update crds
This commit is contained in:
@@ -387,9 +387,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"toGroups": {
|
||||
"description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -398,18 +398,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -593,13 +597,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -622,14 +631,6 @@
|
||||
"http"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"kafka": {}
|
||||
},
|
||||
"required": [
|
||||
"kafka"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"dns": {}
|
||||
@@ -637,14 +638,6 @@
|
||||
"required": [
|
||||
"dns"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"l7proto": {}
|
||||
},
|
||||
"required": [
|
||||
"l7proto"
|
||||
]
|
||||
}
|
||||
],
|
||||
"properties": {
|
||||
@@ -770,57 +763,6 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"kafka": {
|
||||
"description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
|
||||
"items": {
|
||||
"description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
|
||||
"properties": {
|
||||
"apiKey": {
|
||||
"description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"apiVersion": {
|
||||
"description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"clientID": {
|
||||
"description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"role": {
|
||||
"description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
|
||||
"enum": [
|
||||
"produce",
|
||||
"consume"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"topic": {
|
||||
"description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
|
||||
"maxLength": 255,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7": {
|
||||
"description": "Key-value pair rules.",
|
||||
"items": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
|
||||
"type": "object"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7proto": {
|
||||
"description": "Name of the L7 protocol for which the Key-value pair rules apply.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
@@ -829,9 +771,9 @@
|
||||
"serverNames": {
|
||||
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
|
||||
"items": {
|
||||
"description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
|
||||
"description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
|
||||
"maxLength": 255,
|
||||
"pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
|
||||
"pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 1,
|
||||
@@ -1248,9 +1190,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"toGroups": {
|
||||
"description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -1259,18 +1201,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -1369,13 +1315,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -1798,9 +1749,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"fromGroups": {
|
||||
"description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -1809,18 +1760,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -2060,13 +2015,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -2089,14 +2049,6 @@
|
||||
"http"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"kafka": {}
|
||||
},
|
||||
"required": [
|
||||
"kafka"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"dns": {}
|
||||
@@ -2104,14 +2056,6 @@
|
||||
"required": [
|
||||
"dns"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"l7proto": {}
|
||||
},
|
||||
"required": [
|
||||
"l7proto"
|
||||
]
|
||||
}
|
||||
],
|
||||
"properties": {
|
||||
@@ -2237,57 +2181,6 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"kafka": {
|
||||
"description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
|
||||
"items": {
|
||||
"description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
|
||||
"properties": {
|
||||
"apiKey": {
|
||||
"description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"apiVersion": {
|
||||
"description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"clientID": {
|
||||
"description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"role": {
|
||||
"description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
|
||||
"enum": [
|
||||
"produce",
|
||||
"consume"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"topic": {
|
||||
"description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
|
||||
"maxLength": 255,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7": {
|
||||
"description": "Key-value pair rules.",
|
||||
"items": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
|
||||
"type": "object"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7proto": {
|
||||
"description": "Name of the L7 protocol for which the Key-value pair rules apply.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
@@ -2296,9 +2189,9 @@
|
||||
"serverNames": {
|
||||
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
|
||||
"items": {
|
||||
"description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
|
||||
"description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
