This commit is contained in:
2026-09-28 16:28:35 +01:00
parent 666b1ff877
commit e27aa106fd
76 changed files with 5634 additions and 906 deletions
@@ -116,8 +116,45 @@
"description": "ImageName is the full identifier of the image to be tracked,\nincluding the registry (if not Docker Hub), the image name, and an initial/current tag or version.\nThis is the string used to query the container registry and also as a base for finding updates.\nExample: \"docker.io/library/nginx:1.17.10\", \"quay.io/prometheus/node-exporter:v1.5.0\".\nThis field is mandatory.", "description": "ImageName is the full identifier of the image to be tracked,\nincluding the registry (if not Docker Hub), the image name, and an initial/current tag or version.\nThis is the string used to query the container registry and also as a base for finding updates.\nExample: \"docker.io/library/nginx:1.17.10\", \"quay.io/prometheus/node-exporter:v1.5.0\".\nThis field is mandatory.",
"type": "string" "type": "string"
}, },
"imagesVerification": {
"description": "ImagesVerification overrides the signature verification policy for this specific image.\nWhen set, it takes precedence over both the spec-level and ApplicationRef-level\nImagesVerification.",
"properties": {
"cosignKey": {
"description": "CosignKey references a Kubernetes Secret in the same namespace as the\nImageUpdater CR that holds the PEM-encoded ECDSA public key used to verify\ncosign signatures. Providing this field selects cosign key-based verification.",
"properties": {
"key": {
"description": "Key is the key within the Secret's data map whose value contains the credential material\n(e.g. \"cosign.pub\" for a PEM-encoded public key).",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret.",
"type": "string"
}
},
"required": [
"key",
"secretName"
],
"type": "object",
"additionalProperties": false
},
"enabled": {
"default": true,
"description": "Enabled controls whether signature verification is active at this scope.\nDefaults to true when the ImagesVerification block is present.\nSet to false to explicitly opt out of verification for this image or group.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one verification method (cosignKey) is required when verification is enabled",
"rule": "self.enabled == false || has(self.cosignKey)"
}
],
"additionalProperties": false
},
"manifestTargets": { "manifestTargets": {
"description": "ManifestTarget defines how and where to update this image in Kubernetes manifests.\nOnly one of Helm or Kustomize should be specified within this block.\nThis whole block is optional if the image update isn't written to a manifest in a structured way.", "description": "ManifestTarget defines how and where to update this image in Kubernetes manifests.\nExactly one of Helm, Kustomize, or Plugin should be specified within this block.\nThis whole block is optional if the image update isn't written to a manifest in a structured way.",
"properties": { "properties": {
"helm": { "helm": {
"description": "Helm specifies update parameters if the target manifest is managed by Helm\nand updates are to be made to Helm values files.", "description": "Helm specifies update parameters if the target manifest is managed by Helm\nand updates are to be made to Helm values files.",
@@ -151,13 +188,44 @@
], ],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
},
"plugin": {
"description": "Plugin specifies update parameters if the target manifest is managed by a Config Management Plugin.\nWhen the argocd write-back method is configured, updates will be written as environment variables\nin the Argo CD Application spec.source.plugin.env list. When the git write-back method is\nconfigured, updates will be written to the .argocd-source-<appName>.yaml file in the git repository.",
"properties": {
"name": {
"description": "Name is the environment variable name for the image repository/name part.\nExample: \"IMAGE_NAME\", \"REDIS_IMAGE_REPO\".\nIf Spec is set, this field is ignored.",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"spec": {
"description": "Spec is the environment variable name where the full image string\n(e.g., \"image/name:1.0\") should be written.\nUse this if your plugin expects the entire image reference in a single env var.\nIf this is set, Name and Tag will be ignored.",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"tag": {
"description": "Tag is the environment variable name for the image tag part.\nExample: \"IMAGE_TAG\", \"REDIS_IMAGE_VERSION\".\nIf Spec is set, this field is ignored.",
"maxLength": 253,
"minLength": 1,
"type": "string"
} }
}, },
"type": "object", "type": "object",
"x-kubernetes-validations": [ "x-kubernetes-validations": [
{ {
"message": "Exactly one of helm or kustomize must be specified within manifestTargets if the block is present.", "message": "At least one of spec or name must be specified in plugin target.",
"rule": "has(self.helm) ? !has(self.kustomize) : has(self.kustomize)" "rule": "has(self.spec) || has(self.name)"
}
],
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "Exactly one of helm, kustomize, or plugin must be specified within manifestTargets if the block is present.",
"rule": "(has(self.helm) ? 1 : 0) + (has(self.kustomize) ? 1 : 0) + (has(self.plugin) ? 1 : 0) == 1"
} }
], ],
"additionalProperties": false "additionalProperties": false
@@ -176,6 +244,43 @@
], ],
"x-kubernetes-list-type": "map" "x-kubernetes-list-type": "map"
}, },
"imagesVerification": {
"description": "ImagesVerification overrides the global signature verification policy for applications\nmatched by this ApplicationRef. When set, it takes precedence over the spec-level\nImagesVerification for all images in this group, but can still be overridden\nat the individual ImageConfig level.",
"properties": {
"cosignKey": {
"description": "CosignKey references a Kubernetes Secret in the same namespace as the\nImageUpdater CR that holds the PEM-encoded ECDSA public key used to verify\ncosign signatures. Providing this field selects cosign key-based verification.",
"properties": {
"key": {
"description": "Key is the key within the Secret's data map whose value contains the credential material\n(e.g. \"cosign.pub\" for a PEM-encoded public key).",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret.",
"type": "string"
}
},
"required": [
"key",
"secretName"
],
"type": "object",
"additionalProperties": false
},
"enabled": {
"default": true,
"description": "Enabled controls whether signature verification is active at this scope.\nDefaults to true when the ImagesVerification block is present.\nSet to false to explicitly opt out of verification for this image or group.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one verification method (cosignKey) is required when verification is enabled",
"rule": "self.enabled == false || has(self.cosignKey)"
}
],
"additionalProperties": false
},
"labelSelectors": { "labelSelectors": {
"description": "LabelSelectors indicates the label selectors to apply for application selection", "description": "LabelSelectors indicates the label selectors to apply for application selection",
"properties": { "properties": {
@@ -276,15 +381,11 @@
"additionalProperties": false "additionalProperties": false
}, },
"method": { "method": {
"default": "argocd",
"description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".", "description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".",
"pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$", "pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$",
"type": "string" "type": "string"
} }
}, },
"required": [
"method"
],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
} }
@@ -349,6 +450,43 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"imagesVerification": {
"description": "ImagesVerification defines the global default image signature verification policy.\nWhen set, every image update is subject to cryptographic verification before being\ncommitted to Git or applied to an Argo CD Application.\nCan be overridden at the ApplicationRef or ImageConfig level.",
"properties": {
"cosignKey": {
"description": "CosignKey references a Kubernetes Secret in the same namespace as the\nImageUpdater CR that holds the PEM-encoded ECDSA public key used to verify\ncosign signatures. Providing this field selects cosign key-based verification.",
"properties": {
"key": {
"description": "Key is the key within the Secret's data map whose value contains the credential material\n(e.g. \"cosign.pub\" for a PEM-encoded public key).",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret.",
"type": "string"
}
},
"required": [
"key",
"secretName"
],
"type": "object",
"additionalProperties": false
},
"enabled": {
"default": true,
"description": "Enabled controls whether signature verification is active at this scope.\nDefaults to true when the ImagesVerification block is present.\nSet to false to explicitly opt out of verification for this image or group.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one verification method (cosignKey) is required when verification is enabled",
"rule": "self.enabled == false || has(self.cosignKey)"
}
],
"additionalProperties": false
},
"writeBackConfig": { "writeBackConfig": {
"description": "WriteBackConfig provides global default settings for how and where to write back image updates.\nThis can be overridden at the ApplicationRef level.", "description": "WriteBackConfig provides global default settings for how and where to write back image updates.\nThis can be overridden at the ApplicationRef level.",
"properties": { "properties": {
@@ -393,15 +531,11 @@
"additionalProperties": false "additionalProperties": false
}, },
"method": { "method": {
"default": "argocd",
"description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".", "description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".",
"pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$", "pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$",
"type": "string" "type": "string"
} }
}, },
"required": [
"method"
],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
} }
@@ -589,6 +589,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -1044,6 +1048,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -1639,6 +1647,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -2119,6 +2131,10 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"description": "RepoURL is the URL to the git repository that contains the hydrated manifests. If not set, defaults to\nthe DrySource.RepoURL.",
"type": "string"
},
"targetBranch": { "targetBranch": {
"description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.", "description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.",
"type": "string" "type": "string"
@@ -2583,6 +2599,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -3239,6 +3259,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -3694,6 +3718,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -4311,6 +4339,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -4766,6 +4798,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -5377,6 +5413,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -5832,6 +5872,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -6443,6 +6487,10 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"description": "RepoURL is the URL to the git repository that contains the hydrated manifests. If not set, defaults to\nthe DrySource.RepoURL.",
"type": "string"
},
"targetBranch": { "targetBranch": {
"description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.", "description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.",
"type": "string" "type": "string"
@@ -6476,6 +6524,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastComparedDryRevision": {
"description": "LastComparedDryRevision holds the resolved revision from the most recent dry source comparison.\nThis is updated on every evaluation, even when hydration is skipped due to no changes.",
"type": "string"
},
"lastSuccessfulOperation": { "lastSuccessfulOperation": {
"description": "LastSuccessfulOperation holds info about the most recent successful hydration", "description": "LastSuccessfulOperation holds info about the most recent successful hydration",
"properties": { "properties": {
@@ -6956,6 +7008,10 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"description": "RepoURL is the URL to the git repository that contains the hydrated manifests. If not set, defaults to\nthe DrySource.RepoURL.",
"type": "string"
},
"targetBranch": { "targetBranch": {
"description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.", "description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.",
