update crds
This commit is contained in:
@@ -0,0 +1,744 @@
|
||||
{
|
||||
"description": "Pomerium define runtime-configurable Pomerium settings\nthat do not fall into the category of deployment parameters",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "PomeriumSpec defines Pomerium-specific configuration parameters.",
|
||||
"properties": {
|
||||
"accessLogFields": {
|
||||
"description": "AccessLogFields sets the <a href=\"https://www.pomerium.com/docs/reference/access-log-fields\">access fields</a> to log.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"allowUpgrades": {
|
||||
"description": "AllowUpgrades sets the allowed upgrade types.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"authenticate": {
|
||||
"description": "Authenticate sets authenticate service parameters.\nIf not specified, a Pomerium-hosted authenticate service would be used.",
|
||||
"properties": {
|
||||
"url": {
|
||||
"description": "AuthenticateURL is a dedicated domain URL\nthe non-authenticated persons would be referred to.\n\n<p><ul>\n <li>You do not need to create a dedicated <code>Ingress</code> for this\n\t\tvirtual route, as it is handled by Pomerium internally. </li>\n\t<li>You do need create a secret with corresponding TLS certificate for this route\n\t\tand reference it via <a href=\"#prop-certificates\"><code>certificates</code></a>.\n\t\tIf you use <code>cert-manager</code> with <code>HTTP01</code> challenge,\n\t\tyou may use <code>pomerium</code> <code>ingressClass</code> to solve it.</li>\n</ul></p>",
|
||||
"format": "uri",
|
||||
"pattern": "^https://",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"url"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"authorizeLogFields": {
|
||||
"description": "AuthorizeLogFields sets the <a href=\"https://www.pomerium.com/docs/reference/authorize-log-fields\">authorize fields</a> to log.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"bearerTokenFormat": {
|
||||
"description": "BearerTokenFormat sets the <a href=\"https://www.pomerium.com/docs/reference/bearer-token-format\">Bearer Token Format</a>.",
|
||||
"enum": [
|
||||
"default",
|
||||
"idp_access_token",
|
||||
"idp_identity_token"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"caSecrets": {
|
||||
"description": "CASecret should refer to k8s secrets with key <code>ca.crt</code> containing a CA certificate.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"certificateAutoProvision": {
|
||||
"description": "CertificateAutoProvision sets the certificate auto provision settings.\nThis is a fallback for routes that are not defined via Ingress or\nGateway resources. When configured, cert-manager certificate resources\nwill be created for any routes which have no matching TLS certificate.",
|
||||
"properties": {
|
||||
"clusterIssuer": {
|
||||
"description": "The cert-manager ClusterIssuer that will be used for new certificates.\nCertificates will be created in the same namespace as the controller\npod.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"issuer": {
|
||||
"description": "The cert-manager Issuer that will be used for new certificates.\nCertificates will be created in the same namespace as the Issuer.",
|
||||
"format": "namespace/name",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"certificates": {
|
||||
"description": "Certificates is a list of secrets of type TLS to use",
|
||||
"format": "namespace/name",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"circuitBreakerThresholds": {
|
||||
"description": "CircuitBreakerThresholds sets the circuit breaker thresholds settings.",
|
||||
"properties": {
|
||||
"maxConnectionPools": {
|
||||
"description": "MaxConnectionPools sets the maximum number of connection pools per\ncluster that Envoy will concurrently support at once. If not specified,\nthe default is unlimited. Set this for clusters which create a large\nnumber of connection pools.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"maxConnections": {
|
||||
"description": "MaxConnections sets the maximum number of connections that Envoy will\nmake to the upstream cluster. If not specified, the default is 1024.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"maxPendingRequests": {
|
||||
"description": "MaxPendingRequests sets the maximum number of pending requests that\nEnvoy will allow to the upstream cluster. If not specified, the\ndefault is 1024. This limit is applied as a connection limit for\nnon-HTTP traffic.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"maxRequests": {
