update crds
This commit is contained in:
@@ -0,0 +1,487 @@
|
||||
{
|
||||
"description": "IngressRoute is the CRD implementation of a Traefik HTTP Router.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "IngressRouteSpec defines the desired state of IngressRoute.",
|
||||
"properties": {
|
||||
"entryPoints": {
|
||||
"description": "EntryPoints defines the list of entry point names to bind to.\nEntry points have to be configured in the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/install-configuration/entrypoints/\nDefault: all.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"ingressClassName": {
|
||||
"description": "IngressClassName defines the name of the IngressClass cluster resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"parentRefs": {
|
||||
"description": "ParentRefs defines references to parent IngressRoute resources for multi-layer routing.\nWhen set, this IngressRoute's routers will be children of the referenced parent IngressRoute's routers.\nMore info: https://doc.traefik.io/traefik/v3.7/routing/routers/#parentrefs",
|
||||
"items": {
|
||||
"description": "IngressRouteRef is a reference to an IngressRoute resource.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced IngressRoute resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced IngressRoute resource.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"routes": {
|
||||
"description": "Routes defines the list of routes.",
|
||||
"items": {
|
||||
"description": "Route holds the HTTP route configuration.",
|
||||
"properties": {
|
||||
"kind": {
|
||||
"description": "Kind defines the kind of the route.\nRule is the only supported kind.\nIf not defined, defaults to Rule.",
|
||||
"enum": [
|
||||
"Rule"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"match": {
|
||||
"description": "Match defines the router's rule.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/routing/rules-and-priority/",
|
||||
"type": "string"
|
||||
},
|
||||
"middlewares": {
|
||||
"description": "Middlewares defines the list of references to Middleware resources.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/kubernetes/crd/http/middleware/",
|
||||
"items": {
|
||||
"description": "MiddlewareRef is a reference to a Middleware resource.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Middleware resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Middleware resource.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"observability": {
|
||||
"description": "Observability defines the observability configuration for a router.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/routing/observability/",
|
||||
"properties": {
|
||||
"accessLogs": {
|
||||
"description": "AccessLogs enables access logs for this router.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"metrics": {
|
||||
"description": "Metrics enables metrics for this router.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"traceVerbosity": {
|
||||
"default": "minimal",
|
||||
"description": "TraceVerbosity defines the verbosity level of the tracing for this router.",
|
||||
"enum": [
|
||||
"minimal",
|
||||
"detailed"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"tracing": {
|
||||
"description": "Tracing enables tracing for this router.",
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"priority": {
|
||||
"description": "Priority defines the router's priority.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/routing/rules-and-priority/#priority",
|
||||
"maximum": 9223372036854775000,
|
||||
"type": "integer"
|
||||
},
|
||||
"services": {
|
||||
"description": "Services defines the list of Service.\nIt can contain any combination of TraefikService and/or reference to a Kubernetes Service.",
|
||||
"items": {
|
||||
"description": "Service defines an upstream HTTP service to proxy traffic to.",
|
||||
"properties": {
|
||||
"healthCheck": {
|
||||
"description": "Healthcheck defines health checks for ExternalName services.",
|
||||
"properties": {
|
||||
"followRedirects": {
|
||||
"description": "FollowRedirects defines whether redirects should be followed during the health check calls.\nDefault: true",
|
||||
"type": "boolean"
|
||||
},
|
||||
"headers": {
|
||||
"additionalProperties": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "Headers defines custom headers to be sent to the health check endpoint.",
|
||||
"type": "object"
|
||||
},
|
||||
"hostname": {
|
||||
"description": "Hostname defines the value of hostname in the Host header of the health check request.",
|
||||
"type": "string"
|
||||
},
|
||||
"interval": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "Interval defines the frequency of the health check calls for healthy targets.\nDefault: 30s",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"method": {
|
||||
"description": "Method defines the healthcheck method.",
|
||||
"type": "string"
|
||||
},
|
||||
"mode": {
|
||||
"description": "Mode defines the health check mode.\nIf defined to grpc, will use the gRPC health check protocol to probe the server.\nDefault: http",
|
||||
"type": "string"
|
||||
},
|
||||
"path": {
|
||||
"description": "Path defines the server URL path for the health check endpoint.",
|
||||
"type": "string"
|
||||
},
|
||||
"port": {
|
||||
