelector": {
"description": "APISelector selects the APIs that will be visible to the configured audience.\nMultiple APICatalogItem can select the same set of APIs.\nThis field is optional and follows standard label selector semantics.\nAn empty APISelector matches any API.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"apis": {
"description": "APIs defines a set of APIs that will be visible to the configured audience.\nMultiple APICatalogItem can select the same APIs.\nWhen combined with APISelector, this set of APIs is appended to the matching APIs.",
"items": {
"description": "APIReference references an API.",
"properties": {
"name": {
"description": "Name of the API.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated apis",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"everyone": {
"description": "Everyone indicates that all users will see these APIs.",
"type": "boolean"
},
"groups": {
"description": "Groups are the consumer groups that will see the APIs.",
"items": {
"type": "string"
},
"type": "array"
},
"operationFilter": {
"description": "OperationFilter specifies the visible operations on APIs and APIVersions.\nIf not set, all operations are available.\nAn empty OperationFilter prohibits all operations.",
"properties": {
"include": {
"description": "Include defines the names of OperationSets that will be accessible.",
"items": {
"type": "string"
},
"maxItems": 100,
"type": "array"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "groups and everyone are mutually exclusive",
"rule": "(has(self.everyone) && has(self.groups)) ? !(self.everyone && self.groups.size() > 0) : true"
},
{
"message": "groups is required when everyone is false",
"rule": "(has(self.everyone) && self.everyone) || (has(self.groups) && self.groups.size() > 0)"
}
],
"additionalProperties": false
},
"status": {
"description": "The current status of this APICatalogItem.",
"properties": {
"conditions": {
"description": "Conditions is the list of status conditions.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APICatalogItem.",
"type": "string"
},
"resolvedApis": {
"description": "ResolvedAPIs is the list of APIs that were successfully resolved.",
"items": {
"description": "ResolvedAPIReference references a resolved API.",
"properties": {
"name": {
"description": "Name of the API.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"unresolvedApis": {
"description": "UnresolvedAPIs is the list of APIs that could not be resolved.",
"items": {
"description": "ResolvedAPIReference references a resolved API.",
"properties": {
"name": {
"description": "Name of the API.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,190 @@
{
"description": "APIPlan defines API Plan policy.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIPlan.",
"properties": {
"description": {
"description": "Description describes the plan.",
"type": "string"
},
"quota": {
"description": "Quota defines the quota policy.",
"properties": {
"bucket": {
"default": "subscription",
"description": "Bucket defines the bucket strategy for the quota.",
"enum": [
"subscription",
"application-api",
"application"
],
"type": "string"
},
"limit": {
"description": "Limit is the maximum number of requests per sliding Period.",
"type": "integer",
"x-kubernetes-validations": [
{
"message": "must be a positive number",
"rule": "self >= 0"
}
]
},
"period": {
"description": "Period is the unit of time for the Limit.",
"format": "duration",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be between 1s and 9999h",
"rule": "self >= duration('1s') && self <= duration('9999h')"
}
]
}
},
"required": [
"limit"
],
"type": "object",
"additionalProperties": false
},
"rateLimit": {
"description": "RateLimit defines the rate limit policy.",
"properties": {
"bucket": {
"default": "subscription",
"description": "Bucket defines the bucket strategy for the rate limit.",
"enum": [
"subscription",
"application-api",
"application"
],
"type": "string"
},
"limit": {
"description": "Limit is the number of requests per Period used to calculate the regeneration rate.\nTraffic will converge to this rate over time by delaying requests when possible, and dropping them when throttling alone is not enough.",
"type": "integer",
"x-kubernetes-validations": [
{
"message": "must be a positive number",
"rule": "self >= 0"
}
]
},
"period": {
"description": "Period is the time unit used to express the rate.\nCombined with Limit, it defines the rate at which request capacity regenerates (Limit \u00f7 Period).",