|
||||
"description": "MaxRequests sets the maximum number of parallel requests that Envoy\nwill make to the upstream cluster. If not specified, the default is\n1024. This limit does not apply to non-HTTP traffic.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"maxRetries": {
|
||||
"description": "MaxRetries sets the maximum number of parallel retries that Envoy\nwill allow to the upstream cluster. If not specified, the default is 3.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"codecType": {
|
||||
"description": "CodecType sets the <a href=\"https://www.pomerium.com/docs/reference/codec-type\">Codec Type</a>.",
|
||||
"enum": [
|
||||
"auto",
|
||||
"http1",
|
||||
"http2",
|
||||
"http3"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"cookie": {
|
||||
"description": "Cookie defines Pomerium session cookie options.",
|
||||
"properties": {
|
||||
"domain": {
|
||||
"description": "Domain defaults to the same host that set the cookie.\nIf you specify the domain explicitly, then subdomains would also be included.",
|
||||
"type": "string"
|
||||
},
|
||||
"expire": {
|
||||
"description": "Expire sets cookie and Pomerium session expiration time.\nOnce session expires, users would have to re-login.\nIf you change this parameter, existing sessions are not affected.\n<p>See <a href=\"https://www.pomerium.com/docs/enterprise/about#session-management\">Session Management</a>\n(Enterprise) for a more fine-grained session controls.</p>\n<p>Defaults to 14 hours.</p>",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"httpOnly": {
|
||||
"description": "HTTPOnly if set to <code>false</code>, the cookie would be accessible from within the JavaScript.\nDefaults to <code>true</code>.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"name": {
|
||||
"description": "Name sets the Pomerium session cookie name.\nDefaults to <code>_pomerium</code>",
|
||||
"type": "string"
|
||||
},
|
||||
"sameSite": {
|
||||
"description": "SameSite sets the SameSite option for cookies.\nDefaults to <code></code>.",
|
||||
"enum": [
|
||||
"strict",
|
||||
"lax",
|
||||
"none"
|
||||
],
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"dataBroker": {
|
||||
"description": "DataBroker sets the databroker settings.",
|
||||
"properties": {
|
||||
"clusterLeaderId": {
|
||||
"description": "ClusterLeaderID defines the cluster leader in a clustered databroker.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"dns": {
|
||||
"description": "DNS sets the dns settings.",
|
||||
"properties": {
|
||||
"failureRefreshRate": {
|
||||
"description": "FailureRefreshRate is the rate at which DNS lookups are refreshed when requests are failing.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"lookupFamily": {
|
||||
"description": "LookupFamily is the DNS IP address resolution policy.",
|
||||
"enum": [
|
||||
"auto",
|
||||
"v4_only",
|
||||
"v6_only",
|
||||
"v4_preferred",
|
||||
"all"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"queryTimeout": {
|
||||
"description": "QueryTimeout is the amount of time each name server is given to respond to a query on the first try of any given server.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"queryTries": {
|
||||
"description": "QueryTries is the maximum number of query attempts the resolver will make before giving up. Each attempt may use a different name server.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"refreshRate": {
|
||||
"description": "RefreshRate is the rate at which DNS lookups are refreshed.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"udpMaxQueries": {
|
||||
"description": "UDPMaxQueries caps the number of UDP based DNS queries on a single port.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"useTcp": {
|
||||
"description": "UseTCP uses TCP for all DNS queries instead of the default protocol UDP.",
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"downstreamMtls": {
|
||||
"description": "DownstreamMTLS sets the <a href=\"https://www.pomerium.com/docs/reference/downstream-mtls-settings\">Downstream MTLS Settings</a>.",
|
||||
"properties": {
|
||||
"ca": {
|
||||
"description": "CA is a bundle of PEM-encoded X.509 certificates that will be treated as trust anchors when verifying client certificates.",
|
||||
"format": "byte",
|
||||
"type": "string"
|
||||
},
|
||||
"crl": {
|
||||
"description": "CRL is a bundle of PEM-encoded certificate revocation lists to be consulted during certificate validation.",
|
||||
"format": "byte",
|
||||
"type": "string"
|