"description": "Port defines the server URL port for the health check endpoint.",
|
||||
"type": "integer"
|
||||
},
|
||||
"scheme": {
|
||||
"description": "Scheme replaces the server URL scheme for the health check endpoint.",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status defines the expected HTTP status code of the response to the health check request.",
|
||||
"type": "integer"
|
||||
},
|
||||
"timeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "Timeout defines the maximum duration Traefik will wait for a health check request before considering the server unhealthy.\nDefault: 5s",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"unhealthyInterval": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "UnhealthyInterval defines the frequency of the health check calls for unhealthy targets.\nWhen UnhealthyInterval is not defined, it defaults to the Interval value.\nDefault: 30s",
|
||||
"x-kubernetes-int-or-string": true
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind defines the kind of the Service.",
|
||||
"enum": [
|
||||
"Service",
|
||||
"TraefikService"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"middlewares": {
|
||||
"description": "Middlewares defines the list of references to Middleware resources to apply to the service.",
|
||||
"items": {
|
||||
"description": "MiddlewareRef is a reference to a Middleware resource.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Middleware resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Middleware resource.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Kubernetes Service or TraefikService.\nThe differentiation between the two is specified in the Kind field.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Kubernetes Service or TraefikService.",
|
||||
"type": "string"
|
||||
},
|
||||
"nativeLB": {
|
||||
"description": "NativeLB controls, when creating the load-balancer,\nwhether the LB's children are directly the pods IPs or if the only child is the Kubernetes Service clusterIP.\nThe Kubernetes Service itself does load-balance to the pods.\nBy default, NativeLB is false.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"nodePortLB": {
|
||||
"description": "NodePortLB controls, when creating the load-balancer,\nwhether the LB's children are directly the nodes internal IPs using the nodePort when the service type is NodePort.\nIt allows services to be reachable when Traefik runs externally from the Kubernetes cluster but within the same network of the nodes.\nBy default, NodePortLB is false.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"passHostHeader": {
|
||||
"description": "PassHostHeader defines whether the client Host header is forwarded to the upstream Kubernetes Service.\nBy default, passHostHeader is true.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"passiveHealthCheck": {
|
||||
"description": "PassiveHealthCheck defines passive health checks for ExternalName services.",
|
||||
"properties": {
|
||||
"failureWindow": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "FailureWindow defines the time window during which the failed attempts must occur for the server to be marked as unhealthy. It also defines for how long the server will be considered unhealthy.",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"maxFailedAttempts": {
|
||||
"description": "MaxFailedAttempts is the number of consecutive failed attempts allowed within the failure window before marking the server as unhealthy.",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"port": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "Port defines the port of a Kubernetes Service.\nThis can be a reference to a named port.",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"responseForwarding": {
|
||||
"description": "ResponseForwarding defines how Traefik forwards the response from the upstream Kubernetes Service to the client.",
|
||||
"properties": {
|
||||
"flushInterval": {
|
||||
"description": "FlushInterval defines the interval, in milliseconds, in between flushes to the client while copying the response body.\nA negative value means to flush immediately after each write to the client.\nThis configuration is ignored when ReverseProxy recognizes a response as a streaming response;\nfor such responses, writes are flushed to the client immediately.\nDefault: 100ms",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"scheme": {
|
||||
"description": "Scheme defines the scheme to use for the request to the upstream Kubernetes Service.\nIt defaults to https when Kubernetes Service port is 443, http otherwise.",
|
||||
"type": "string"
|
||||
},
|
||||
"serversTransport": {
|
||||
"description": "ServersTransport defines the name of ServersTransport resource to use.\nIt allows to configure the transport between Traefik and your servers.\nCan only be used on a Kubernetes Service.",
|
||||
"type": "string"
|
||||
},
|
||||
"sticky": {
|
||||
"description": "Sticky defines the sticky sessions configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/load-balancing/service/#sticky-sessions",
|
||||
"properties": {
|
||||
"cookie": {
|
||||
"description": "Cookie defines the sticky cookie configuration.",
|
||||
"properties": {
|
||||
"domain": {
|
||||