"format": "duration",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be between 1s and 1h",
"rule": "self >= duration('1s') && self <= duration('1h')"
}
]
}
},
"required": [
"limit"
],
"type": "object",
"additionalProperties": false
},
"title": {
"description": "Title is the human-readable name of the plan.",
"type": "string"
}
},
"required": [
"title"
],
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this APIPlan.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APIPlan.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,207 @@
{
"description": "APIPortal defines a developer portal for accessing the documentation of APIs.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIPortal.",
"properties": {
"auth": {
"description": "Auth references the APIPortalAuth resource for authentication configuration.",
"properties": {
"name": {
"description": "Name is the name of the APIPortalAuth resource.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"description": {
"description": "Description of the APIPortal.",
"type": "string"
},
"title": {
"description": "Title is the public facing name of the APIPortal.",
"type": "string"
},
"trustedUrls": {
"description": "TrustedURLs are the urls that are trusted by the OAuth 2.0 authorization server.",
"items": {
"type": "string"
},
"maxItems": 1,
"minItems": 1,
"type": "array",
"x-kubernetes-validations": [
{
"message": "must be a valid URLs",
"rule": "self.all(x, isURL(x))"
}
]
},
"ui": {
"description": "UI holds the UI customization options.",
"properties": {
"logoUrl": {
"description": "LogoURL is the public URL of the logo.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"trustedUrls"
],
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this APIPortal.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APIPortal.",
"type": "string"
},
"oidc": {
"description": "OIDC is the OIDC configuration for accessing the exposed APIPortal WebUI.",
"properties": {
"clientId": {
"description": "ClientID is the OIDC ClientID for accessing the exposed APIPortal WebUI.",
"type": "string"
},
"companyClaim": {
"description": "CompanyClaim is the name of the JWT claim containing the user company.",
"type": "string"
},
"emailClaim": {
"description": "EmailClaim is the name of the JWT claim containing the user email.",
"type": "string"
},
"firstnameClaim": {
"description": "FirstnameClaim is the name of the JWT claim containing the user firstname.",
"type": "string"
},
"generic": {
"description": "Generic indicates whether or not the APIPortal authentication relies on Generic OIDC.",
"type": "boolean"
},
"groupsClaim": {
"description": "GroupsClaim is the name of the JWT claim containing the user groups.",
"type": "string"
},
"issuer": {
"description": "Issuer is the OIDC issuer for accessing the exposed APIPortal WebUI.",
"type": "string"
},
"lastnameClaim": {
"description": "LastnameClaim is the name of the JWT claim containing the user lastname.",
"type": "string"
},
"scopes": {
"description": "Scopes is the OIDC scopes for getting user attributes during the authentication to the exposed APIPortal WebUI.",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the secret containing the OIDC ClientSecret for accessing the exposed APIPortal WebUI.",
"type": "string"
},
"syncedAttributes": {
"description": "SyncedAttributes configure the user attributes to sync.",
"items": {
"type": "string"
},
"type": "array"
},
"userIdClaim": {
"description": "UserIDClaim is the name of the JWT claim containing the user ID.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,329 @@
{
"description": "APIPortalAuth defines the authentication configuration for an APIPortal.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIPortalAuth.",
"properties": {
"ldap": {
"description": "LDAP configures the LDAP authentication.",
"properties": {
"attribute": {
"default": "cn",
"description": "Attribute is the LDAP object attribute used to form a bind DN when sending bind queries.\nThe bind DN is formed as <Attribute>=<Username>,<BaseDN>.",
"type": "string"
},
"attributes": {
"description": "Attributes configures LDAP attribute mappings for user attributes.",
"properties": {
"company": {
"description": "Company is the LDAP attribute for user company.",
"type": "string"
},
"email": {
"description": "Email is the LDAP attribute for user email.",
"type": "string"
},
"firstname": {
"description": "Firstname is the LDAP attribute for user first name.",
"type": "string"
},
"lastname": {
"description": "Lastname is the LDAP attribute for user last name.",