||||
},
|
||||
"enforcement": {
|
||||
"description": "Enforcement controls Pomerium's behavior when a client does not present a trusted client certificate.",
|
||||
"enum": [
|
||||
"policy_with_default_deny",
|
||||
"policy",
|
||||
"reject_connection"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"matchSubjectAltNames": {
|
||||
"description": "Match Subject Alt Names can be used to add an additional constraint when validating client certificates.",
|
||||
"properties": {
|
||||
"dns": {
|
||||
"type": "string"
|
||||
},
|
||||
"email": {
|
||||
"type": "string"
|
||||
},
|
||||
"ipAddress": {
|
||||
"type": "string"
|
||||
},
|
||||
"uri": {
|
||||
"type": "string"
|
||||
},
|
||||
"userPrincipalName": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"maxVerifyDepth": {
|
||||
"description": "MaxVerifyDepth sets a limit on the depth of a certificate chain presented by the client.",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"envoyDynamicExtensions": {
|
||||
"description": "EnvoyDynamicExtensions file paths to the extensions to be loaded by Envoy at runtime.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"headersWithUnderscoresAction": {
|
||||
"description": "HeadersWithUnderscoresAction controls the behavior for a request with a\nheader name containing an underscore character. The default behavior is\nreject_request.",
|
||||
"enum": [
|
||||
"allow",
|
||||
"reject_request",
|
||||
"drop_header"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"identityProvider": {
|
||||
"description": "IdentityProvider configure single-sign-on authentication and user identity details\nby integrating with your <a href=\"https://www.pomerium.com/docs/identity-providers/\">Identity Provider</a>",
|
||||
"properties": {
|
||||
"provider": {
|
||||
"description": "Provider is the short-hand name of a built-in OpenID Connect (oidc) identity provider to be used for authentication.\nTo use a generic provider, set to <code>oidc</code>.",
|
||||
"enum": [
|
||||
"apple",
|
||||
"auth0",
|
||||
"azure",
|
||||
"cognito",
|
||||
"github",
|
||||
"gitlab",
|
||||
"google",
|
||||
"hosted",
|
||||
"oidc",
|
||||
"okta",
|
||||
"onelogin",
|
||||
"ping"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"refreshDirectory": {
|
||||
"description": "RefreshDirectory is no longer supported,\nplease see <a href=\"https://docs.pomerium.com/docs/overview/upgrading#idp-directory-sync\">Upgrade Guide</a>.",
|
||||
"properties": {
|
||||
"interval": {
|
||||
"description": "interval is the time that pomerium will sync your IDP directory.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"timeout": {
|
||||
"description": "timeout is the maximum time allowed each run.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"interval",
|
||||
"timeout"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"requestParams": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "RequestParams to be added as part of a sign-in request using OAuth2 code flow.",
|
||||
"format": "namespace/name",
|
||||
"type": "object"
|
||||
},
|
||||
"requestParamsSecret": {
|
||||
"description": "RequestParamsSecret is a reference to a secret for additional parameters you'd prefer not to provide in plaintext.",
|
||||
"format": "namespace/name",
|
||||
"type": "string"
|
||||
},
|
||||
"scopes": {
|
||||
"description": "Scopes Identity provider scopes correspond to access privilege scopes\nas defined in Section 3.3 of OAuth 2.0 RFC6749.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"secret": {
|
||||
"description": "Secret containing IdP provider specific parameters.\nand must contain at least <code>client_id</code> and <code>client_secret</code> values.",
|
||||
"format": "namespace/name",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"serviceAccountFromSecret": {
|
||||
"description": "ServiceAccountFromSecret is no longer supported,\nsee <a href=\"https://docs.pomerium.com/docs/overview/upgrading#idp-directory-sync\">Upgrade Guide</a>.",
|
||||
"type": "string"
|
||||
},
|
||||
"url": {
|
||||
"description": "URL is the base path to an identity provider's OpenID connect discovery document.\nSee <a href=\"https://pomerium.com/docs/identity-providers\">Identity Providers</a> guides for details.",
|
||||
"format": "uri",
|
||||
"pattern": "^https://",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"provider"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"fieldPath": ".secret",
|
||||
"message": "secret is required unless provider is 'hosted'",
|
||||