"description": "Domain defines the host to which the cookie will be sent.\nMore info: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie#domaindomain-value",
|
||||
"type": "string"
|
||||
},
|
||||
"httpOnly": {
|
||||
"description": "HTTPOnly defines whether the cookie can be accessed by client-side APIs, such as JavaScript.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"maxAge": {
|
||||
"description": "MaxAge defines the number of seconds until the cookie expires.\nWhen set to a negative number, the cookie expires immediately.\nWhen set to zero, the cookie never expires.",
|
||||
"type": "integer"
|
||||
},
|
||||
"name": {
|
||||
"description": "Name defines the Cookie name.",
|
||||
"type": "string"
|
||||
},
|
||||
"path": {
|
||||
"description": "Path defines the path that must exist in the requested URL for the browser to send the Cookie header.\nWhen not provided the cookie will be sent on every request to the domain.\nMore info: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie#pathpath-value",
|
||||
"type": "string"
|
||||
},
|
||||
"sameSite": {
|
||||
"description": "SameSite defines the same site policy.\nMore info: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite",
|
||||
"enum": [
|
||||
"none",
|
||||
"lax",
|
||||
"strict",
|
||||
"None",
|
||||
"Lax",
|
||||
"Strict"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"secure": {
|
||||
"description": "Secure defines whether the cookie can only be transmitted over an encrypted connection (i.e. HTTPS).",
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"strategy": {
|
||||
"description": "Strategy defines the load balancing strategy between the servers.\nSupported values are: wrr (Weighed round-robin), p2c (Power of two choices), hrw (Highest Random Weight), and leasttime (Least-Time).\nRoundRobin value is deprecated and supported for backward compatibility.",
|
||||
"enum": [
|
||||
"wrr",
|
||||
"p2c",
|
||||
"hrw",
|
||||
"leasttime",
|
||||
"RoundRobin"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"weight": {
|
||||
"description": "Weight defines the weight and should only be specified when Name references a TraefikService object\n(and to be precise, one that embeds a Weighted Round Robin).",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"syntax": {
|
||||
"description": "Syntax defines the router's rule syntax.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/routing/rules-and-priority/#rulesyntax\n\nDeprecated: Please do not use this field and rewrite the router rules to use the v3 syntax.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"match"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"tls": {
|
||||
"description": "TLS defines the TLS configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/routing/router/#tls",
|
||||
"properties": {
|
||||
"certResolver": {
|
||||
"description": "CertResolver defines the name of the certificate resolver to use.\nCert resolvers have to be configured in the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/install-configuration/tls/certificate-resolvers/acme/",
|
||||
"type": "string"
|
||||
},
|
||||
"domains": {
|
||||
"description": "Domains defines the list of domains that will be used to issue certificates.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-certificates/#domains",
|
||||
"items": {
|
||||
"description": "Domain holds a domain name with SANs.",
|
||||
"properties": {
|
||||
"main": {
|
||||
"description": "Main defines the main domain name.",
|
||||
"type": "string"
|
||||
},
|
||||
"sans": {
|
||||
"description": "SANs defines the subject alternative domain names.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"options": {
|
||||
"description": "Options defines the reference to a TLSOption, that specifies the parameters of the TLS connection.\nIf not defined, the `default` TLSOption is used.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-options/",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced TLSOption.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/kubernetes/crd/http/tlsoption/",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced TLSOption.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/kubernetes/crd/http/tlsoption/",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the referenced Kubernetes Secret to specify the certificate details.",
|
||||
"type": "string"
|
||||
},
|
||||
"store": {
|
||||
"description": "Store defines the reference to the TLSStore, that will be used to store certificates.\nPlease note that only `default` TLSStore can be used.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced TLSStore.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/kubernetes/crd/http/tlsstore/",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced TLSStore.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/kubernetes/crd/http/tlsstore/",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"routes"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,245 @@
|
||||
{
|
||||
"description": "IngressRouteTCP is the CRD implementation of a Traefik TCP Router.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "IngressRouteTCPSpec defines the desired state of IngressRouteTCP.",
|
||||
"properties": {
|
||||
"entryPoints": {
|
||||