"type": "string"
},
"userId": {
"description": "UserID is the LDAP attribute for user ID mapping.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"baseDn": {
"description": "BaseDN is the base domain name that should be used for bind and search queries.",
"type": "string"
},
"bindDn": {
"description": "BindDN is the domain name to bind to in order to authenticate to the LDAP server when running in search mode.\nIf empty, an anonymous bind will be done.",
"type": "string"
},
"bindPasswordSecretName": {
"description": "BindPasswordSecretName is the name of the Kubernetes Secret containing the password for the bind DN.\nThe secret must contain a key named 'password'.",
"maxLength": 253,
"type": "string"
},
"certificateAuthority": {
"description": "CertificateAuthority is a PEM-encoded certificate to use to establish a connection with the LDAP server if the\nconnection uses TLS but that the certificate was signed by a custom Certificate Authority.",
"type": "string"
},
"groups": {
"description": "Groups configures group extraction.",
"properties": {
"memberOfAttribute": {
"default": "memberOf",
"description": "MemberOfAttribute is the LDAP attribute containing group memberships (e.g., \"memberOf\").",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"insecureSkipVerify": {
"description": "InsecureSkipVerify controls whether the server's certificate chain and host name is verified.",
"type": "boolean"
},
"searchFilter": {
"description": "SearchFilter is used to filter LDAP search queries.\nExample: (&(objectClass=inetOrgPerson)(gidNumber=500)(uid=%s))\n%s can be used as a placeholder for the username.",
"type": "string"
},
"startTls": {
"description": "StartTLS instructs the middleware to issue a StartTLS request when initializing the connection with the LDAP server.",
"type": "boolean"
},
"syncedAttributes": {
"description": "SyncedAttributes are the user attributes to synchronize with Hub platform.",
"items": {
"enum": [
"groups",
"userId",
"firstname",
"lastname",
"email",
"company"
],
"type": "string"
},
"maxItems": 6,
"type": "array"
},
"url": {
"description": "URL is the URL of the LDAP server, including the protocol (ldap or ldaps) and the port.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid LDAP URL",
"rule": "isURL(self) && (self.startsWith('ldap://') || self.startsWith('ldaps://'))"
}
]
}
},
"required": [
"baseDn",
"url"
],
"type": "object",
"additionalProperties": false
},
"oidc": {
"description": "OIDC configures the OIDC authentication.",
"properties": {
"claims": {
"description": "Claims configures JWT claim mappings for user attributes.",
"properties": {
"company": {
"description": "Company is the JWT claim for user company.",
"type": "string"
},
"email": {
"description": "Email is the JWT claim for user email.",
"type": "string"
},
"firstname": {
"description": "Firstname is the JWT claim for user first name.",
"type": "string"
},
"groups": {
"description": "Groups is the JWT claim for user groups. This field is required for authorization.",
"type": "string"
},
"lastname": {
"description": "Lastname is the JWT claim for user last name.",
"type": "string"
},
"userId": {
"description": "UserID is the JWT claim for user ID mapping.",
"type": "string"
}
},
"required": [
"groups"
],
"type": "object",
"additionalProperties": false
},
"clientConfig": {
"description": "ClientConfig configures the HTTP client used to communicate with the OIDC provider.",
"properties": {
"maxRetries": {
"default": 3,
"description": "MaxRetries defines the maximum number of retry attempts for failed requests.",
"type": "integer"
},
"timeoutSeconds": {
"default": 5,
"description": "TimeoutSeconds configures the maximum amount of seconds to wait before giving up on requests.",
"type": "integer"
},
"tls": {
"description": "TLS configures TLS for the HTTP client.",
"properties": {
"ca": {
"description": "CA sets the CA bundle used to verify the server certificate.",
"type": "string"
},
"insecureSkipVerify": {
"description": "InsecureSkipVerify skips the server certificate validation.\nFor testing purposes only, do not use in production.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"issuerUrl": {
"description": "IssuerURL is the OIDC provider issuer URL.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid URL",
"rule": "isURL(self)"
}
]
},
"scopes": {
"description": "Scopes is a list of OAuth2 scopes.",
"items": {
"type": "string"
},
"type": "array"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret containing clientId and clientSecret keys.",