"type": "string" "type": "string"
@@ -7012,6 +7068,10 @@
"type": "string" "type": "string"
}, },
"type": "array" "type": "array"
},
"isAppOfApps": {
"description": "IsAppOfApps holds true if the application has any application for child resource.",
"type": "boolean"
} }
}, },
"type": "object", "type": "object",
@@ -7529,6 +7589,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -7984,6 +8048,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -558,6 +558,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -964,6 +967,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -1356,6 +1362,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -2008,6 +2017,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -2414,6 +2426,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -2806,6 +2821,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -3461,6 +3479,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -3867,6 +3888,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -4259,6 +4283,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -4878,6 +4905,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -5284,6 +5314,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -5676,6 +5709,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -6331,6 +6367,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -6737,6 +6776,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -7129,6 +7171,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -7781,6 +7826,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -8187,6 +8235,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -8579,6 +8630,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -9234,6 +9288,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -9640,6 +9697,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -10032,6 +10092,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -10651,6 +10714,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -11057,6 +11123,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -11449,6 +11518,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -12083,6 +12155,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -12489,6 +12564,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -12881,6 +12959,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -13874,6 +13955,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -14280,6 +14364,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -14672,6 +14759,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -15030,6 +15120,9 @@
"api": { "api": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"insecure": { "insecure": {
"type": "boolean" "type": "boolean"
}, },
@@ -15071,6 +15164,9 @@
"appSecretName": { "appSecretName": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"organization": { "organization": {
"type": "string" "type": "string"
}, },
@@ -15124,6 +15220,9 @@
"group": { "group": {
"type": "string" "type": "string"
}, },
"includeArchivedRepos": {
"type": "boolean"
},
"includeSharedProjects": { "includeSharedProjects": {
"type": "boolean" "type": "boolean"
}, },
@@ -15652,6 +15751,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -16058,6 +16160,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -16450,6 +16555,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -17100,6 +17208,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -17506,6 +17617,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -17898,6 +18012,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -18556,6 +18673,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -18962,6 +19082,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -19354,6 +19477,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -20006,6 +20132,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -20412,6 +20541,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -20804,6 +20936,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -21459,6 +21594,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -21865,6 +22003,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -22257,6 +22398,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -22876,6 +23020,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -23282,6 +23429,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -23674,6 +23824,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -24308,6 +24461,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -24714,6 +24870,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -25106,6 +25265,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -26099,6 +26261,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -26505,6 +26670,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -26897,6 +27065,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -27255,6 +27426,9 @@
"api": { "api": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"insecure": { "insecure": {
"type": "boolean" "type": "boolean"
}, },
@@ -27296,6 +27470,9 @@
"appSecretName": { "appSecretName": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"organization": { "organization": {
"type": "string" "type": "string"
}, },
@@ -27349,6 +27526,9 @@
"group": { "group": {
"type": "string" "type": "string"
}, },
"includeArchivedRepos": {
"type": "boolean"
},
"includeSharedProjects": { "includeSharedProjects": {
"type": "boolean" "type": "boolean"
}, },
@@ -27877,6 +28057,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -28283,6 +28466,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -28675,6 +28861,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -29331,6 +29520,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -29737,6 +29929,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -30129,6 +30324,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -30761,6 +30959,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -31167,6 +31368,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -31559,6 +31763,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -32552,6 +32759,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -32958,6 +33168,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -33350,6 +33563,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -33708,6 +33924,9 @@
"api": { "api": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"insecure": { "insecure": {
"type": "boolean" "type": "boolean"
}, },
@@ -33749,6 +33968,9 @@
"appSecretName": { "appSecretName": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"organization": { "organization": {
"type": "string" "type": "string"
}, },
@@ -33802,6 +34024,9 @@
"group": { "group": {
"type": "string" "type": "string"
}, },
"includeArchivedRepos": {
"type": "boolean"
},
"includeSharedProjects": { "includeSharedProjects": {
"type": "boolean" "type": "boolean"
}, },
@@ -34330,6 +34555,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -34736,6 +34964,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -35128,6 +35359,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -35906,6 +36140,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -36312,6 +36549,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -36704,6 +36944,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -259,9 +259,9 @@
"type": "array" "type": "array"
}, },
"signatureKeys": { "signatureKeys": {
"description": "SignatureKeys contains a list of PGP key IDs that commits in Git must be signed with in order to be allowed for sync", "description": "SignatureKeys contains a list of PGP key IDs that commits in Git must be signed with in order to be allowed for sync\n\nDeprecated: Use SourceIntegrity instead. SignatureKeys will be removed with the next major version.",
"items": { "items": {
"description": "SignatureKey is the specification of a key required to verify commit signatures with", "description": "SignatureKey is the specification of a key required to verify commit signatures with\n\nDeprecated: Use SourceIntegrity instead. SignatureKeys will be removed with the next major version.",
"properties": { "properties": {
"keyID": { "keyID": {
"description": "The ID of the key in hexadecimal notation", "description": "The ID of the key in hexadecimal notation",
@@ -276,6 +276,77 @@
}, },
"type": "array" "type": "array"
}, },
"sourceIntegrity": {
"description": "SourceIntegrity represents a constraint on manifest sources integrity to be met before they can be used.\nDo not access directly, use EffectiveSourceIntegrity() for correct backwards compatibility handling.",
"properties": {
"git": {
"description": "Git - policies for git source verification",
"properties": {
"policies": {
"items": {
"properties": {
"gpg": {
"description": "Verify GPG commit/tag signatures",
"properties": {
"keys": {
"description": "List of key IDs to trust. The keys need to be in the repository server keyring.",
"items": {
"type": "string"
},
"type": "array"
},
"mode": {
"type": "string"
}
},
"required": [
"keys",
"mode"
],
"type": "object",
"additionalProperties": false
},
"repos": {
"description": "List of repository criteria restricting repositories the policy will apply to",
"items": {
"properties": {
"url": {
"description": "URL specifier, glob.",
"type": "string"
}
},
"required": [
"url"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"gpg",
"repos"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"policies"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"git"
],
"type": "object",
"additionalProperties": false
},
"sourceNamespaces": { "sourceNamespaces": {
"description": "SourceNamespaces defines the namespaces application resources are allowed to be created in", "description": "SourceNamespaces defines the namespaces application resources are allowed to be created in",
"items": { "items": {
@@ -340,6 +411,10 @@
"description": "Schedule is the time the window will begin, specified in cron format", "description": "Schedule is the time the window will begin, specified in cron format",
"type": "string" "type": "string"
}, },
"syncOverrun": {
"description": "SyncOverrun allows ongoing syncs to continue in two scenarios:\nFor deny windows: allows syncs that started before the deny window became active to continue running\nFor allow windows: allows syncs that started during the allow window to continue after the window ends",
"type": "boolean"
},
"timeZone": { "timeZone": {
"description": "TimeZone of the sync that will be applied to the schedule", "description": "TimeZone of the sync that will be applied to the schedule",
"type": "string" "type": "string"
@@ -0,0 +1,392 @@
{
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"properties": {
"destinationCIDRs": {
"description": "DestinationCIDRs is a list of destination CIDRs for destination IP addresses.\nIf a destination IP matches any one CIDR, it will be selected.",
"items": {
"pattern": "^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]|[1-2][0-9]|3[0-2])$|^s*((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:)))(%.+)?s*(\\/(12[0-8]|1[0-1][0-9]|[1-9][0-9]|[0-9]))$",
"type": "string"
},
"type": "array"
},
"egressGateway": {
"description": "EgressGateway is the gateway node responsible for SNATing traffic.\nIn case multiple nodes are a match for the given set of labels, the first node\nin lexical ordering based on their name will be selected.",
"properties": {
"egressIP": {
"description": "EgressIP is the source IP address that the egress traffic is SNATed\nwith.\n\nExample:\nWhen set to \"192.168.1.100\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IP address 192.168.1.100.\n\nWhen set to \"2001:db8::1\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IPv6 address 2001:db8::1.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"maxLength": 39,
"type": "string",
"x-kubernetes-validations": [
{
"message": "egressIP must be a valid IP address",
"rule": "self == '' || isIP(self)"
}
]
},
"interface": {
"description": "Interface is the network interface to which the egress IP address\nthat the traffic is SNATed with is assigned.\n\nExample:\nWhen set to \"eth1\", matching egress traffic will be redirected to the\nnode matching the NodeSelector field and SNATed with the first IPv4\naddress assigned to the eth1 interface.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"type": "string"
},
"nodeSelector": {
"description": "This is a label selector which selects the node that should act as\negress gateway for the given policy.\nIn case multiple nodes are selected, only the first one in the\nlexical ordering over the node names will be used.\nThis field follows standard label selector semantics.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"required": [
"nodeSelector"
],
"type": "object",
"additionalProperties": false