"description": "EntryPoints defines the list of entry point names to bind to.\nEntry points have to be configured in the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/install-configuration/entrypoints/\nDefault: all.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"ingressClassName": {
|
||||
"description": "IngressClassName defines the name of the IngressClass cluster resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"routes": {
|
||||
"description": "Routes defines the list of routes.",
|
||||
"items": {
|
||||
"description": "RouteTCP holds the TCP route configuration.",
|
||||
"properties": {
|
||||
"match": {
|
||||
"description": "Match defines the router's rule.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/routing/rules-and-priority/",
|
||||
"type": "string"
|
||||
},
|
||||
"middlewares": {
|
||||
"description": "Middlewares defines the list of references to MiddlewareTCP resources.",
|
||||
"items": {
|
||||
"description": "ObjectReference is a generic reference to a Traefik resource.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Traefik resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Traefik resource.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"priority": {
|
||||
"description": "Priority defines the router's priority.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/routing/rules-and-priority/#priority",
|
||||
"maximum": 9223372036854775000,
|
||||
"type": "integer"
|
||||
},
|
||||
"services": {
|
||||
"description": "Services defines the list of TCP services.",
|
||||
"items": {
|
||||
"description": "ServiceTCP defines an upstream TCP service to proxy traffic to.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Kubernetes Service.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Kubernetes Service.",
|
||||
"type": "string"
|
||||
},
|
||||
"nativeLB": {
|
||||
"description": "NativeLB controls, when creating the load-balancer,\nwhether the LB's children are directly the pods IPs or if the only child is the Kubernetes Service clusterIP.\nThe Kubernetes Service itself does load-balance to the pods.\nBy default, NativeLB is false.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"nodePortLB": {
|
||||
"description": "NodePortLB controls, when creating the load-balancer,\nwhether the LB's children are directly the nodes internal IPs using the nodePort when the service type is NodePort.\nIt allows services to be reachable when Traefik runs externally from the Kubernetes cluster but within the same network of the nodes.\nBy default, NodePortLB is false.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"port": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "Port defines the port of a Kubernetes Service.\nThis can be a reference to a named port.",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"proxyProtocol": {
|
||||
"description": "ProxyProtocol defines the PROXY protocol configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/service/#proxy-protocol\n\nDeprecated: ProxyProtocol will not be supported in future APIVersions, please use ServersTransport to configure ProxyProtocol instead.",
|
||||
"properties": {
|
||||
"version": {
|
||||
"description": "Version defines the PROXY Protocol version to use.",
|
||||
"maximum": 2,
|
||||
"minimum": 1,
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"serversTransport": {
|
||||
"description": "ServersTransport defines the name of ServersTransportTCP resource to use.\nIt allows to configure the transport between Traefik and your servers.\nCan only be used on a Kubernetes Service.",
|
||||
"type": "string"
|
||||
},
|
||||
"terminationDelay": {
|
||||
"description": "TerminationDelay defines the deadline that the proxy sets, after one of its connected peers indicates\nit has closed the writing capability of its connection, to close the reading capability as well,\nhence fully terminating the connection.\nIt is a duration in milliseconds, defaulting to 100.\nA negative value means an infinite deadline (i.e. the reading capability is never closed).\n\nDeprecated: TerminationDelay will not be supported in future APIVersions, please use ServersTransport to configure the TerminationDelay instead.",
|
||||
"type": "integer"
|
||||
},
|
||||
"tls": {
|
||||
"description": "TLS determines whether to use TLS when dialing with the backend.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"weight": {
|
||||
"description": "Weight defines the weight used when balancing requests between multiple Kubernetes Service.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"port"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"syntax": {
|
||||
"description": "Syntax defines the router's rule syntax.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/routing/rules-and-priority/#rulesyntax\n\nDeprecated: Please do not use this field and rewrite the router rules to use the v3 syntax.",
|
||||
"enum": [
|
||||
"v3",
|
||||
"v2"
|
||||
],
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"match"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"tls": {
|
||||
"description": "TLS defines the TLS configuration on a layer 4 / TCP Route.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/routing/router/#tls",
|
||||
"properties": {
|
||||
"certResolver": {
|
||||
"description": "CertResolver defines the name of the certificate resolver to use.\nCert resolvers have to be configured in the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/install-configuration/tls/certificate-resolvers/acme/",