"maxLength": 253,
"type": "string"
},
"syncedAttributes": {
"description": "SyncedAttributes are the user attributes to synchronize with Hub platform.",
"items": {
"enum": [
"groups",
"userId",
"firstname",
"lastname",
"email",
"company"
],
"type": "string"
},
"maxItems": 6,
"type": "array"
}
},
"required": [
"claims",
"issuerUrl",
"secretName"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of oidc or ldap must be specified",
"rule": "[has(self.oidc), has(self.ldap)].filter(x, x).size() == 1"
}
],
"additionalProperties": false
},
"status": {
"description": "The current status of this APIPortalAuth.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APIPortalAuth.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,164 @@
{
"description": "APIRateLimit defines how group of consumers are rate limited on a set of APIs.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIRateLimit.",
"properties": {
"apiSelector": {
"description": "APISelector selects the APIs that will be rate limited.\nMultiple APIRateLimits can select the same set of APIs.\nThis field is optional and follows standard label selector semantics.\nAn empty APISelector matches any API.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"apis": {
"description": "APIs defines a set of APIs that will be rate limited.\nMultiple APIRateLimits can select the same APIs.\nWhen combined with APISelector, this set of APIs is appended to the matching APIs.",
"items": {
"description": "APIReference references an API.",
"properties": {
"name": {
"description": "Name of the API.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated apis",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"everyone": {
"description": "Everyone indicates that all users will, by default, be rate limited with this configuration.\nIf an APIRateLimit explicitly target a group, the default rate limit will be ignored.",
"type": "boolean"
},
"groups": {
"description": "Groups are the consumer groups that will be rate limited.\nMultiple APIRateLimits can target the same set of consumer groups, the most restrictive one applies.\nWhen a consumer belongs to multiple groups, the least restrictive APIRateLimit applies.",
"items": {
"type": "string"
},
"type": "array"
},
"limit": {
"description": "Limit is the maximum number of token in the bucket.",
"type": "integer",
"x-kubernetes-validations": [
{
"message": "must be a positive number",
"rule": "self >= 0"
}
]
},
"period": {
"description": "Period is the unit of time for the Limit.",
"format": "duration",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be between 1s and 1h",
"rule": "self >= duration('1s') && self <= duration('1h')"
}
]
},
"strategy": {
"description": "Strategy defines how the bucket state will be synchronized between the different Traefik Hub instances.\nIt can be, either \"local\" or \"distributed\".",
"enum": [
"local",
"distributed"
],
"type": "string"
}
},
"required": [
"limit"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "groups and everyone are mutually exclusive",
"rule": "(has(self.everyone) && has(self.groups)) ? !(self.everyone && self.groups.size() > 0) : true"
}
],
"additionalProperties": false
},
"status": {
"description": "The current status of this APIRateLimit.",
"properties": {
"hash": {
"description": "Hash is a hash representing the APIRateLimit.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,341 @@
{
"description": "APIVersion defines a version of an API.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this APIVersion.",
"properties": {
"cors": {
"description": "Cors defines the Cross-Origin Resource Sharing configuration.",
"properties": {
"addVaryHeader": {
"description": "AddVaryHeader defines whether the Vary header is automatically added/updated when the AllowOriginsList is set.",
"type": "boolean"
},
"allowCredentials": {
"description": "AllowCredentials defines whether the request can include user credentials.",
"type": "boolean"
},
"allowHeadersList": {
"description": "AllowHeadersList defines the Access-Control-Request-Headers values sent in preflight response.",
"items": {
"type": "string"
},
"type": "array"
},
"allowMethodsList": {
"description": "AllowMethodsList defines the Access-Control-Request-Method values sent in preflight response.",
"items": {
"type": "string"
},
"type": "array"
},
"allowOriginListRegex": {
"description": "AllowOriginListRegex is a list of allowable origins written following the Regular Expression syntax (https://golang.org/pkg/regexp/).",
"items": {