|
||||
"maxLength": 255,
|
||||
"pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
|
||||
"pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 1,
|
||||
@@ -2566,9 +2459,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"fromGroups": {
|
||||
"description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -2577,18 +2470,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -2743,13 +2640,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -2775,13 +2677,13 @@
|
||||
"labels": {
|
||||
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
|
||||
"items": {
|
||||
"description": "Label is the Cilium's representation of a container label.",
|
||||
"description": "Label is Cilium's representation of a label.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"type": "string"
|
||||
},
|
||||
"source": {
|
||||
"description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
|
||||
"description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
|
||||
"type": "string"
|
||||
},
|
||||
"value": {
|
||||
@@ -3246,9 +3148,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"toGroups": {
|
||||
"description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -3257,18 +3159,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -3452,13 +3358,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -3481,14 +3392,6 @@
|
||||
"http"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"kafka": {}
|
||||
},
|
||||
"required": [
|
||||
"kafka"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"dns": {}
|
||||
@@ -3496,14 +3399,6 @@
|
||||
"required": [
|
||||
"dns"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"l7proto": {}
|
||||
},
|
||||
"required": [
|
||||
"l7proto"
|
||||
]
|
||||
}
|
||||
],
|
||||
"properties": {
|
||||
@@ -3629,57 +3524,6 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"kafka": {
|
||||
"description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
|
||||
"items": {
|
||||
"description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
|
||||
"properties": {
|
||||
"apiKey": {
|
||||
"description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"apiVersion": {
|
||||
"description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"clientID": {
|
||||
"description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"role": {
|
||||
"description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
|
||||
"enum": [
|
||||
"produce",
|
||||
"consume"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"topic": {
|
||||
"description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
|
||||
"maxLength": 255,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7": {
|
||||
"description": "Key-value pair rules.",
|
||||
"items": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
|
||||
"type": "object"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7proto": {
|
||||
"description": "Name of the L7 protocol for which the Key-value pair rules apply.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
@@ -3688,9 +3532,9 @@
|
||||
"serverNames": {
|
||||
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
|
||||
"items": {
|
||||
"description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
|
||||
"description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
|
||||
"maxLength": 255,
|
||||
"pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
|
||||
"pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 1,
|
||||
@@ -4107,9 +3951,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"toGroups": {
|
||||
"description": "ToGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "ToGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nToGroups entries are functionally equivalent to toCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\ntoGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -4118,18 +3962,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -4228,13 +4076,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -4657,9 +4510,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"fromGroups": {
|
||||
"description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -4668,18 +4521,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -4919,13 +4776,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -4948,14 +4810,6 @@
|
||||
"http"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"kafka": {}
|
||||
},
|
||||
"required": [
|
||||
"kafka"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"dns": {}
|
||||
@@ -4963,14 +4817,6 @@
|
||||
"required": [
|
||||
"dns"
|
||||
]
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"l7proto": {}
|
||||
},
|
||||
"required": [
|
||||
"l7proto"
|
||||
]
|
||||
}
|
||||
],
|
||||
"properties": {
|
||||
@@ -5096,57 +4942,6 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"kafka": {
|
||||
"description": "Kafka-specific rules.\nDeprecated: This beta feature is deprecated and will be removed in a future release.",