|
||||
"type": "string"
|
||||
},
|
||||
"domains": {
|
||||
"description": "Domains defines the list of domains that will be used to issue certificates.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/tls/#domains",
|
||||
"items": {
|
||||
"description": "Domain holds a domain name with SANs.",
|
||||
"properties": {
|
||||
"main": {
|
||||
"description": "Main defines the main domain name.",
|
||||
"type": "string"
|
||||
},
|
||||
"sans": {
|
||||
"description": "SANs defines the subject alternative domain names.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"options": {
|
||||
"description": "Options defines the reference to a TLSOption, that specifies the parameters of the TLS connection.\nIf not defined, the `default` TLSOption is used.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/tls/#tls-options",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Traefik resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Traefik resource.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"passthrough": {
|
||||
"description": "Passthrough defines whether a TLS router will terminate the TLS connection.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the referenced Kubernetes Secret to specify the certificate details.",
|
||||
"type": "string"
|
||||
},
|
||||
"store": {
|
||||
"description": "Store defines the reference to the TLSStore, that will be used to store certificates.\nPlease note that only `default` TLSStore can be used.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Traefik resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Traefik resource.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"routes"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,101 @@
|
||||
{
|
||||
"description": "IngressRouteUDP is a CRD implementation of a Traefik UDP Router.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "IngressRouteUDPSpec defines the desired state of a IngressRouteUDP.",
|
||||
"properties": {
|
||||
"entryPoints": {
|
||||
"description": "EntryPoints defines the list of entry point names to bind to.\nEntry points have to be configured in the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/install-configuration/entrypoints/\nDefault: all.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"ingressClassName": {
|
||||
"description": "IngressClassName defines the name of the IngressClass cluster resource.",
|
||||
"type": "string"
|
||||
},
|
||||
"routes": {
|
||||
"description": "Routes defines the list of routes.",
|
||||
"items": {
|
||||
"description": "RouteUDP holds the UDP route configuration.",
|
||||
"properties": {
|
||||
"services": {
|
||||
"description": "Services defines the list of UDP services.",
|
||||
"items": {
|
||||
"description": "ServiceUDP defines an upstream UDP service to proxy traffic to.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name defines the name of the referenced Kubernetes Service.",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defines the namespace of the referenced Kubernetes Service.",
|
||||
"type": "string"
|
||||
},
|
||||
"nativeLB": {
|
||||
"description": "NativeLB controls, when creating the load-balancer,\nwhether the LB's children are directly the pods IPs or if the only child is the Kubernetes Service clusterIP.\nThe Kubernetes Service itself does load-balance to the pods.\nBy default, NativeLB is false.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"nodePortLB": {
|
||||
"description": "NodePortLB controls, when creating the load-balancer,\nwhether the LB's children are directly the nodes internal IPs using the nodePort when the service type is NodePort.\nIt allows services to be reachable when Traefik runs externally from the Kubernetes cluster but within the same network of the nodes.\nBy default, NodePortLB is false.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"port": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "Port defines the port of a Kubernetes Service.\nThis can be a reference to a named port.",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"weight": {
|
||||
"description": "Weight defines the weight used when balancing requests between multiple Kubernetes Service.",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"port"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"routes"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,69 @@
|
||||
{
|
||||
"description": "MiddlewareTCP is the CRD implementation of a Traefik TCP middleware.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/middlewares/overview/",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "MiddlewareTCPSpec defines the desired state of a MiddlewareTCP.",
|
||||
"properties": {
|
||||
"inFlightConn": {
|
||||
"description": "InFlightConn defines the InFlightConn middleware configuration.",
|
||||
"properties": {
|
||||
"amount": {
|
||||
"description": "Amount defines the maximum amount of allowed simultaneous connections.\nThe middleware closes the connection if there are already amount connections opened.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ipAllowList": {
|
||||