"type": "string"
},
"type": "array"
},
"allowOriginsList": {
"description": "AllowOriginsList is a list of allowable origins. Can also be a wildcard origin \"*\".",
"items": {
"type": "string"
},
"type": "array"
},
"exposeHeadersList": {
"description": "ExposeHeadersList defines the Access-Control-Expose-Headers values sent in preflight response.",
"items": {
"type": "string"
},
"type": "array"
},
"maxAge": {
"description": "MaxAge defines the time that a preflight request may be cached.",
"format": "int64",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"description": {
"description": "Description explains what the APIVersion does.",
"type": "string"
},
"openApiSpec": {
"description": "OpenAPISpec defines the API contract as an OpenAPI specification.",
"properties": {
"operationSets": {
"description": "OperationSets defines the sets of operations to be referenced for granular filtering in APICatalogItems or ManagedSubscriptions.",
"items": {
"description": "OperationSet gives a name to a set of matching OpenAPI operations.\nThis set of operations can then be referenced for granular filtering in APICatalogItems or ManagedSubscriptions.",
"properties": {
"matchers": {
"description": "Matchers defines a list of alternative rules for matching OpenAPI operations.",
"items": {
"description": "OperationMatcher defines criteria for matching an OpenAPI operation.",
"minProperties": 1,
"properties": {
"methods": {
"description": "Methods specifies the HTTP methods to be included for selection.",
"items": {
"type": "string"
},
"maxItems": 10,
"type": "array"
},
"path": {
"description": "Path specifies the exact path of the operations to select.",
"maxLength": 255,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must start with a '/'",
"rule": "self.startsWith('/')"
},
{
"message": "cannot contains '../'",
"rule": "!self.matches(r\"\"\"(\\/\\.\\.\\/)|(\\/\\.\\.$)\"\"\")"
}
]
},
"pathPrefix": {
"description": "PathPrefix specifies the path prefix of the operations to select.",
"maxLength": 255,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must start with a '/'",
"rule": "self.startsWith('/')"
},
{
"message": "cannot contains '../'",
"rule": "!self.matches(r\"\"\"(\\/\\.\\.\\/)|(\\/\\.\\.$)\"\"\")"
}
]
},
"pathRegex": {
"description": "PathRegex specifies a regular expression pattern for matching operations based on their paths.",
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "path, pathPrefix and pathRegex are mutually exclusive",
"rule": "[has(self.path), has(self.pathPrefix), has(self.pathRegex)].filter(x, x).size() <= 1"
}
],
"additionalProperties": false
},
"maxItems": 100,
"minItems": 1,
"type": "array"
},
"name": {
"description": "Name is the name of the OperationSet to reference in APICatalogItems or ManagedSubscriptions.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"matchers",
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array"
},
"override": {
"description": "Override holds data used to override OpenAPI specification.",
"properties": {
"servers": {
"items": {
"properties": {
"url": {
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid URL",
"rule": "isURL(self)"
}
]
}
},
"required": [
"url"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"minItems": 1,
"type": "array"
}
},
"required": [
"servers"
],
"type": "object",
"additionalProperties": false
},
"path": {
"description": "Path specifies the endpoint path within the Kubernetes Service where the OpenAPI specification can be obtained.\nThe Service queried is determined by the associated Ingress, IngressRoute, or HTTPRoute resource to which the API is attached.\nIt's important to note that this option is incompatible if the Ingress or IngressRoute specifies multiple backend services.\nThe Path must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"maxLength": 255,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must start with a '/'",
"rule": "self.startsWith('/')"
},
{
"message": "cannot contains '../'",
"rule": "!self.matches(r\"\"\"(\\/\\.\\.\\/)|(\\/\\.\\.$)\"\"\")"
}
]
},
"refreshInterval": {
"description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
"format": "duration",
"type": "string"
},
"url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid URL",
"rule": "isURL(self)"
}
]
},
"validateRequestBodySchema": {
"description": "ValidateRequestBodySchema validates the request body against the OpenAPI specification.\nThis option overrides the default behavior configured in the static configuration.",
"type": "boolean"
},