},
"egressGateways": {
"default": [],
"description": "Optional list of gateway nodes responsible for SNATing traffic.\nIf this field has any entries the contents of the egressGateway field will be ignored.\nIn case multiple nodes are a match for the given set of labels in each entry,\nthe first node in lexical ordering based on their name will be selected for each entry.",
"items": {
"description": "EgressGateway identifies the node that should act as egress gateway for a\ngiven egress Gateway policy. In addition to that it also specifies the\nconfiguration of said node (which egress IP or network interface should be\nused to SNAT traffic).",
"properties": {
"egressIP": {
"description": "EgressIP is the source IP address that the egress traffic is SNATed\nwith.\n\nExample:\nWhen set to \"192.168.1.100\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IP address 192.168.1.100.\n\nWhen set to \"2001:db8::1\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IPv6 address 2001:db8::1.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"maxLength": 39,
"type": "string",
"x-kubernetes-validations": [
{
"message": "egressIP must be a valid IP address",
"rule": "self == '' || isIP(self)"
}
]
},
"interface": {
"description": "Interface is the network interface to which the egress IP address\nthat the traffic is SNATed with is assigned.\n\nExample:\nWhen set to \"eth1\", matching egress traffic will be redirected to the\nnode matching the NodeSelector field and SNATed with the first IPv4\naddress assigned to the eth1 interface.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"type": "string"
},
"nodeSelector": {
"description": "This is a label selector which selects the node that should act as\negress gateway for the given policy.\nIn case multiple nodes are selected, only the first one in the\nlexical ordering over the node names will be used.\nThis field follows standard label selector semantics.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"required": [
"nodeSelector"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 64,
"type": "array"
},
"excludedCIDRs": {
"description": "ExcludedCIDRs is a list of destination CIDRs that will be excluded\nfrom the egress gateway redirection and SNAT logic.\nShould be a subset of destinationCIDRs otherwise it will not have any\neffect.",
"items": {
"pattern": "^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]|[1-2][0-9]|3[0-2])$|^s*((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:)))(%.+)?s*(\\/(12[0-8]|1[0-1][0-9]|[1-9][0-9]|[0-9]))$",
"type": "string"
},
"type": "array"
},
"selectors": {
"description": "Egress represents a list of rules by which egress traffic is\nfiltered from the source pods.",
"items": {
"properties": {
"namespaceSelector": {
"description": "Selects Namespaces using cluster-scoped labels. This field follows standard label\nselector semantics; if present but empty, it selects all namespaces.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"nodeSelector": {
"description": "This is a label selector which selects Pods by Node. This field follows standard label\nselector semantics; if present but empty, it selects all nodes.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"podSelector": {
"description": "This is a label selector which selects Pods. This field follows standard label\nselector semantics; if present but empty, it selects all pods.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"destinationCIDRs",
"egressGateway",
"selectors"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"metadata"
],
"type": "object"
}
+7 -1
View File
@@ -211,7 +211,13 @@
"refreshInterval": { "refreshInterval": {
"description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.", "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
"format": "duration", "format": "duration",
"type": "string" "type": "string",
"x-kubernetes-validations": [
{
"message": "must be at least 1m",
"rule": "self >= duration('1m')"
}
]
}, },
"url": { "url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.", "description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
@@ -184,6 +184,10 @@
], ],
"additionalProperties": false "additionalProperties": false
}, },
"keyless": {
"description": "Keyless configures keyless authentication.",
"type": "object"
},
"ldap": { "ldap": {
"description": "LDAP configures LDAP authentication.", "description": "LDAP configures LDAP authentication.",
"properties": { "properties": {
@@ -247,7 +251,7 @@
"x-kubernetes-validations": [ "x-kubernetes-validations": [
{ {
"message": "exactly one authentication method must be specified", "message": "exactly one authentication method must be specified",
"rule": "[has(self.apiKey), has(self.jwt), has(self.ldap)].filter(x, x).size() == 1" "rule": "[has(self.apiKey), has(self.jwt), has(self.ldap), has(self.keyless)].filter(x, x).size() == 1"
} }
], ],
"additionalProperties": false "additionalProperties": false
@@ -151,6 +151,14 @@
"description": "Lastname is the JWT claim for user last name.", "description": "Lastname is the JWT claim for user last name.",
"type": "string" "type": "string"
}, },
"organizationId": {
"description": "OrganizationID is the JWT claim for the ID of the organization the user belongs to.",
"type": "string"
},
"organizationName": {
"description": "OrganizationName is the JWT claim for the name of the organization the user belongs to.",
"type": "string"
},
"userId": { "userId": {
"description": "UserID is the JWT claim for user ID mapping.", "description": "UserID is the JWT claim for user ID mapping.",
"type": "string" "type": "string"
@@ -211,7 +211,13 @@
"refreshInterval": { "refreshInterval": {
"description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.", "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
"format": "duration", "format": "duration",
"type": "string" "type": "string",
"x-kubernetes-validations": [
{
"message": "must be at least 1m",
"rule": "self >= duration('1m')"
}
]
}, },
"url": { "url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.", "description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
@@ -153,6 +153,53 @@
"description": "Claims specifies an expression that validate claims in order to authorize the request.", "description": "Claims specifies an expression that validate claims in order to authorize the request.",
"type": "string" "type": "string"
}, },
"managedApplicationSelector": {
"description": "ManagedApplicationSelector selects the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.\nThis field is optional and follows standard label selector semantics.\nAn empty ManagedApplicationSelector matches any ManagedApplication.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"managedApplications": { "managedApplications": {
"description": "ManagedApplications references the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.", "description": "ManagedApplications references the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.",
"items": { "items": {
@@ -292,6 +339,24 @@
}, },
"type": "array" "type": "array"
}, },
"resolvedManagedApplications": {
"description": "ResolvedManagedApplications is the list of ManagedApplications that were successfully resolved.",
"items": {
"description": "ResolvedManagedApplicationReference references a resolved ManagedApplication.",
"properties": {
"name": {
"description": "Name of the ManagedApplication.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"syncedAt": { "syncedAt": {
"format": "date-time", "format": "date-time",
"type": "string" "type": "string"
@@ -314,6 +379,24 @@
}, },
"type": "array" "type": "array"
}, },
"unresolvedManagedApplications": {
"description": "UnresolvedManagedApplications is the list of ManagedApplications that could not be resolved.",
"items": {
"description": "ResolvedManagedApplicationReference references a resolved ManagedApplication.",
"properties": {
"name": {
"description": "Name of the ManagedApplication.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"version": { "version": {
"type": "string" "type": "string"
} }
@@ -24,6 +24,8 @@
}, },
"exposeName": { "exposeName": {
"description": "ExposeName is the name of the service to expose.\nBy default it uses <namespace>-<name>.", "description": "ExposeName is the name of the service to expose.\nBy default it uses <namespace>-<name>.",
"maxLength": 253,
"pattern": "^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$",
"type": "string" "type": "string"
}, },
"healthCheck": { "healthCheck": {
@@ -30,7 +30,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak RealmRepresentation", "description": "Definition contains the Keycloak RealmRepresentation. Set the realm name\nvia spec.realmName.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -54,7 +54,8 @@
"additionalProperties": false "additionalProperties": false
}, },
"realmName": { "realmName": {
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)", "description": "RealmName is the name of the realm in Keycloak. It is immutable once set:\nrenaming a realm in Keycloak is destructive and would orphan it.",
"minLength": 1,
"type": "string" "type": "string"
}, },
"smtpSecretRef": { "smtpSecretRef": {
@@ -88,9 +89,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"realmName"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of instanceRef or clusterInstanceRef must be set",
"rule": "has(self.instanceRef) != has(self.clusterInstanceRef)"
},
{
"message": "spec.realmName is immutable once set",
"rule": "!has(oldSelf.realmName) || self.realmName == oldSelf.realmName"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -167,6 +179,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after SMTP credential merging). Keycloak masks\nsmtpServer.password on read, so this is the only way to detect that\nthe desired password changed and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
@@ -53,10 +53,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -71,6 +67,12 @@
"providerId" "providerId"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -16,7 +16,8 @@
"description": "KeycloakClientSpec defines the desired state of KeycloakClient", "description": "KeycloakClientSpec defines the desired state of KeycloakClient",
"properties": { "properties": {
"clientId": { "clientId": {
"description": "ClientId is the client ID in Keycloak (defaults to metadata.name)", "description": "ClientId is the client ID in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string" "type": "string"
}, },
"clientSecretRef": { "clientSecretRef": {
@@ -61,7 +62,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak ClientRepresentation", "description": "Definition contains the Keycloak ClientRepresentation. Set the client ID\nvia spec.clientId.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -71,10 +72,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -84,12 +81,29 @@
"additionalProperties": false "additionalProperties": false
} }
}, },
"required": [
"clientId"
],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.clientId is immutable once set",
"rule": "!has(oldSelf.clientId) || self.clientId == oldSelf.clientId"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
"description": "KeycloakClientStatus defines the observed state of KeycloakClient", "description": "KeycloakClientStatus defines the observed state of KeycloakClient",
"properties": { "properties": {
"clientId": {
"description": "ClientID is the resolved client ID (clientId) in Keycloak",
"type": "string"
},
"clientUUID": { "clientUUID": {
"description": "ClientUUID is the Keycloak internal ID", "description": "ClientUUID is the Keycloak internal ID",
"type": "string" "type": "string"
@@ -30,20 +30,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak ClientScopeRepresentation", "description": "Definition contains the Keycloak ClientScopeRepresentation. Set the client\nscope name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the client scope name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,14 +55,29 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
"description": "KeycloakClientScopeStatus defines the observed state of KeycloakClientScope", "description": "KeycloakClientScopeStatus defines the observed state of KeycloakClientScope",
"properties": { "properties": {
"clientScopeName": {
"description": "ClientScopeName is the resolved client scope name in Keycloak",
"type": "string"
},
"conditions": { "conditions": {
"description": "Conditions represent the latest available observations", "description": "Conditions represent the latest available observations",
"items": { "items": {
