This commit is contained in:
2026-09-28 16:28:35 +01:00
parent 666b1ff877
commit e27aa106fd
76 changed files with 5634 additions and 906 deletions
@@ -1265,7 +1265,7 @@
"additionalProperties": false
},
"externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.",
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1,
"type": "string"
},
@@ -1334,7 +1334,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -1393,7 +1393,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -1690,7 +1690,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -1749,7 +1749,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -1940,7 +1940,7 @@
"description": "Selects a key of a ConfigMap.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -2208,6 +2208,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -2329,6 +2333,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -2419,6 +2427,10 @@
"grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32",
@@ -2483,6 +2495,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -2621,6 +2637,10 @@
"grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32",
@@ -2685,6 +2705,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -3056,6 +3080,10 @@
"grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32",
@@ -3120,6 +3148,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -3238,8 +3270,16 @@
"items": {
"description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
"description": "Path within the container at which the volume should be mounted.",
"type": "string"
},
"mountPropagation": {
@@ -3298,7 +3338,7 @@
"type": "boolean"
},
"disableCompaction": {
"description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.41.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.41.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.",
"description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.42.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.42.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.",
"type": "boolean"
},
"dnsConfig": {
@@ -3619,7 +3659,7 @@
"description": "Selects a key of a ConfigMap.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -3887,6 +3927,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -4008,6 +4052,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -4098,6 +4146,10 @@
"grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32",
@@ -4162,6 +4214,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -4300,6 +4356,10 @@
"grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32",
@@ -4364,6 +4424,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -4735,6 +4799,10 @@
"grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32",
@@ -4799,6 +4867,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true
},
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string"
@@ -4917,8 +4989,16 @@
"items": {
"description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
"description": "Path within the container at which the volume should be mounted.",
"type": "string"
},
"mountPropagation": {
@@ -5588,7 +5668,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -5729,7 +5809,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -5784,7 +5864,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -5969,7 +6049,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -6028,7 +6108,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -6437,7 +6517,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -6578,7 +6658,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -6633,7 +6713,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -6888,7 +6968,7 @@
"additionalProperties": false
},
"externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.",
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1,
"type": "string"
},
@@ -6952,7 +7032,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -7011,7 +7091,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -7295,10 +7375,23 @@
"additionalProperties": false
},
"retention": {
"description": "retention defines how long to retain the Prometheus data.\n\nDefault: \"24h\" if `spec.retention` and `spec.retentionSize` are empty.",
"description": "retention defines how long to retain the Prometheus data.\n\nDefault: \"24h\" if `spec.retention`, `spec.retentionSize` and\n`spec.retentionPercentage` are empty.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string"
},
"retentionPercentage": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "retentionPercentage defines the maximum percentage of the data volume's\ncapacity used by the Prometheus data.\n\nThe value is a number between 0 and 100. If set to 0, percentage-based\nretention is disabled.\n\nIt requires Prometheus >= v3.11.0 and is ignored by older versions.",
"pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
"x-kubernetes-int-or-string": true
},
"retentionSize": {
"description": "retentionSize defines the maximum number of bytes used by the Prometheus data.",
"pattern": "(^0|([0-9]*[.])?[0-9]+((K|M|G|T|E|P)i?)?B)$",
@@ -7681,7 +7774,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -7740,7 +7833,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -8052,7 +8145,7 @@
"type": "integer"
},
"seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string"
},
"seLinuxOptions": {
@@ -8365,6 +8458,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string"
},
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": {
"anyOf": [
{
@@ -8404,7 +8502,7 @@
"x-kubernetes-list-type": "atomic"
},
"dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": {
"apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8428,7 +8526,7 @@
"additionalProperties": false
},
"dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": {
"apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8619,7 +8717,7 @@
"x-kubernetes-list-type": "atomic"
},
"dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": {
"apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8643,7 +8741,7 @@
"additionalProperties": false
},
"dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": {
"apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8876,6 +8974,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string"
},
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": {
@@ -8986,7 +9133,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -9045,7 +9192,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -9354,8 +9501,16 @@
"items": {
"description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
"description": "Path within the container at which the volume should be mounted.",
"type": "string"
},
"mountPropagation": {
@@ -9597,7 +9752,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -9656,7 +9811,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -9867,8 +10022,16 @@
"items": {
"description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.",
"description": "Path within the container at which the volume should be mounted.",
"type": "string"
},
"mountPropagation": {
@@ -10087,6 +10250,11 @@
"format": "int32",
"type": "integer"
},
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": {
@@ -10104,6 +10272,11 @@
"path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -10180,6 +10353,11 @@
"format": "int32",
"type": "integer"
},
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": {
"description": "Items is a list of downward API volume file",
"items": {
@@ -10244,6 +10422,11 @@
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -10266,6 +10449,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string"
},
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": {
"anyOf": [
{
@@ -10305,7 +10493,7 @@
"x-kubernetes-list-type": "atomic"
},
"dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": {
"apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -10329,7 +10517,7 @@
"additionalProperties": false
},
"dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": {
"apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -10834,6 +11022,11 @@
"format": "int32",
"type": "integer"
},
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": {
@@ -10904,6 +11097,11 @@
"signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -10932,6 +11130,11 @@
"path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -11025,6 +11228,11 @@
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -11068,6 +11276,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": {
"additionalProperties": {
"type": "string"
@@ -11103,6 +11316,11 @@
"path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -11144,6 +11362,11 @@
"path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -11328,6 +11551,11 @@
"format": "int32",
"type": "integer"
},
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": {
@@ -11345,6 +11573,11 @@
"path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
}
},
"required": [
@@ -11514,7 +11747,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {
@@ -11580,7 +11813,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": {
"key": {
"description": "The key to select.",
"description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string"
},
"name": {