"validateRequestMethodAndPath": {
"description": "ValidateRequestMethodAndPath validates that the path and method matches an operation defined in the OpenAPI specification.\nThis option overrides the default behavior configured in the static configuration.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "path or url must be defined",
"rule": "has(self.path) || has(self.url)"
}
],
"additionalProperties": false
},
"release": {
"description": "Release is the version number of the API.\nThis value must follow the SemVer format: https://semver.org/",
"maxLength": 100,
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid semver version",
"rule": "self.matches(r\"\"\"^v?(0|[1-9]\\d*)\\.(0|[1-9]\\d*)\\.(0|[1-9]\\d*)(?:-((?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\\.(?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\\+([0-9a-zA-Z-]+(?:\\.[0-9a-zA-Z-]+)*))?$\"\"\")"
}
]
},
"title": {
"description": "Title is the public facing name of the APIVersion.",
"type": "string"
}
},
"required": [
"release"
],
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this APIVersion.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the APIVersion.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,170 @@
{
"description": "ContentItem defines additional documentation for given resource.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "Defines the documentation to attach to the referenced resource.",
"properties": {
"content": {
"description": "Content is the valid markdown content.",
"maxLength": 1500000,
"type": "string"
},
"link": {
"description": "Link is the link to the content.",
"properties": {
"href": {
"description": "Href is the public URL of the content.",
"type": "string",
"x-kubernetes-validations": [
{
"message": "must be a valid URL",
"rule": "isURL(self)"
}
]
}
},
"required": [
"href"
],
"type": "object",
"additionalProperties": false
},
"order": {
"description": "Order defines the order of the content in the UI.",
"format": "int32",
"minimum": 0,
"type": "integer"
},
"parentRef": {
"description": "ParentRef is the reference to the resource that this content belongs to.",
"properties": {
"kind": {
"description": "Kind is the kind of the resource that this content belongs to.",
"enum": [
"APIPortal",
"API",
"APIBundle"
],
"type": "string"
},
"name": {
"description": "Name is the name of the resource that this content belongs to.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"kind",
"name"
],
"type": "object",
"additionalProperties": false
},
"title": {
"description": "Title is the public-facing name of the ContentItem.",
"maxLength": 253,
"minLength": 1,
"type": "string"
}
},
"required": [
"order",
"parentRef",
"title"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of content or link must be specified",
"rule": "[has(self.content), has(self.link)].filter(x, x).size() == 1"
}
],
"additionalProperties": false
},
"status": {
"description": "The current status of this ContentItem.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the ContentItem.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,155 @@
{
"description": "ManagedApplication represents a managed application.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "ManagedApplicationSpec describes the ManagedApplication.",
"properties": {
"apiKeys": {
"description": "APIKeys references the API keys used to authenticate the application when calling APIs.",
"items": {
"description": "APIKey describes an API key used to authenticate the application when calling APIs.",
"properties": {
"secretName": {
"description": "SecretName references the name of the secret containing the API key.",
"maxLength": 253,
"type": "string"
},
"suspended": {
"type": "boolean"
},
"title": {
"type": "string"
},
"value": {
"description": "Value is the API key value.",
"maxLength": 4096,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "secretName and value are mutually exclusive",
"rule": "[has(self.secretName), has(self.value)].filter(x, x).size() <= 1"
}
],
"additionalProperties": false
},
"maxItems": 100,
"type": "array"
},
"appId": {
"description": "AppID is the identifier of the ManagedApplication.\nIt should be unique.",
"maxLength": 253,
"type": "string"
},
"notes": {
"description": "Notes contains notes about application.",
"type": "string"
},
"owner": {
"description": "Owner represents the owner of the ManagedApplication.\nIt should be:\n- `sub` when using OIDC\n- `externalID` when using external IDP",
"maxLength": 253,
"type": "string"
}
},
"required": [
"appId",
"owner"
],