@@ -29,21 +29,36 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Each secret\nvalue is wrapped as a single-element list to match ComponentRepresentation\nconfig (map[string][]string). Secret values take precedence over values\nspecified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"definition": { "definition": {
"description": "Definition contains the Keycloak ComponentRepresentation", "description": "Definition contains the Keycloak ComponentRepresentation. Set the component\nname via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the component name in Keycloak. Immutable once set. The\nproviderType is set in spec.definition.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,9 +69,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -141,6 +167,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks secret config values\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
@@ -16,7 +16,7 @@
"description": "KeycloakGroupSpec defines the desired state of KeycloakGroup", "description": "KeycloakGroupSpec defines the desired state of KeycloakGroup",
"properties": { "properties": {
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for top-level groups\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the cluster-scoped resource", "description": "Name of the cluster-scoped resource",
@@ -30,20 +30,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak GroupRepresentation", "description": "Definition contains the Keycloak GroupRepresentation. Set the group name\nvia spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the group name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"parentGroupRef": { "parentGroupRef": {
"description": "ParentGroupRef is a reference to a parent KeycloakGroup (for nested groups)", "description": "ParentGroupRef is a reference to a parent KeycloakGroup for nested groups.\nThe realm is derived from the parent chain, so realmRef and clusterRealmRef\nmust not be set alongside it.\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -53,15 +54,11 @@
"additionalProperties": false "additionalProperties": false
}, },
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm for top-level groups\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -72,9 +69,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or parentGroupRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.parentGroupRef) ? 1 : 0) == 1"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -140,6 +148,10 @@
"description": "GroupID is the Keycloak internal group ID", "description": "GroupID is the Keycloak internal group ID",
"type": "string" "type": "string"
}, },
"groupName": {
"description": "GroupName is the resolved group name in Keycloak",
"type": "string"
},
"instance": { "instance": {
"description": "Instance contains the resolved instance reference", "description": "Instance contains the resolved instance reference",
"properties": { "properties": {
@@ -15,6 +15,11 @@
"spec": { "spec": {
"description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider", "description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider",
"properties": { "properties": {
"alias": {
"description": "Alias is the identity provider alias in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
@@ -33,7 +38,7 @@
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.", "description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the Kubernetes Secret", "description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string" "type": "string"
} }
}, },
@@ -44,20 +49,30 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak IdentityProviderRepresentation", "description": "Definition contains the Keycloak IdentityProviderRepresentation. Set the\nalias via spec.alias.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"organizationRef": {
"description": "OrganizationRef references a KeycloakOrganization in the same namespace.\nThe organization's status.organizationID is injected as organizationId\non the identity provider. Requires Keycloak 26 or later. Do not set\norganizationId in definition; use this field instead.",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -85,14 +100,29 @@
} }
}, },
"required": [ "required": [
"alias",
"definition" "definition"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.alias is immutable once set",
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
"description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider", "description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider",
"properties": { "properties": {
"alias": {
"description": "Alias is the resolved identity provider alias in Keycloak",
"type": "string"
},
"conditions": { "conditions": {
"description": "Conditions represent the latest available observations", "description": "Conditions represent the latest available observations",
"items": { "items": {
@@ -164,10 +194,18 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks config.clientSecret\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
}, },
"organizationID": {
"description": "OrganizationID is the resolved Keycloak organization ID when\nspec.organizationRef is set.",
"type": "string"
},
"ready": { "ready": {
"description": "Ready indicates if the identity provider is ready", "description": "Ready indicates if the identity provider is ready",
"type": "boolean" "type": "boolean"
@@ -15,8 +15,22 @@
"spec": { "spec": {
"description": "KeycloakIdentityProviderMapperSpec defines the desired state of KeycloakIdentityProviderMapper", "description": "KeycloakIdentityProviderMapperSpec defines the desired state of KeycloakIdentityProviderMapper",
"properties": { "properties": {
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"definition": { "definition": {
"description": "Definition contains the Keycloak IdentityProviderMapperRepresentation.\nThe identityProviderAlias field is auto-injected from the parent\nKeycloakIdentityProvider at reconcile time and does not need to be set\nhere.", "description": "Definition contains the Keycloak IdentityProviderMapperRepresentation. The\nidentityProviderAlias field is injected from the parent KeycloakIdentityProvider\nat reconcile time. Set the mapper name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -26,10 +40,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -37,13 +47,25 @@
], ],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
},
"name": {
"description": "Name is the mapper name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
} }
}, },
"required": [ "required": [
"definition", "definition",
"identityProviderRef" "identityProviderRef",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -30,20 +30,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak OrganizationRepresentation", "description": "Definition contains the Keycloak OrganizationRepresentation. Set the\norganization name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the organization name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,9 +55,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -146,6 +158,10 @@
"description": "OrganizationID is the Keycloak internal organization ID", "description": "OrganizationID is the Keycloak internal organization ID",
"type": "string" "type": "string"
}, },
"organizationName": {
"description": "OrganizationName is the resolved organization name in Keycloak",
"type": "string"
},
"ready": { "ready": {
"description": "Ready indicates if the organization is ready", "description": "Ready indicates if the organization is ready",
"type": "boolean" "type": "boolean"
@@ -21,10 +21,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -39,9 +35,19 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
}
}, },
"namespace": { "required": [
"description": "Namespace of the resource (optional, defaults to the same namespace)", "name"
],
"type": "object",
"additionalProperties": false
},
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string" "type": "string"
} }
}, },
@@ -52,15 +58,31 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak ProtocolMapperRepresentation", "description": "Definition contains the Keycloak ProtocolMapperRepresentation. Set the\nmapper name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
},
"name": {
"description": "Name is the protocol mapper name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of clientRef or clientScopeRef must be set",
"rule": "has(self.clientRef) != has(self.clientScopeRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -30,7 +30,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak RealmRepresentation", "description": "Definition contains the Keycloak RealmRepresentation. Set the realm name\nvia spec.realmName.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -40,10 +40,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -53,7 +49,8 @@
"additionalProperties": false "additionalProperties": false
}, },
"realmName": { "realmName": {
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)", "description": "RealmName is the name of the realm in Keycloak. It is immutable once set:\nrenaming a realm in Keycloak is destructive and would orphan it.",
"minLength": 1,
"type": "string" "type": "string"
}, },
"smtpSecretRef": { "smtpSecretRef": {
@@ -82,9 +79,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"realmName"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of instanceRef or clusterInstanceRef must be set",
"rule": "has(self.instanceRef) != has(self.clusterInstanceRef)"
},
{
"message": "spec.realmName is immutable once set",
"rule": "!has(oldSelf.realmName) || self.realmName == oldSelf.realmName"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -161,6 +169,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after SMTP credential merging). Keycloak masks\nsmtpServer.password on read, so this is the only way to detect that\nthe desired password changed and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
@@ -169,6 +181,10 @@
"description": "Ready indicates if the realm is ready", "description": "Ready indicates if the realm is ready",
"type": "boolean" "type": "boolean"
}, },
"realmName": {
"description": "RealmName is the resolved realm name in Keycloak",
"type": "string"
},
"resourcePath": { "resourcePath": {
"description": "ResourcePath is the Keycloak API path for this realm", "description": "ResourcePath is the Keycloak API path for this realm",
"type": "string" "type": "string"
@@ -15,6 +15,11 @@
"spec": { "spec": {
"description": "KeycloakRequiredActionSpec defines the desired state of KeycloakRequiredAction", "description": "KeycloakRequiredActionSpec defines the desired state of KeycloakRequiredAction",
"properties": { "properties": {
"alias": {
"description": "Alias is the required action alias in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
@@ -29,8 +34,22 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"definition": { "definition": {
"description": "Definition contains the Keycloak RequiredActionProviderRepresentation", "description": "Definition contains the Keycloak RequiredActionProviderRepresentation. Set\nthe alias via spec.alias.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -40,10 +59,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,9 +69,20 @@
} }
}, },
"required": [ "required": [
"alias",
"definition" "definition"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.alias is immutable once set",
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -16,15 +16,11 @@
"description": "KeycloakRoleSpec defines the desired state of KeycloakRole", "description": "KeycloakRoleSpec defines the desired state of KeycloakRole",
"properties": { "properties": {
"clientRef": { "clientRef": {
"description": "ClientRef is a reference to a KeycloakClient for client-level roles\nIf not specified, the role is a realm-level role", "description": "ClientRef is a reference to a KeycloakClient for client-level roles.\nThe realm is derived from the referenced client, so realmRef and\nclusterRealmRef must not be set alongside it.\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -34,7 +30,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the cluster-scoped resource", "description": "Name of the cluster-scoped resource",
@@ -48,20 +44,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak RoleRepresentation", "description": "Definition contains the Keycloak RoleRepresentation. Set the role name via\nspec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the role name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -72,9 +69,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -28,10 +28,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -49,6 +45,12 @@