|
||||
"items": {
|
||||
"description": "PortRule is a list of Kafka protocol constraints. All fields are\noptional, if all fields are empty or missing, the rule will match all\nKafka messages.",
|
||||
"properties": {
|
||||
"apiKey": {
|
||||
"description": "APIKey is a case-insensitive string matched against the key of a\nrequest, e.g. \"produce\", \"fetch\", \"createtopic\", \"deletetopic\", et al\nReference: https://kafka.apache.org/protocol#protocol_api_keys\n\nIf omitted or empty, and if Role is not specified, then all keys are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"apiVersion": {
|
||||
"description": "APIVersion is the version matched against the api version of the\nKafka message. If set, it has to be a string representing a positive\ninteger.\n\nIf omitted or empty, all versions are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"clientID": {
|
||||
"description": "ClientID is the client identifier as provided in the request.\n\nFrom Kafka protocol documentation:\nThis is a user supplied identifier for the client application. The\nuser can use any identifier they like and it will be used when\nlogging errors, monitoring aggregates, etc. For example, one might\nwant to monitor not just the requests per second overall, but the\nnumber coming from each client application (each of which could\nreside on multiple servers). This id acts as a logical grouping\nacross all requests from a particular client.\n\nIf omitted or empty, all client identifiers are allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"role": {
|
||||
"description": "Role is a case-insensitive string and describes a group of API keys\nnecessary to perform certain higher-level Kafka operations such as \"produce\"\nor \"consume\". A Role automatically expands into all APIKeys required\nto perform the specified higher-level operation.\n\nThe following values are supported:\n - \"produce\": Allow producing to the topics specified in the rule\n - \"consume\": Allow consuming from the topics specified in the rule\n\nThis field is incompatible with the APIKey field, i.e APIKey and Role\ncannot both be specified in the same rule.\n\nIf omitted or empty, and if APIKey is not specified, then all keys are\nallowed.",
|
||||
"enum": [
|
||||
"produce",
|
||||
"consume"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"topic": {
|
||||
"description": "Topic is the topic name contained in the message. If a Kafka request\ncontains multiple topics, then all topics must be allowed or the\nmessage will be rejected.\n\nThis constraint is ignored if the matched request message type\ndoesn't contain any topic. Maximum size of Topic can be 249\ncharacters as per recent Kafka spec and allowed characters are\na-z, A-Z, 0-9, -, . and _.\n\nOlder Kafka versions had longer topic lengths of 255, but in Kafka 0.10\nversion the length was changed from 255 to 249. For compatibility\nreasons we are using 255.\n\nIf omitted or empty, all topics are allowed.",
|
||||
"maxLength": 255,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7": {
|
||||
"description": "Key-value pair rules.",
|
||||
"items": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "PortRuleL7 is a list of key-value pairs interpreted by a L7 protocol as\nprotocol constraints. All fields are optional, if all fields are empty or\nmissing, the rule does not have any effect.",
|
||||
"type": "object"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"l7proto": {
|
||||
"description": "Name of the L7 protocol for which the Key-value pair rules apply.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
@@ -5155,9 +4950,9 @@
|
||||
"serverNames": {
|
||||
"description": "ServerNames is a list of allowed TLS SNI values. If not empty, then\nTLS must be present and one of the provided SNIs must be indicated in the\nTLS handshake.",
|
||||
"items": {
|
||||
"description": "ServerName allows using prefix only wildcards to match DNS names.\n\n- \"*\" matches 0 or more DNS valid characters, and may only occur at the\nbeginning of the pattern. As a special case a \"*\" as the leftmost character,\nwithout a following \".\" matches all subdomains as well as the name to the right.\n\nExamples:\n - `*.cilium.io` matches exactly one subdomain of cilium at that level www.cilium.io and blog.cilium.io match, cilium.io and google.com do not.\n - `**.cilium.io` matches more than one subdomain of cilium, e.g. sub1.sub2.cilium.io and sub.cilium.io match, cilium.io do not.",
|
||||