"description": "IPAllowList defines the IPAllowList middleware configuration.\nThis middleware accepts/refuses connections based on the client IP.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/middlewares/ipallowlist/",
|
||||
"properties": {
|
||||
"sourceRange": {
|
||||
"description": "SourceRange defines the allowed IPs (or ranges of allowed IPs by using CIDR notation).",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"ipWhiteList": {
|
||||
"description": "IPWhiteList defines the IPWhiteList middleware configuration.\nThis middleware accepts/refuses connections based on the client IP.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/middlewares/ipwhitelist/\n\nDeprecated: please use IPAllowList instead.",
|
||||
"properties": {
|
||||
"sourceRange": {
|
||||
"description": "SourceRange defines the allowed IPs (or ranges of allowed IPs by using CIDR notation).",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,193 @@
|
||||
{
|
||||
"description": "ServersTransport is the CRD implementation of a ServersTransport.\nIf no serversTransport is specified, the default@internal will be used.\nThe default@internal serversTransport is created from the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/load-balancing/serverstransport/",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "ServersTransportSpec defines the desired state of a ServersTransport.",
|
||||
"properties": {
|
||||
"certificatesSecrets": {
|
||||
"description": "CertificatesSecrets defines a list of secret storing client certificates for mTLS.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"cipherSuites": {
|
||||
"description": "CipherSuites defines the cipher suites to use when contacting backend servers.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"disableHTTP2": {
|
||||
"description": "DisableHTTP2 disables HTTP/2 for connections with backend servers.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"forwardingTimeouts": {
|
||||
"description": "ForwardingTimeouts defines the timeouts for requests forwarded to the backend servers.",
|
||||
"properties": {
|
||||
"dialTimeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "DialTimeout is the amount of time to wait until a connection to a backend server can be established.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"idleConnTimeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "IdleConnTimeout is the maximum period for which an idle HTTP keep-alive connection will remain open before closing itself.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"pingTimeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "PingTimeout is the timeout after which the HTTP/2 connection will be closed if a response to ping is not received.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"readIdleTimeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "ReadIdleTimeout is the timeout after which a health check using ping frame will be carried out if no frame is received on the HTTP/2 connection.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"responseHeaderTimeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "ResponseHeaderTimeout is the amount of time to wait for a server's response headers after fully writing the request (including its body, if any).",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"insecureSkipVerify": {
|
||||
"description": "InsecureSkipVerify disables SSL certificate verification.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"maxIdleConnsPerHost": {
|
||||
"description": "MaxIdleConnsPerHost controls the maximum idle (keep-alive) to keep per-host.",
|
||||
"minimum": -1,
|
||||
"type": "integer"
|
||||
},
|
||||
"maxVersion": {
|
||||
"description": "MaxVersion defines the maximum TLS version to use when contacting backend servers.",
|
||||
"type": "string"
|
||||
},
|
||||
"minVersion": {
|
||||
"description": "MinVersion defines the minimum TLS version to use when contacting backend servers.",
|
||||
"type": "string"
|
||||
},
|
||||
"peerCertURI": {
|
||||
"description": "PeerCertURI defines the peer cert URI used to match against SAN URI during the peer certificate verification.",
|
||||
"type": "string"
|
||||
},
|
||||
"rootCAs": {
|
||||
"description": "RootCAs defines a list of CA certificate Secrets or ConfigMaps used to validate server certificates.",
|
||||
"items": {
|
||||
"description": "RootCA defines a reference to a Secret or a ConfigMap that holds a CA certificate.\nIf both a Secret and a ConfigMap reference are defined, the Secret reference takes precedence.",
|
||||
"properties": {
|
||||
"configMap": {
|
||||
"description": "ConfigMap defines the name of a ConfigMap that holds a CA certificate.\nThe referenced ConfigMap must contain a certificate under either a tls.ca or a ca.crt key.",
|
||||
"type": "string"
|
||||
},
|
||||
"secret": {
|
||||
"description": "Secret defines the name of a Secret that holds a CA certificate.\nThe referenced Secret must contain a certificate under either a tls.ca or a ca.crt key.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "RootCA cannot have both Secret and ConfigMap defined.",
|
||||
"rule": "!has(self.secret) || !has(self.configMap)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"rootCAsSecrets": {
|
||||