"name" "name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "at most one of clientRef or clientId may be set",
"rule": "!(has(self.clientRef) && has(self.clientId))"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"roleRef": { "roleRef": {
@@ -57,10 +59,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -78,9 +76,19 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
}
}, },
"namespace": { "required": [
"description": "Namespace of the resource (optional, defaults to the same namespace)", "name"
],
"type": "object",
"additionalProperties": false
},
"serviceAccountRef": {
"description": "ServiceAccountRef references a KeycloakClient to assign roles to its\nauto-created service account user. This avoids needing an intermediate\nKeycloakUser CR for clients with serviceAccountsEnabled: true.",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string" "type": "string"
} }
}, },
@@ -96,10 +104,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -110,6 +114,12 @@
} }
}, },
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of userRef, groupRef, or serviceAccountRef must be set",
"rule": "(has(self.userRef) ? 1 : 0) + (has(self.groupRef) ? 1 : 0) + (has(self.serviceAccountRef) ? 1 : 0) == 1"
}
],
"additionalProperties": false "additionalProperties": false
} }
}, },
@@ -117,6 +127,12 @@
"subject" "subject"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of role or roleRef must be set",
"rule": "has(self.role) != has(self.roleRef)"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -21,10 +21,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -33,6 +29,16 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"clientRoles": {
"additionalProperties": {
"items": {
"type": "string"
},
"type": "array"
},
"description": "ClientRoles maps a client's clientId to the authoritative set of\nclient-level role names for this user. When omitted, client roles are not\nmanaged; when set, roles on clients absent from the map are removed.\nDo not combine with KeycloakRoleMapping resources targeting the same user.",
"type": "object"
},
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users with cluster-scoped realms", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users with cluster-scoped realms",
"properties": { "properties": {
@@ -48,12 +54,19 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak UserRepresentation", "description": "Definition contains the Keycloak UserRepresentation. Set the username via\nspec.username; role and group assignments go in spec.realmRoles,\nspec.clientRoles, and spec.groups.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"groups": {
"description": "Groups is the authoritative set of group names this user belongs to,\nreconciled via the Keycloak group-membership endpoints. When omitted,\ngroup memberships are not managed; an empty list removes all memberships.",
"items": {
"type": "string"
},
"type": "array"
},
"initialPassword": { "initialPassword": {
"description": "InitialPassword sets the initial password for the user (only on creation)", "description": "InitialPassword sets the initial password for the user (only on creation).\nFor managed credentials stored in a Kubernetes secret, use KeycloakUserCredential.",
"properties": { "properties": {
"temporary": { "temporary": {
"description": "Temporary indicates if the user must change password on first login", "description": "Temporary indicates if the user must change password on first login",
@@ -76,10 +89,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -88,34 +97,34 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"userSecret": { "realmRoles": {
"description": "UserSecret configures where to store user credentials", "description": "RealmRoles is the authoritative set of realm-level role names for this\nuser, reconciled via the Keycloak role-mapping endpoints. When omitted,\nrealm roles are not managed; an empty list removes all realm roles.\nPointer types so an explicit empty value survives JSON round-trips.\nDo not combine with KeycloakRoleMapping resources targeting the same user.",
"properties": { "items": {
"generatePassword": {
"description": "GeneratePassword indicates whether to generate a password",
"type": "boolean"
},
"passwordKey": {
"description": "PasswordKey is the key for the password (defaults to \"password\")",
"type": "string" "type": "string"
}, },
"secretName": { "type": "array"
"description": "SecretName is the name of the Kubernetes secret to create",
"type": "string"
}, },
"usernameKey": { "username": {
"description": "UsernameKey is the key for the username in the secret (defaults to \"username\")", "description": "Username is the username in Keycloak. Required for regular realm users;\nomit it for service account users, which are identified by clientRef and\nwhose username is derived by Keycloak. Immutable once set.",
"minLength": 1,
"type": "string" "type": "string"
} }
}, },
"required": [ "type": "object",
"secretName" "x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
},
{
"message": "spec.username is required unless spec.clientRef is set (service account user)",
"rule": "has(self.clientRef) || (has(self.username) && size(self.username) > 0)"
},
{
"message": "spec.username is immutable once set",
"rule": "!has(oldSelf.username) || (has(self.username) && self.username == oldSelf.username)"
}
], ],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -239,6 +248,10 @@
"userID": { "userID": {
"description": "UserID is the Keycloak internal user ID", "description": "UserID is the Keycloak internal user ID",
"type": "string" "type": "string"
},
"username": {
"description": "Username is the resolved username in Keycloak",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -21,10 +21,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -1090,7 +1090,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1231,7 +1231,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1286,7 +1286,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1455,7 +1455,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1510,7 +1510,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1909,7 +1909,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1964,7 +1964,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2191,7 +2191,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2266,6 +2266,11 @@
"description": "clusterLabel defines the identifier that uniquely identifies the Alertmanager cluster.\nYou should only set it when the Alertmanager cluster includes Alertmanager instances which are external to this Alertmanager resource. In practice, the addresses of the external instances are provided via the `.spec.additionalPeers` field.", "description": "clusterLabel defines the identifier that uniquely identifies the Alertmanager cluster.\nYou should only set it when the Alertmanager cluster includes Alertmanager instances which are external to this Alertmanager resource. In practice, the addresses of the external instances are provided via the `.spec.additionalPeers` field.",
"type": "string" "type": "string"
}, },
"clusterPeerName": {
"description": "clusterPeerName defines the name that this Alertmanager instance uses to\nadvertise itself to other cluster peers (the `--cluster.peer-name` flag,\navailable since Alertmanager v0.30.0).\n\nIf not set, the operator defaults to the pod's name (`$(POD_NAME)`),\nwhich is injected via the Kubernetes downward API. Setting this field\nlets you override that default with either a literal value or a string\nreferencing environment variables that are already available in the\nAlertmanager container (for example `$(POD_NAME).$(NAMESPACE)`).\n\n/ It requires Alertmanager >= 0.30.0.",
"minLength": 1,
"type": "string"
},
"clusterPeerTimeout": { "clusterPeerTimeout": {
"description": "clusterPeerTimeout defines the timeout for cluster peering.", "description": "clusterPeerTimeout defines the timeout for cluster peering.",
"pattern": "^(0|(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$", "pattern": "^(0|(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
@@ -2289,7 +2294,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2344,7 +2349,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2458,7 +2463,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2524,7 +2529,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2691,7 +2696,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2959,6 +2964,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3080,6 +3089,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3170,6 +3183,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3234,6 +3251,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3372,6 +3393,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3436,6 +3461,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3807,6 +3836,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3871,6 +3904,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3989,8 +4026,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -4235,7 +4280,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4503,6 +4548,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4624,6 +4673,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4714,6 +4767,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4778,6 +4835,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4916,6 +4977,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4980,6 +5045,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -5351,6 +5420,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -5415,6 +5488,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -5533,8 +5610,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -5841,7 +5926,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -5976,6 +6061,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -6015,7 +6105,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6039,7 +6129,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6230,7 +6320,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6254,7 +6344,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6487,6 +6577,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -6712,8 +6851,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -6932,6 +7079,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -6949,6 +7101,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7025,6 +7182,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -7089,6 +7251,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7111,6 +7278,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -7150,7 +7322,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7174,7 +7346,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7679,6 +7851,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -7749,6 +7926,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7777,6 +7959,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7870,6 +8057,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7913,6 +8105,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -7948,6 +8145,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7989,6 +8191,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8173,6 +8380,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -8190,6 +8402,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8357,7 +8574,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8423,7 +8640,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -401,7 +401,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -542,7 +542,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -597,7 +597,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -770,7 +770,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -825,7 +825,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1112,7 +1112,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1167,7 +1167,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1427,7 +1427,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1568,7 +1568,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1623,7 +1623,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1796,7 +1796,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1851,7 +1851,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2153,7 +2153,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2294,7 +2294,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2349,7 +2349,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2522,7 +2522,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2577,7 +2577,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2948,7 +2948,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3089,7 +3089,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3144,7 +3144,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3317,7 +3317,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3372,7 +3372,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3760,7 +3760,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3901,7 +3901,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3956,7 +3956,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4129,7 +4129,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4184,7 +4184,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4576,7 +4576,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4717,7 +4717,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4772,7 +4772,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4945,7 +4945,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5000,7 +5000,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5438,7 +5438,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5579,7 +5579,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5634,7 +5634,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5807,7 +5807,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5862,7 +5862,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6368,7 +6368,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6509,7 +6509,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6564,7 +6564,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6737,7 +6737,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6792,7 +6792,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7139,7 +7139,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7280,7 +7280,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7335,7 +7335,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7508,7 +7508,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7563,7 +7563,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7713,7 +7713,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -7979,7 +7979,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8120,7 +8120,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8175,7 +8175,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8348,7 +8348,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8403,7 +8403,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8746,7 +8746,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8887,7 +8887,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8942,7 +8942,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9115,7 +9115,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9170,7 +9170,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9461,7 +9461,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9602,7 +9602,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9657,7 +9657,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9830,7 +9830,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9885,7 +9885,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10160,7 +10160,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10301,7 +10301,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10356,7 +10356,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10529,7 +10529,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10584,7 +10584,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10930,7 +10930,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11071,7 +11071,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11126,7 +11126,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11299,7 +11299,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11354,7 +11354,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -211,7 +211,13 @@
"refreshInterval": { "refreshInterval": {
"description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.", "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
"format": "duration", "format": "duration",
"type": "string" "type": "string",
"x-kubernetes-validations": [
{
"message": "must be at least 1m",
"rule": "self >= duration('1m')"
}
]
}, },
"url": { "url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.", "description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
@@ -184,6 +184,10 @@
], ],
"additionalProperties": false "additionalProperties": false
}, },
"keyless": {
"description": "Keyless configures keyless authentication.",
"type": "object"
},
"ldap": { "ldap": {
"description": "LDAP configures LDAP authentication.", "description": "LDAP configures LDAP authentication.",
"properties": { "properties": {
@@ -247,7 +251,7 @@
"x-kubernetes-validations": [ "x-kubernetes-validations": [
{ {
"message": "exactly one authentication method must be specified", "message": "exactly one authentication method must be specified",
"rule": "[has(self.apiKey), has(self.jwt), has(self.ldap)].filter(x, x).size() == 1" "rule": "[has(self.apiKey), has(self.jwt), has(self.ldap), has(self.keyless)].filter(x, x).size() == 1"
} }
], ],
"additionalProperties": false "additionalProperties": false
@@ -151,6 +151,14 @@
"description": "Lastname is the JWT claim for user last name.", "description": "Lastname is the JWT claim for user last name.",
"type": "string" "type": "string"
}, },
"organizationId": {
"description": "OrganizationID is the JWT claim for the ID of the organization the user belongs to.",
"type": "string"
},
"organizationName": {
"description": "OrganizationName is the JWT claim for the name of the organization the user belongs to.",
"type": "string"
},
"userId": { "userId": {
"description": "UserID is the JWT claim for user ID mapping.", "description": "UserID is the JWT claim for user ID mapping.",
"type": "string" "type": "string"
@@ -211,7 +211,13 @@
"refreshInterval": { "refreshInterval": {
"description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.", "description": "RefreshInterval defines the rate at which the OpenAPI specification is refreshed.",
"format": "duration", "format": "duration",
"type": "string" "type": "string",
"x-kubernetes-validations": [
{
"message": "must be at least 1m",
"rule": "self >= duration('1m')"
}
]
}, },
"url": { "url": {
"description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.", "description": "URL is a Traefik Hub agent accessible URL for obtaining the OpenAPI specification.\nThe URL must be accessible via a GET request method and should serve a YAML or JSON document containing the OpenAPI specification.",
@@ -589,6 +589,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -1044,6 +1048,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -1639,6 +1647,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -2119,6 +2131,10 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"description": "RepoURL is the URL to the git repository that contains the hydrated manifests. If not set, defaults to\nthe DrySource.RepoURL.",
"type": "string"
},
"targetBranch": { "targetBranch": {
"description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.", "description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.",
"type": "string" "type": "string"
@@ -2583,6 +2599,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -3239,6 +3259,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -3694,6 +3718,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -4311,6 +4339,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -4766,6 +4798,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -5377,6 +5413,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -5832,6 +5872,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -6443,6 +6487,10 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"description": "RepoURL is the URL to the git repository that contains the hydrated manifests. If not set, defaults to\nthe DrySource.RepoURL.",
"type": "string"
},
"targetBranch": { "targetBranch": {
"description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.", "description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.",
"type": "string" "type": "string"
@@ -6476,6 +6524,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastComparedDryRevision": {
"description": "LastComparedDryRevision holds the resolved revision from the most recent dry source comparison.\nThis is updated on every evaluation, even when hydration is skipped due to no changes.",
"type": "string"
},
"lastSuccessfulOperation": { "lastSuccessfulOperation": {
"description": "LastSuccessfulOperation holds info about the most recent successful hydration", "description": "LastSuccessfulOperation holds info about the most recent successful hydration",
"properties": { "properties": {
@@ -6956,6 +7008,10 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"description": "RepoURL is the URL to the git repository that contains the hydrated manifests. If not set, defaults to\nthe DrySource.RepoURL.",
"type": "string"
},
"targetBranch": { "targetBranch": {
"description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.", "description": "TargetBranch is the branch from which hydrated manifests will be synced.\nIf HydrateTo is not set, this is also the branch to which hydrated manifests are committed.",
"type": "string" "type": "string"
@@ -7012,6 +7068,10 @@
"type": "string" "type": "string"
}, },
"type": "array" "type": "array"
},
"isAppOfApps": {
"description": "IsAppOfApps holds true if the application has any application for child resource.",
"type": "boolean"
} }
}, },
"type": "object", "type": "object",
@@ -7529,6 +7589,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -7984,6 +8048,10 @@
"description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests", "description": "RepoURL is the URL to the repository (Git or Helm) that contains the application manifests",
"type": "string" "type": "string"
}, },
"tagPrefix": {
"description": "TagPrefix filters git tags to only those with this prefix before evaluating targetRevision as a semver constraint.\nThe prefix is stripped from tag names before comparison and re-added to the resolved version.\nFor example, with tagPrefix \"component-b/\" and targetRevision \"1.0.*\", tags like \"component-b/1.0.0\" and\n\"component-b/1.0.1\" are candidates, and the constraint resolves to \"component-b/1.0.1\".",
"type": "string"
},
"targetRevision": { "targetRevision": {
"description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.", "description": "TargetRevision defines the revision of the source to sync the application to.\nIn case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD.\nIn case of Helm, this is a semver tag for the Chart's version.",
"type": "string" "type": "string"
@@ -558,6 +558,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -964,6 +967,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -1356,6 +1362,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -2008,6 +2017,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -2414,6 +2426,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -2806,6 +2821,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -3461,6 +3479,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -3867,6 +3888,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -4259,6 +4283,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -4878,6 +4905,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -5284,6 +5314,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -5676,6 +5709,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -6331,6 +6367,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -6737,6 +6776,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -7129,6 +7171,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -7781,6 +7826,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -8187,6 +8235,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -8579,6 +8630,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -9234,6 +9288,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -9640,6 +9697,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -10032,6 +10092,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -10651,6 +10714,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -11057,6 +11123,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -11449,6 +11518,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -12083,6 +12155,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -12489,6 +12564,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -12881,6 +12959,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -13874,6 +13955,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -14280,6 +14364,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -14672,6 +14759,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -15030,6 +15120,9 @@
"api": { "api": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"insecure": { "insecure": {
"type": "boolean" "type": "boolean"
}, },
@@ -15071,6 +15164,9 @@