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this ManagedApplication.",
"properties": {
"apiKeyVersions": {
"additionalProperties": {
"type": "string"
},
"type": "object"
},
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the ManagedApplication.",
"type": "string"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,326 @@
{
"description": "ManagedSubscription defines a Subscription managed by the API manager as the result of a pre-negotiation with its\nAPI consumers. This subscription grant consuming access to a set of APIs to a set of Applications.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "The desired behavior of this ManagedSubscription.",
"properties": {
"apiBundles": {
"description": "APIBundles defines a set of APIBundle that will be accessible.\nMultiple ManagedSubscriptions can select the same APIBundles.",
"items": {
"description": "APIBundleReference references an APIBundle.",
"properties": {
"name": {
"description": "Name of the APIBundle.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated apiBundles",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"apiPlan": {
"description": "APIPlan defines which APIPlan will be used.",
"properties": {
"name": {
"description": "Name of the APIPlan.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"apiSelector": {
"description": "APISelector selects the APIs that will be accessible.\nMultiple ManagedSubscriptions can select the same set of APIs.\nThis field is optional and follows standard label selector semantics.\nAn empty APISelector matches any API.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"apis": {
"description": "APIs defines a set of APIs that will be accessible.\nMultiple ManagedSubscriptions can select the same APIs.\nWhen combined with APISelector, this set of APIs is appended to the matching APIs.",
"items": {
"description": "APIReference references an API.",
"properties": {
"name": {
"description": "Name of the API.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated apis",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"applications": {
"description": "Applications references the Applications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same AppID.\n\nDeprecated: Use ManagedApplications instead.",
"items": {
"description": "ApplicationReference references an Application.",
"properties": {
"appId": {
"description": "AppID is the public identifier of the application.\nIn the case of OIDC, it corresponds to the clientId.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"appId"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array"
},
"claims": {
"description": "Claims specifies an expression that validate claims in order to authorize the request.",
"type": "string"
},
"managedApplications": {
"description": "ManagedApplications references the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.",
"items": {
"description": "ManagedApplicationReference references a ManagedApplication.",
"properties": {
"name": {
"description": "Name is the name of the ManagedApplication.",
"maxLength": 253,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 100,
"type": "array",
"x-kubernetes-validations": [
{
"message": "duplicated managed applications",
"rule": "self.all(x, self.exists_one(y, x.name == y.name))"
}
]
},
"operationFilter": {
"description": "OperationFilter specifies the allowed operations on APIs and APIVersions.\nIf not set, all operations are available.\nAn empty OperationFilter prohibits all operations.",
"properties": {
"include": {
"description": "Include defines the names of OperationSets that will be accessible.",
"items": {
"type": "string"
},
"maxItems": 100,
"type": "array"
}
},
"type": "object",
"additionalProperties": false
},
"weight": {
"description": "Weight specifies the evaluation order of the APIPlan.\nWhen multiple ManagedSubscriptions targets the same API and Application with different APIPlan,\nthe APIPlan with the highest weight will be enforced. If weights are equal, alphabetical order is used.",
"type": "integer",
"x-kubernetes-validations": [
{
"message": "must be a positive number",
"rule": "self >= 0"
}
]
}
},
"required": [
"apiPlan"
],
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this ManagedSubscription.",
"properties": {
"conditions": {
"description": "Conditions is the list of status conditions.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"hash": {
"description": "Hash is a hash representing the ManagedSubscription.",
"type": "string"
},
"resolvedApis": {