"description": "RootCAsSecrets defines a list of CA secret used to validate self-signed certificate.\n\nDeprecated: RootCAsSecrets is deprecated, please use the RootCAs option instead.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"serverName": {
|
||||
"description": "ServerName defines the server name used to contact the server.",
|
||||
"type": "string"
|
||||
},
|
||||
"spiffe": {
|
||||
"description": "Spiffe defines the SPIFFE configuration.",
|
||||
"properties": {
|
||||
"ids": {
|
||||
"description": "IDs defines the allowed SPIFFE IDs (takes precedence over the SPIFFE TrustDomain).",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"trustDomain": {
|
||||
"description": "TrustDomain defines the allowed SPIFFE trust domain.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,156 @@
|
||||
{
|
||||
"description": "ServersTransportTCP is the CRD implementation of a TCPServersTransport.\nIf no tcpServersTransport is specified, a default one named default@internal will be used.\nThe default@internal tcpServersTransport can be configured in the static configuration.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/tcp/serverstransport/",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "ServersTransportTCPSpec defines the desired state of a ServersTransportTCP.",
|
||||
"properties": {
|
||||
"dialKeepAlive": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "DialKeepAlive is the interval between keep-alive probes for an active network connection. If zero, keep-alive probes are sent with a default value (currently 15 seconds), if supported by the protocol and operating system. Network protocols or operating systems that do not support keep-alives ignore this field. If negative, keep-alive probes are disabled.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"dialTimeout": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "DialTimeout is the amount of time to wait until a connection to a backend server can be established.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"proxyProtocol": {
|
||||
"description": "ProxyProtocol holds the PROXY Protocol configuration.",
|
||||
"properties": {
|
||||
"version": {
|
||||
"description": "Version defines the PROXY Protocol version to use.",
|
||||
"maximum": 2,
|
||||
"minimum": 1,
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"terminationDelay": {
|
||||
"anyOf": [
|
||||
{
|
||||
"type": "integer"
|
||||
},
|
||||
{
|
||||
"type": "string"
|
||||
}
|
||||
],
|
||||
"description": "TerminationDelay defines the delay to wait before fully terminating the connection, after one connected peer has closed its writing capability.",
|
||||
"pattern": "^([0-9]+(ns|us|\u00b5s|ms|s|m|h)?)+$",
|
||||
"x-kubernetes-int-or-string": true
|
||||
},
|
||||
"tls": {
|
||||
"description": "TLS defines the TLS configuration",
|
||||
"properties": {
|
||||
"certificatesSecrets": {
|
||||
"description": "CertificatesSecrets defines a list of secret storing client certificates for mTLS.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"insecureSkipVerify": {
|
||||
"description": "InsecureSkipVerify disables TLS certificate verification.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"peerCertURI": {
|
||||
"description": "MaxIdleConnsPerHost controls the maximum idle (keep-alive) to keep per-host.\nPeerCertURI defines the peer cert URI used to match against SAN URI during the peer certificate verification.",
|
||||
"type": "string"
|
||||
},
|
||||
"rootCAs": {
|
||||
"description": "RootCAs defines a list of CA certificate Secrets or ConfigMaps used to validate server certificates.",
|
||||
"items": {
|
||||
"description": "RootCA defines a reference to a Secret or a ConfigMap that holds a CA certificate.\nIf both a Secret and a ConfigMap reference are defined, the Secret reference takes precedence.",
|
||||
"properties": {
|
||||
"configMap": {
|
||||
"description": "ConfigMap defines the name of a ConfigMap that holds a CA certificate.\nThe referenced ConfigMap must contain a certificate under either a tls.ca or a ca.crt key.",
|
||||
"type": "string"
|
||||
},
|
||||
"secret": {
|
||||
"description": "Secret defines the name of a Secret that holds a CA certificate.\nThe referenced Secret must contain a certificate under either a tls.ca or a ca.crt key.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "RootCA cannot have both Secret and ConfigMap defined.",
|
||||
"rule": "!has(self.secret) || !has(self.configMap)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"rootCAsSecrets": {
|
||||
"description": "RootCAsSecrets defines a list of CA secret used to validate self-signed certificate.\n\nDeprecated: RootCAsSecrets is deprecated, please use the RootCAs option instead.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"serverName": {
|
||||
"description": "ServerName defines the server name used to contact the server.",
|
||||
"type": "string"
|
||||
},
|
||||
"spiffe": {
|
||||
"description": "Spiffe defines the SPIFFE configuration.",
|
||||
"properties": {
|
||||
"ids": {
|
||||
"description": "IDs defines the allowed SPIFFE IDs (takes precedence over the SPIFFE TrustDomain).",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"trustDomain": {
|
||||
"description": "TrustDomain defines the allowed SPIFFE trust domain.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,94 @@
|
||||
{
|
||||