"appSecretName": { "appSecretName": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"organization": { "organization": {
"type": "string" "type": "string"
}, },
@@ -15124,6 +15220,9 @@
"group": { "group": {
"type": "string" "type": "string"
}, },
"includeArchivedRepos": {
"type": "boolean"
},
"includeSharedProjects": { "includeSharedProjects": {
"type": "boolean" "type": "boolean"
}, },
@@ -15652,6 +15751,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -16058,6 +16160,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -16450,6 +16555,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -17100,6 +17208,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -17506,6 +17617,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -17898,6 +18012,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -18556,6 +18673,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -18962,6 +19082,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -19354,6 +19477,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -20006,6 +20132,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -20412,6 +20541,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -20804,6 +20936,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -21459,6 +21594,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -21865,6 +22003,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -22257,6 +22398,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -22876,6 +23020,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -23282,6 +23429,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -23674,6 +23824,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -24308,6 +24461,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -24714,6 +24870,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -25106,6 +25265,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -26099,6 +26261,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -26505,6 +26670,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -26897,6 +27065,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -27255,6 +27426,9 @@
"api": { "api": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"insecure": { "insecure": {
"type": "boolean" "type": "boolean"
}, },
@@ -27296,6 +27470,9 @@
"appSecretName": { "appSecretName": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"organization": { "organization": {
"type": "string" "type": "string"
}, },
@@ -27349,6 +27526,9 @@
"group": { "group": {
"type": "string" "type": "string"
}, },
"includeArchivedRepos": {
"type": "boolean"
},
"includeSharedProjects": { "includeSharedProjects": {
"type": "boolean" "type": "boolean"
}, },
@@ -27877,6 +28057,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -28283,6 +28466,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -28675,6 +28861,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -29331,6 +29520,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -29737,6 +29929,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -30129,6 +30324,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -30761,6 +30959,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -31167,6 +31368,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -31559,6 +31763,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -32552,6 +32759,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -32958,6 +33168,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -33350,6 +33563,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -33708,6 +33924,9 @@
"api": { "api": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"insecure": { "insecure": {
"type": "boolean" "type": "boolean"
}, },
@@ -33749,6 +33968,9 @@
"appSecretName": { "appSecretName": {
"type": "string" "type": "string"
}, },
"excludeArchivedRepos": {
"type": "boolean"
},
"organization": { "organization": {
"type": "string" "type": "string"
}, },
@@ -33802,6 +34024,9 @@
"group": { "group": {
"type": "string" "type": "string"
}, },
"includeArchivedRepos": {
"type": "boolean"
},
"includeSharedProjects": { "includeSharedProjects": {
"type": "boolean" "type": "boolean"
}, },
@@ -34330,6 +34555,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -34736,6 +34964,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -35128,6 +35359,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -35906,6 +36140,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -36312,6 +36549,9 @@
"pattern": "^.{2,}|[^./]$", "pattern": "^.{2,}|[^./]$",
"type": "string" "type": "string"
}, },
"repoURL": {
"type": "string"
},
"targetBranch": { "targetBranch": {
"type": "string" "type": "string"
} }
@@ -36704,6 +36944,9 @@
"repoURL": { "repoURL": {
"type": "string" "type": "string"
}, },
"tagPrefix": {
"type": "string"
},
"targetRevision": { "targetRevision": {
"type": "string" "type": "string"
} }
@@ -259,9 +259,9 @@
"type": "array" "type": "array"
}, },
"signatureKeys": { "signatureKeys": {
"description": "SignatureKeys contains a list of PGP key IDs that commits in Git must be signed with in order to be allowed for sync", "description": "SignatureKeys contains a list of PGP key IDs that commits in Git must be signed with in order to be allowed for sync\n\nDeprecated: Use SourceIntegrity instead. SignatureKeys will be removed with the next major version.",
"items": { "items": {
"description": "SignatureKey is the specification of a key required to verify commit signatures with", "description": "SignatureKey is the specification of a key required to verify commit signatures with\n\nDeprecated: Use SourceIntegrity instead. SignatureKeys will be removed with the next major version.",
"properties": { "properties": {
"keyID": { "keyID": {
"description": "The ID of the key in hexadecimal notation", "description": "The ID of the key in hexadecimal notation",
@@ -276,6 +276,77 @@
}, },
"type": "array" "type": "array"
}, },
"sourceIntegrity": {
"description": "SourceIntegrity represents a constraint on manifest sources integrity to be met before they can be used.\nDo not access directly, use EffectiveSourceIntegrity() for correct backwards compatibility handling.",
"properties": {
"git": {
"description": "Git - policies for git source verification",
"properties": {
"policies": {
"items": {
"properties": {
"gpg": {
"description": "Verify GPG commit/tag signatures",
"properties": {
"keys": {
"description": "List of key IDs to trust. The keys need to be in the repository server keyring.",
"items": {
"type": "string"
},
"type": "array"
},
"mode": {
"type": "string"
}
},
"required": [
"keys",
"mode"
],
"type": "object",
"additionalProperties": false
},
"repos": {
"description": "List of repository criteria restricting repositories the policy will apply to",
"items": {
"properties": {
"url": {
"description": "URL specifier, glob.",
"type": "string"
}
},
"required": [
"url"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"gpg",
"repos"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"policies"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"git"
],
"type": "object",
"additionalProperties": false
},
"sourceNamespaces": { "sourceNamespaces": {
"description": "SourceNamespaces defines the namespaces application resources are allowed to be created in", "description": "SourceNamespaces defines the namespaces application resources are allowed to be created in",
"items": { "items": {
@@ -340,6 +411,10 @@
"description": "Schedule is the time the window will begin, specified in cron format", "description": "Schedule is the time the window will begin, specified in cron format",
"type": "string" "type": "string"
}, },
"syncOverrun": {
"description": "SyncOverrun allows ongoing syncs to continue in two scenarios:\nFor deny windows: allows syncs that started before the deny window became active to continue running\nFor allow windows: allows syncs that started during the allow window to continue after the window ends",
"type": "boolean"
},
"timeZone": { "timeZone": {
"description": "TimeZone of the sync that will be applied to the schedule", "description": "TimeZone of the sync that will be applied to the schedule",
"type": "string" "type": "string"
@@ -0,0 +1,392 @@
{
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"properties": {
"destinationCIDRs": {
"description": "DestinationCIDRs is a list of destination CIDRs for destination IP addresses.\nIf a destination IP matches any one CIDR, it will be selected.",
"items": {
"pattern": "^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]|[1-2][0-9]|3[0-2])$|^s*((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:)))(%.+)?s*(\\/(12[0-8]|1[0-1][0-9]|[1-9][0-9]|[0-9]))$",
"type": "string"
},
"type": "array"
},
"egressGateway": {
"description": "EgressGateway is the gateway node responsible for SNATing traffic.\nIn case multiple nodes are a match for the given set of labels, the first node\nin lexical ordering based on their name will be selected.",
"properties": {
"egressIP": {
"description": "EgressIP is the source IP address that the egress traffic is SNATed\nwith.\n\nExample:\nWhen set to \"192.168.1.100\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IP address 192.168.1.100.\n\nWhen set to \"2001:db8::1\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IPv6 address 2001:db8::1.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"maxLength": 39,
"type": "string",
"x-kubernetes-validations": [
{
"message": "egressIP must be a valid IP address",
"rule": "self == '' || isIP(self)"
}
]
},
"interface": {
"description": "Interface is the network interface to which the egress IP address\nthat the traffic is SNATed with is assigned.\n\nExample:\nWhen set to \"eth1\", matching egress traffic will be redirected to the\nnode matching the NodeSelector field and SNATed with the first IPv4\naddress assigned to the eth1 interface.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"type": "string"
},
"nodeSelector": {
"description": "This is a label selector which selects the node that should act as\negress gateway for the given policy.\nIn case multiple nodes are selected, only the first one in the\nlexical ordering over the node names will be used.\nThis field follows standard label selector semantics.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"required": [
"nodeSelector"
],
"type": "object",
"additionalProperties": false
},
"egressGateways": {
"default": [],
"description": "Optional list of gateway nodes responsible for SNATing traffic.\nIf this field has any entries the contents of the egressGateway field will be ignored.\nIn case multiple nodes are a match for the given set of labels in each entry,\nthe first node in lexical ordering based on their name will be selected for each entry.",
"items": {
"description": "EgressGateway identifies the node that should act as egress gateway for a\ngiven egress Gateway policy. In addition to that it also specifies the\nconfiguration of said node (which egress IP or network interface should be\nused to SNAT traffic).",
"properties": {
"egressIP": {
"description": "EgressIP is the source IP address that the egress traffic is SNATed\nwith.\n\nExample:\nWhen set to \"192.168.1.100\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IP address 192.168.1.100.\n\nWhen set to \"2001:db8::1\", matching egress traffic will be\nredirected to the node matching the NodeSelector field and SNATed\nwith IPv6 address 2001:db8::1.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"maxLength": 39,
"type": "string",
"x-kubernetes-validations": [
{
"message": "egressIP must be a valid IP address",
"rule": "self == '' || isIP(self)"
}
]
},
"interface": {
"description": "Interface is the network interface to which the egress IP address\nthat the traffic is SNATed with is assigned.\n\nExample:\nWhen set to \"eth1\", matching egress traffic will be redirected to the\nnode matching the NodeSelector field and SNATed with the first IPv4\naddress assigned to the eth1 interface.\n\nWhen none of the Interface or EgressIP fields is specified, the\npolicy will use the first IPv4 assigned to the interface with the\ndefault route.",
"type": "string"
},
"nodeSelector": {
"description": "This is a label selector which selects the node that should act as\negress gateway for the given policy.\nIn case multiple nodes are selected, only the first one in the\nlexical ordering over the node names will be used.\nThis field follows standard label selector semantics.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"required": [
"nodeSelector"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 64,
"type": "array"
},
"excludedCIDRs": {
"description": "ExcludedCIDRs is a list of destination CIDRs that will be excluded\nfrom the egress gateway redirection and SNAT logic.\nShould be a subset of destinationCIDRs otherwise it will not have any\neffect.",