"description": "ResolvedAPIs is the list of APIs that were successfully resolved.",
"items": {
"description": "ResolvedAPIReference references a resolved API.",
"properties": {
"name": {
"description": "Name of the API.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"syncedAt": {
"format": "date-time",
"type": "string"
},
"unresolvedApis": {
"description": "UnresolvedAPIs is the list of APIs that could not be resolved.",
"items": {
"description": "ResolvedAPIReference references a resolved API.",
"properties": {
"name": {
"description": "Name of the API.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"version": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}
@@ -0,0 +1,212 @@
{
"description": "Uplink is an inter-cluster service advertisement: a child cluster declares an Uplink to advertise\nto a parent cluster that it can handle a particular workload.",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "UplinkSpec describes the Uplink.",
"properties": {
"entryPoints": {
"description": "EntryPoints references uplinkEntryPoints. When omitted, uses default uplinkEntrypoints.",
"items": {
"type": "string"
},
"type": "array"
},
"exposeName": {
"description": "ExposeName is the name of the service to expose.\nBy default it uses <namespace>-<name>.",
"type": "string"
},
"healthCheck": {
"description": "HealthCheck configures the active health check on the parent cluster for this uplink's load balancer.",
"properties": {
"followRedirects": {
"description": "FollowRedirects defines whether redirects should be followed during the health check calls.\nDefault: true",
"type": "boolean"
},
"headers": {
"additionalProperties": {
"type": "string"
},
"description": "Headers defines custom headers to be sent to the health check endpoint.",
"type": "object"
},
"hostname": {
"description": "Hostname defines the value of hostname in the Host header of the health check request.",
"type": "string"
},
"interval": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "Interval defines the frequency of the health check calls for healthy targets.\nDefault: 30s",
"x-kubernetes-int-or-string": true
},
"method": {
"description": "Method defines the healthcheck method.",
"type": "string"
},
"mode": {
"description": "Mode defines the health check mode.\nIf defined to grpc, will use the gRPC health check protocol to probe the server.\nDefault: http",
"type": "string"
},
"path": {
"description": "Path defines the server URL path for the health check endpoint.",
"type": "string"
},
"port": {
"description": "Port defines the server URL port for the health check endpoint.",
"type": "integer"
},
"scheme": {
"description": "Scheme replaces the server URL scheme for the health check endpoint.",
"type": "string"
},
"status": {
"description": "Status defines the expected HTTP status code of the response to the health check request.",
"type": "integer"
},
"timeout": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "Timeout defines the maximum duration Traefik will wait for a health check request before considering the server unhealthy.\nDefault: 5s",
"x-kubernetes-int-or-string": true
},
"unhealthyInterval": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "UnhealthyInterval defines the frequency of the health check calls for unhealthy targets.\nWhen UnhealthyInterval is not defined, it defaults to the Interval value.\nDefault: 30s",
"x-kubernetes-int-or-string": true
}
},
"type": "object",
"additionalProperties": false
},
"passiveHealthCheck": {
"description": "PassiveHealthCheck configures the passive health check on the parent cluster for this uplink's load balancer.",
"properties": {
"failureWindow": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "FailureWindow defines the time window during which the failed attempts must occur for the server to be marked as unhealthy. It also defines for how long the server will be considered unhealthy.",
"x-kubernetes-int-or-string": true
},
"maxFailedAttempts": {
"description": "MaxFailedAttempts is the number of consecutive failed attempts allowed within the failure window before marking the server as unhealthy.",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"weight": {
"description": "Weight for WRR on the parent.",
"type": "integer",
"x-kubernetes-validations": [
{
"message": "must be a positive number",
"rule": "self >= 0"
}
]
}
},
"type": "object",
"additionalProperties": false
},
"status": {
"description": "The current status of this Uplink.",
"properties": {
"conditions": {
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}