"reason": "FieldValueRequired",
|
||||
"rule": "self.provider != 'hosted' ? has(self.secret) : true"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"idpAccessTokenAllowedAudiences": {
|
||||
"description": "IDPAccessTokenAllowedAudiences specifies the\n<a href=\"https://www.pomerium.com/docs/reference/idp-access-token-allowed-audiences\">idp access token allowed audiences</a>\nlist.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"jwtClaimHeaders": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "JWTClaimHeaders convert claims from the assertion token\ninto HTTP headers and adds them into JWT assertion header.\nPlease make sure to read\n<a href=\"https://www.pomerium.com/docs/capabilities/getting-users-identity\">\nGetting User Identity</a> guide.",
|
||||
"type": "object"
|
||||
},
|
||||
"mcpAllowedAsMetadataDomains": {
|
||||
"description": "MCPAllowedASMetadataDomains specifies the allowed domains for upstream AS/PRM metadata URLs.\nSupports wildcard patterns like \"*.example.com\".\nThis restricts which domains Pomerium will contact during upstream OAuth discovery\n(resource_metadata from WWW-Authenticate, authorization_servers from PRM).\nSee <a href=\"https://www.pomerium.com/docs/reference/mcp\">MCP Settings</a>.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"mcpAllowedClientIdDomains": {
|
||||
"description": "MCPAllowedClientIDDomains specifies the allowed domains for MCP client ID metadata URLs.\nThis is required when MCP is enabled.\nSee <a href=\"https://www.pomerium.com/docs/reference/mcp\">MCP Settings</a>.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"mergeSlashes": {
|
||||
"description": "MergeSlashes controls whether adjacent slashes in the request URI path\nwill be merged into one. Defaults to true.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"normalizePath": {
|
||||
"description": "NormalizePath controls whether request URI paths will be normalized\naccording to RFC 3986. Defaults to true.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"otel": {
|
||||
"description": "OTEL sets the <a href=\"https://www.pomerium.com/docs/reference/tracing\">OpenTelemetry Tracing</a>.",
|
||||
"properties": {
|
||||
"bspMaxExportBatchSize": {
|
||||
"description": "BSPMaxExportBatchSize sets the maximum number of spans to export in a single batch",
|
||||
"format": "int32",
|
||||
"type": "integer"
|
||||
},
|
||||
"bspScheduleDelay": {
|
||||
"description": "BSPScheduleDelay sets interval between two consecutive exports",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"endpoint": {
|
||||
"description": "An OTLP/gRPC or OTLP/HTTP base endpoint URL with optional port.<br/>Example: `http://localhost:4318`",
|
||||
"type": "string"
|
||||
},
|
||||
"headers": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Extra headers",
|
||||
"type": "object"
|
||||
},
|
||||
"logLevel": {
|
||||
"description": "LogLevel sets the log level for the OpenTelemetry SDK.",
|
||||
"enum": [
|
||||
"trace",
|
||||
"debug",
|
||||
"info",
|
||||
"warn",
|
||||
"error"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"protocol": {
|
||||
"description": "Valid values are `\"grpc\"` or `\"http/protobuf\"`.",
|
||||
"enum": [
|
||||
"grpc",
|
||||
"http/protobuf"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"resourceAttributes": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "ResourceAttributes sets the additional attributes to be added to the trace.",
|
||||
"type": "object"
|
||||
},
|
||||
"sampling": {
|
||||
"description": "Sampling sets sampling probability between [0, 1].",
|
||||
"format": "number",
|
||||
"type": "string"
|
||||
},
|
||||
"timeout": {
|
||||
"description": "Export request timeout duration",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"endpoint",
|
||||
"protocol"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"passIdentityHeaders": {
|
||||
"description": "PassIdentityHeaders sets the <a href=\"https://www.pomerium.com/docs/reference/pass-identity-headers\">pass identity headers</a> option.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"pathWithEscapedSlashesAction": {
|
||||
"description": "PathWithEscapedSlashesAction controls the behavior for a request with an\nescaped slash or backslash character in the URI path. This operation will\noccur before path normalization and the merge slashes operation. The\ndefault behavior is reject_request.",
|
||||
"enum": [
|
||||
"keep_unchanged",
|
||||
"reject_request",
|
||||
"unescape_and_redirect",
|
||||