"description": "TLSOption is the CRD implementation of a Traefik TLS Option, allowing to configure some parameters of the TLS connection.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-certificates/#certificates-stores#tls-options",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "TLSOptionSpec defines the desired state of a TLSOption.",
|
||||
"properties": {
|
||||
"alpnProtocols": {
|
||||
"description": "ALPNProtocols defines the list of supported application level protocols for the TLS handshake, in order of preference.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-certificates/#certificates-stores#alpn-protocols",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"cipherSuites": {
|
||||
"description": "CipherSuites defines the list of supported cipher suites for TLS versions up to TLS 1.2.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-certificates/#certificates-stores#cipher-suites",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"clientAuth": {
|
||||
"description": "ClientAuth defines the server's policy for TLS Client Authentication.",
|
||||
"properties": {
|
||||
"clientAuthType": {
|
||||
"description": "ClientAuthType defines the client authentication type to apply.",
|
||||
"enum": [
|
||||
"NoClientCert",
|
||||
"RequestClientCert",
|
||||
"RequireAnyClientCert",
|
||||
"VerifyClientCertIfGiven",
|
||||
"RequireAndVerifyClientCert"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"secretNames": {
|
||||
"description": "SecretNames defines the names of the referenced Kubernetes Secret storing certificate details.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"curvePreferences": {
|
||||
"description": "CurvePreferences defines the preferred elliptic curves.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-certificates/#certificates-stores#curve-preferences",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"disableSessionTickets": {
|
||||
"description": "DisableSessionTickets disables TLS session resumption via session tickets.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"maxVersion": {
|
||||
"description": "MaxVersion defines the maximum TLS version that Traefik will accept.\nPossible values: VersionTLS10, VersionTLS11, VersionTLS12, VersionTLS13.\nDefault: None.",
|
||||
"type": "string"
|
||||
},
|
||||
"minVersion": {
|
||||
"description": "MinVersion defines the minimum TLS version that Traefik will accept.\nPossible values: VersionTLS10, VersionTLS11, VersionTLS12, VersionTLS13.\nDefault: VersionTLS10.",
|
||||
"type": "string"
|
||||
},
|
||||
"preferServerCipherSuites": {
|
||||
"description": "PreferServerCipherSuites defines whether the server chooses a cipher suite among his own instead of among the client's.\nIt is enabled automatically when minVersion or maxVersion is set.\n\nDeprecated: https://github.com/golang/go/issues/45430",
|
||||
"type": "boolean"
|
||||
},
|
||||
"sniStrict": {
|
||||
"description": "SniStrict defines whether Traefik allows connections from clients connections that do not specify a server_name extension.",
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,89 @@
|
||||
{
|
||||
"description": "TLSStore is the CRD implementation of a Traefik TLS Store.\nFor the time being, only the TLSStore named default is supported.\nThis means that you cannot have two stores that are named default in different Kubernetes namespaces.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/tls/tls-certificates/#certificates-stores#certificates-stores",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "TLSStoreSpec defines the desired state of a TLSStore.",
|
||||
"properties": {
|
||||
"certificates": {
|
||||
"description": "Certificates is a list of secret names, each secret holding a key/certificate pair to add to the store.",
|
||||
"items": {
|
||||
"description": "Certificate holds a secret name for the TLSStore resource.",
|
||||
"properties": {
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the referenced Kubernetes Secret to specify the certificate details.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretName"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"defaultCertificate": {
|
||||
"description": "DefaultCertificate defines the default certificate configuration.",
|
||||
"properties": {
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the referenced Kubernetes Secret to specify the certificate details.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretName"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"defaultGeneratedCert": {
|
||||
"description": "DefaultGeneratedCert defines the default generated certificate configuration.",
|
||||
"properties": {
|
||||
"domain": {
|
||||
"description": "Domain is the domain definition for the DefaultCertificate.",
|
||||
"properties": {
|
||||
"main": {
|
||||
"description": "Main defines the main domain name.",
|
||||
"type": "string"
|
||||
},
|
||||
"sans": {
|
||||
"description": "SANs defines the subject alternative domain names.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resolver": {
|
||||
"description": "Resolver is the name of the resolver that will be used to issue the DefaultCertificate.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"metadata",
|
||||
"spec"
|
||||
],
|
||||
"type": "object"
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user