"description": "ServerName allows using '*' wildcard specifier for matching server names with\nthe below semantics.\n\n- `*` matches 0 or more DNS valid characters, and may occur anywhere in the pattern.\n- `**.` is a special prefix which matches all multilevel subdomains in the prefix.\n\nAs a special case the name \"*\" matches all valid DNS names.\n\nExamples:\n 1. `*.cilium.io` matches subdomains of cilium at that level\n www.cilium.io and blog.cilium.io match, cilium.io and google.com do not\n 2. `*cilium.io` matches cilium.io and all subdomains ends with \"cilium.io\"\n except those containing \".\" separator, subcilium.io and sub-cilium.io match,\n www.cilium.io and blog.cilium.io does not\n 3. `sub*.cilium.io` matches subdomains of cilium where the subdomain component\n begins with \"sub\". sub.cilium.io and subdomain.cilium.io match while www.cilium.io,\n blog.cilium.io, cilium.io and google.com do not\n 4. `**.cilium.io` matches all multilevel subdomains of cilium.io.\n \"app.cilium.io\" and \"test.app.cilium.io\" match but not \"cilium.io\"",
|
||||
"maxLength": 255,
|
||||
"pattern": "^(\\*?\\*\\.)?([-a-zA-Z0-9_]+\\.?)+$",
|
||||
"pattern": "^([-a-zA-Z0-9_*]+[.]?)+$",
|
||||
"type": "string"
|
||||
},
|
||||
"minItems": 1,
|
||||
@@ -5425,9 +5220,9 @@
|
||||
"type": "array"
|
||||
},
|
||||
"fromGroups": {
|
||||
"description": "FromGroups is a directive that allows the integration with multiple outside\nproviders. Currently, only AWS is supported, and the rule can select by\nmultiple sub directives:\n\nExample:\nFromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"description": "FromGroups allows policies to reference CIDRs provided by external integrations.\nCurrently, only AWS is supported, and the rule can select by multiple sub directives.\nFromGroups entries are functionally equivalent to FromCIDR, and have the same\nlimitiations. They cannot select traffic originating from within the cluster.\n\nExample:\nfromGroups:\n- aws:\n securityGroupsIds:\n - 'sg-XXXXXXXXXXXXX'",
|
||||
"items": {
|
||||
"description": "Groups structure to store all kinds of new integrations that needs a new\nderivative policy.",
|
||||
"description": "Groups allows referencing CIDRs that are resolved from an external integration.",
|
||||
"properties": {
|
||||
"aws": {
|
||||
"description": "AWSGroup is an structure that can be used to whitelisting information from AWS integration",
|
||||
@@ -5436,18 +5231,22 @@
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Labels selects AWS ENIs by labels.\nMultiple labels are AND-ed together.",
|
||||
"type": "object"
|
||||
},
|
||||
"region": {
|
||||
"description": "Deprecated: Region is unused.",
|
||||
"type": "string"
|
||||
},
|
||||
"securityGroupsIds": {
|
||||
"description": "SecurityGroupsIds selects VPC SecurityGroups by IDs.\nIf multiple IDs are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any Names specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"securityGroupsNames": {
|
||||
"description": "SecurityGroupsNames selects VPC SecurityGroups by name.\nIf multiple names are specified, they are OR-ed together.\n\nNote that this may be AND-ed with any IDs specified. Specifying both\nIDs and Names is not recommended.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
@@ -5602,13 +5401,18 @@
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"ANY\"\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"description": "Protocol is the L4 protocol. If \"ANY\", omitted or empty, any protocols\nwith transport ports (TCP, UDP, SCTP) match.\n\nAccepted values: \"TCP\", \"UDP\", \"SCTP\", \"VRRP\", \"IGMP\", \"GRE\", \"IPIP\",\n\"IPV6\", \"ESP\", \"AH\", \"ANY\"\n\nTunnel/encapsulation protocols (GRE, IPIP, IPV6, ESP, AH) and other\nextended IP protocols (VRRP, IGMP) require the --enable-extended-ip-protocols\nflag to be set. These protocols do not use transport-layer ports.\n\nMatching on ICMP is not supported.\n\nNamed port specified for a container may narrow this down, but may not\ncontradict this.",
|
||||
"enum": [
|
||||
"TCP",
|
||||
"UDP",
|
||||
"SCTP",
|
||||
"VRRP",
|
||||
"IGMP",
|
||||
"GRE",
|
||||
"IPIP",
|
||||
"IPV6",
|
||||
"ESP",
|
||||
"AH",
|
||||
"ANY"
|
||||
],
|
||||
"type": "string"
|
||||
@@ -5634,13 +5438,13 @@
|
||||
"labels": {
|
||||
"description": "Labels is a list of optional strings which can be used to\nre-identify the rule or to store metadata. It is possible to lookup\nor delete strings based on labels. Labels are not required to be\nunique, multiple rules can have overlapping or identical labels.",
|
||||
"items": {
|
||||
"description": "Label is the Cilium's representation of a container label.",
|
||||
"description": "Label is Cilium's representation of a label.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"type": "string"
|
||||
},
|
||||
"source": {
|
||||
"description": "Source can be one of the above values (e.g.: LabelSourceContainer).",
|
||||
"description": "Source can be one of the above values (e.g.: LabelSourceK8s).",
|
||||
"type": "string"
|
||||
},
|
||||
"value": {
|
||||
@@ -5819,5 +5623,11 @@
|
||||
"required": [
|
||||
"metadata"
|
||||
],
|
||||
"type": "object"
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "spec or specs must be provided",
|
||||
"rule": "has(self.spec) || has(self.specs)"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user