"unescape_and_forward"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"programmaticRedirectDomains": {
|
||||
"description": "ProgrammaticRedirectDomains specifies a list of domains that can be used for\n<a href=\"https://www.pomerium.com/docs/capabilities/programmatic-access\">programmatic redirects</a>.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"runtimeFlags": {
|
||||
"additionalProperties": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"description": "RuntimeFlags sets the <a href=\"https://www.pomerium.com/docs/reference/runtime-flags\">runtime flags</a> to enable/disable certain features.",
|
||||
"type": "object"
|
||||
},
|
||||
"secrets": {
|
||||
"description": "Secrets references a Secret with Pomerium bootstrap parameters.\n\n<p>\n<ul>\n\t<li><a href=\"https://pomerium.com/docs/reference/shared-secret\"><code>shared_secret</code></a>\n\t\t- secures inter-Pomerium service communications.\n\t</li>\n\t<li><a href=\"https://pomerium.com/docs/reference/cookie-secret\"><code>cookie_secret</code></a>\n\t\t- encrypts Pomerium session browser cookie.\n\t\tSee also other <a href=\"#cookie\">Cookie</a> parameters.\n\t</li>\n\t<li><a href=\"https://pomerium.com/docs/reference/signing-key\"><code>signing_key</code></a>\n\t\tsigns Pomerium JWT assertion header. See\n\t\t<a href=\"https://www.pomerium.com/docs/capabilities/getting-users-identity\">Getting the user's identity</a>\n\t\tguide.\n\t</li>\n</ul>\n</p>\n<p>\nIn a default Pomerium installation manifest, they would be generated via a\n<a href=\"https://github.com/pomerium/ingress-controller/blob/main/config/gen_secrets/job.yaml\">one-time job</a>\nand stored in a <code>pomerium/bootstrap</code> Secret.\nYou may re-run the job to rotate the secrets, or update the Secret values manually.\n</p>\n<p>\nWhen defining the Secret in a manifest, put raw values in <code>stringData</code> so\nKubernetes base64-encodes them. Use <code>data</code> only when values are already\nbase64-encoded.\n</p>\n<p>\nExample: <code>stringData.shared_secret</code> and <code>stringData.cookie_secret</code> are\nraw strings, while <code>data.signing_key</code> is base64-encoded.\n</p>",
|
||||
"format": "namespace/name",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"setResponseHeaders": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "SetResponseHeaders specifies a mapping of HTTP Header to be added globally to all managed routes and pomerium's authenticate service.\nSee <a href=\"https://www.pomerium.com/docs/reference/set-response-headers\">Set Response Headers</a>",
|
||||
"type": "object"
|
||||
},
|
||||
"ssh": {
|
||||
"description": "SSH sets the ssh settings.",
|
||||
"properties": {
|
||||
"hostKeySecrets": {
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"userCaKeySecret": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"storage": {
|
||||
"description": "Storage defines persistent storage for sessions and other data.\nSee <a href=\"https://www.pomerium.com/docs/internals/data-storage\">Storage</a> for details.\nIf no storage is specified, Pomerium would use a transient in-memory storage (not recommended for production).",
|
||||
"properties": {
|
||||
"file": {
|
||||
"description": "File specifies file storage options.",
|
||||
"properties": {
|
||||
"path": {
|
||||
"description": "Path defines the local file system path to store data.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"path"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"postgres": {
|
||||
"description": "Postgres specifies PostgreSQL database connection parameters",
|
||||
"properties": {
|
||||
"caSecret": {
|
||||
"description": "CASecret should refer to a k8s secret with key <code>ca.crt</code> containing CA certificate\nthat, if specified, would be used to populate <code>sslrootcert</code> parameter of the connection string.",
|
||||
"format": "namespace/name",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"secret": {
|
||||
"description": "Secret specifies a name of a Secret that must contain\n<code>connection</code> key. See\n<a href=\"https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-CONNSTRING\">DSN Format and Parameters</a>.\nDo not set <code>sslrootcert</code>, <code>sslcert</code> and <code>sslkey</code> via connection string,\nuse <code>tlsSecret</code> and <code>caSecret</code> CRD options instead.",
|
||||
"format": "namespace/name",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"tlsSecret": {
|
||||
"description": "TLSSecret should refer to a k8s secret of type <code>kubernetes.io/tls</code>\nand allows to specify an optional client certificate and key,\nby constructing <code>sslcert</code> and <code>sslkey</code> connection string\n<a href=\"https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-PARAMKEYWORDS\">\nparameter values</a>.",
|
||||
"format": "namespace/name",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secret"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"timeouts": {
|
||||
"description": "Timeout specifies the <a href=\"https://www.pomerium.com/docs/reference/global-timeouts\">global timeouts</a> for all routes.",
|
||||
"properties": {
|
||||
"idle": {
|
||||
"description": "Idle specifies the time at which a downstream or upstream connection will be terminated if there are no active streams.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"read": {
|
||||
"description": "Read specifies the amount of time for the entire request stream to be received from the client.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
},
|
||||
"write": {
|
||||
"description": "Write specifies max stream duration is the maximum time that a stream\u2019s lifetime will span.\nAn HTTP request/response exchange fully consumes a single stream.\nTherefore, this value must be greater than read_timeout as it covers both request and response time.",
|
||||
"format": "duration",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"useProxyProtocol": {
|
||||
"description": "UseProxyProtocol enables <a href=\"https://www.pomerium.com/docs/reference/use-proxy-protocol\">Proxy Protocol</a> support.",
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secrets"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"fieldPath": ".authenticate",
|
||||
"message": "authenticate is required if identityProvider is set",
|
||||
"reason": "FieldValueRequired",
|
||||
"rule": "!has(self.identityProvider) || has(self.authenticate)"
|
||||
},
|
||||
{
|
||||
"fieldPath": ".identityProvider",
|
||||
"message": "identityProvider is required if authenticate is set",
|
||||
"reason": "FieldValueRequired",
|
||||
"rule": "!has(self.authenticate) || has(self.identityProvider)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "PomeriumStatus represents configuration and Ingress status.",
|
||||
"properties": {
|
||||
"certificateAutoProvisionStatus": {
|
||||
"description": "Status of certificate auto provisioning.",
|
||||
"properties": {
|
||||
"dataBrokerLastUpdated": {
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ingress": {
|
||||
"additionalProperties": {
|
||||
"description": "ResourceStatus represents the outcome of the latest attempt to reconcile\nrelevant Kubernetes resource with Pomerium.",
|
||||
"properties": {
|
||||
"error": {
|
||||
"description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
|
||||
"type": "string"
|
||||
},
|
||||
"observedAt": {
|
||||
"description": "ObservedAt is when last reconciliation attempt was made.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration represents the <code>.metadata.generation</code> that was last presented to Pomerium.",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"reconciled": {
|
||||
"description": "Reconciled is whether this object generation was successfully synced with pomerium.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"warnings": {
|
||||
"description": "Warnings while parsing the resource.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"reconciled"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": "Routes provide per-Ingress status.",
|
||||
"type": "object"
|
||||
},
|
||||
"settingsStatus": {
|
||||
"description": "SettingsStatus represent most recent main configuration reconciliation status.",
|
||||
"properties": {
|
||||
"error": {
|
||||
"description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
|
||||
"type": "string"
|
||||
},
|
||||
"observedAt": {
|
||||
"description": "ObservedAt is when last reconciliation attempt was made.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration represents the <code>.metadata.generation</code> that was last presented to Pomerium.",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"reconciled": {
|
||||
"description": "Reconciled is whether this object generation was successfully synced with pomerium.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"warnings": {
|
||||
"description": "Warnings while parsing the resource.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"reconciled"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
Reference in New Issue
Block a user