"items": {
"pattern": "^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\/([0-9]|[1-2][0-9]|3[0-2])$|^s*((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4]d|1dd|[1-9]?d)(.(25[0-5]|2[0-4]d|1dd|[1-9]?d)){3}))|:)))(%.+)?s*(\\/(12[0-8]|1[0-1][0-9]|[1-9][0-9]|[0-9]))$",
"type": "string"
},
"type": "array"
},
"selectors": {
"description": "Egress represents a list of rules by which egress traffic is\nfiltered from the source pods.",
"items": {
"properties": {
"namespaceSelector": {
"description": "Selects Namespaces using cluster-scoped labels. This field follows standard label\nselector semantics; if present but empty, it selects all namespaces.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"nodeSelector": {
"description": "This is a label selector which selects Pods by Node. This field follows standard label\nselector semantics; if present but empty, it selects all nodes.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"podSelector": {
"description": "This is a label selector which selects Pods. This field follows standard label\nselector semantics; if present but empty, it selects all pods.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"enum": [
"In",
"NotIn",
"Exists",
"DoesNotExist"
],
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"description": "MatchLabelsValue represents the value from the MatchLabels {key,value} pair.",
"maxLength": 63,
"pattern": "^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$",
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"type": "array"
}
},
"required": [
"destinationCIDRs",
"egressGateway",
"selectors"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"metadata"
],
"type": "object"
}
@@ -30,7 +30,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak RealmRepresentation", "description": "Definition contains the Keycloak RealmRepresentation. Set the realm name\nvia spec.realmName.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -54,7 +54,8 @@
"additionalProperties": false "additionalProperties": false
}, },
"realmName": { "realmName": {
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)", "description": "RealmName is the name of the realm in Keycloak. It is immutable once set:\nrenaming a realm in Keycloak is destructive and would orphan it.",
"minLength": 1,
"type": "string" "type": "string"
}, },
"smtpSecretRef": { "smtpSecretRef": {
@@ -88,9 +89,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"realmName"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of instanceRef or clusterInstanceRef must be set",
"rule": "has(self.instanceRef) != has(self.clusterInstanceRef)"
},
{
"message": "spec.realmName is immutable once set",
"rule": "!has(oldSelf.realmName) || self.realmName == oldSelf.realmName"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -167,6 +179,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after SMTP credential merging). Keycloak masks\nsmtpServer.password on read, so this is the only way to detect that\nthe desired password changed and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
@@ -116,8 +116,45 @@
"description": "ImageName is the full identifier of the image to be tracked,\nincluding the registry (if not Docker Hub), the image name, and an initial/current tag or version.\nThis is the string used to query the container registry and also as a base for finding updates.\nExample: \"docker.io/library/nginx:1.17.10\", \"quay.io/prometheus/node-exporter:v1.5.0\".\nThis field is mandatory.", "description": "ImageName is the full identifier of the image to be tracked,\nincluding the registry (if not Docker Hub), the image name, and an initial/current tag or version.\nThis is the string used to query the container registry and also as a base for finding updates.\nExample: \"docker.io/library/nginx:1.17.10\", \"quay.io/prometheus/node-exporter:v1.5.0\".\nThis field is mandatory.",
"type": "string" "type": "string"
}, },
"imagesVerification": {
"description": "ImagesVerification overrides the signature verification policy for this specific image.\nWhen set, it takes precedence over both the spec-level and ApplicationRef-level\nImagesVerification.",
"properties": {
"cosignKey": {
"description": "CosignKey references a Kubernetes Secret in the same namespace as the\nImageUpdater CR that holds the PEM-encoded ECDSA public key used to verify\ncosign signatures. Providing this field selects cosign key-based verification.",
"properties": {
"key": {
"description": "Key is the key within the Secret's data map whose value contains the credential material\n(e.g. \"cosign.pub\" for a PEM-encoded public key).",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret.",
"type": "string"
}
},
"required": [
"key",
"secretName"
],
"type": "object",
"additionalProperties": false
},
"enabled": {
"default": true,
"description": "Enabled controls whether signature verification is active at this scope.\nDefaults to true when the ImagesVerification block is present.\nSet to false to explicitly opt out of verification for this image or group.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one verification method (cosignKey) is required when verification is enabled",
"rule": "self.enabled == false || has(self.cosignKey)"
}
],
"additionalProperties": false
},
"manifestTargets": { "manifestTargets": {
"description": "ManifestTarget defines how and where to update this image in Kubernetes manifests.\nOnly one of Helm or Kustomize should be specified within this block.\nThis whole block is optional if the image update isn't written to a manifest in a structured way.", "description": "ManifestTarget defines how and where to update this image in Kubernetes manifests.\nExactly one of Helm, Kustomize, or Plugin should be specified within this block.\nThis whole block is optional if the image update isn't written to a manifest in a structured way.",
"properties": { "properties": {
"helm": { "helm": {
"description": "Helm specifies update parameters if the target manifest is managed by Helm\nand updates are to be made to Helm values files.", "description": "Helm specifies update parameters if the target manifest is managed by Helm\nand updates are to be made to Helm values files.",
@@ -151,13 +188,44 @@
], ],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
},
"plugin": {
"description": "Plugin specifies update parameters if the target manifest is managed by a Config Management Plugin.\nWhen the argocd write-back method is configured, updates will be written as environment variables\nin the Argo CD Application spec.source.plugin.env list. When the git write-back method is\nconfigured, updates will be written to the .argocd-source-<appName>.yaml file in the git repository.",
"properties": {
"name": {
"description": "Name is the environment variable name for the image repository/name part.\nExample: \"IMAGE_NAME\", \"REDIS_IMAGE_REPO\".\nIf Spec is set, this field is ignored.",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"spec": {
"description": "Spec is the environment variable name where the full image string\n(e.g., \"image/name:1.0\") should be written.\nUse this if your plugin expects the entire image reference in a single env var.\nIf this is set, Name and Tag will be ignored.",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"tag": {
"description": "Tag is the environment variable name for the image tag part.\nExample: \"IMAGE_TAG\", \"REDIS_IMAGE_VERSION\".\nIf Spec is set, this field is ignored.",
"maxLength": 253,
"minLength": 1,
"type": "string"
} }
}, },
"type": "object", "type": "object",
"x-kubernetes-validations": [ "x-kubernetes-validations": [
{ {
"message": "Exactly one of helm or kustomize must be specified within manifestTargets if the block is present.", "message": "At least one of spec or name must be specified in plugin target.",
"rule": "has(self.helm) ? !has(self.kustomize) : has(self.kustomize)" "rule": "has(self.spec) || has(self.name)"
}
],
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "Exactly one of helm, kustomize, or plugin must be specified within manifestTargets if the block is present.",
"rule": "(has(self.helm) ? 1 : 0) + (has(self.kustomize) ? 1 : 0) + (has(self.plugin) ? 1 : 0) == 1"
} }
], ],
"additionalProperties": false "additionalProperties": false
@@ -176,6 +244,43 @@
], ],
"x-kubernetes-list-type": "map" "x-kubernetes-list-type": "map"
}, },
"imagesVerification": {
"description": "ImagesVerification overrides the global signature verification policy for applications\nmatched by this ApplicationRef. When set, it takes precedence over the spec-level\nImagesVerification for all images in this group, but can still be overridden\nat the individual ImageConfig level.",
"properties": {
"cosignKey": {
"description": "CosignKey references a Kubernetes Secret in the same namespace as the\nImageUpdater CR that holds the PEM-encoded ECDSA public key used to verify\ncosign signatures. Providing this field selects cosign key-based verification.",
"properties": {
"key": {
"description": "Key is the key within the Secret's data map whose value contains the credential material\n(e.g. \"cosign.pub\" for a PEM-encoded public key).",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret.",
"type": "string"
}
},
"required": [
"key",
"secretName"
],
"type": "object",
"additionalProperties": false
},
"enabled": {
"default": true,
"description": "Enabled controls whether signature verification is active at this scope.\nDefaults to true when the ImagesVerification block is present.\nSet to false to explicitly opt out of verification for this image or group.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one verification method (cosignKey) is required when verification is enabled",
"rule": "self.enabled == false || has(self.cosignKey)"
}
],
"additionalProperties": false
},
"labelSelectors": { "labelSelectors": {
"description": "LabelSelectors indicates the label selectors to apply for application selection", "description": "LabelSelectors indicates the label selectors to apply for application selection",
"properties": { "properties": {
@@ -276,15 +381,11 @@
"additionalProperties": false "additionalProperties": false
}, },
"method": { "method": {
"default": "argocd",
"description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".", "description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".",
"pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$", "pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$",
"type": "string" "type": "string"
} }
}, },
"required": [
"method"
],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
} }
@@ -349,6 +450,43 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"imagesVerification": {
"description": "ImagesVerification defines the global default image signature verification policy.\nWhen set, every image update is subject to cryptographic verification before being\ncommitted to Git or applied to an Argo CD Application.\nCan be overridden at the ApplicationRef or ImageConfig level.",
"properties": {
"cosignKey": {
"description": "CosignKey references a Kubernetes Secret in the same namespace as the\nImageUpdater CR that holds the PEM-encoded ECDSA public key used to verify\ncosign signatures. Providing this field selects cosign key-based verification.",
"properties": {
"key": {
"description": "Key is the key within the Secret's data map whose value contains the credential material\n(e.g. \"cosign.pub\" for a PEM-encoded public key).",
"type": "string"
},
"secretName": {
"description": "SecretName is the name of the Kubernetes Secret.",
"type": "string"
}
},
"required": [
"key",
"secretName"
],
"type": "object",
"additionalProperties": false
},
"enabled": {
"default": true,
"description": "Enabled controls whether signature verification is active at this scope.\nDefaults to true when the ImagesVerification block is present.\nSet to false to explicitly opt out of verification for this image or group.",
"type": "boolean"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one verification method (cosignKey) is required when verification is enabled",
"rule": "self.enabled == false || has(self.cosignKey)"
}
],
"additionalProperties": false
},
"writeBackConfig": { "writeBackConfig": {
"description": "WriteBackConfig provides global default settings for how and where to write back image updates.\nThis can be overridden at the ApplicationRef level.", "description": "WriteBackConfig provides global default settings for how and where to write back image updates.\nThis can be overridden at the ApplicationRef level.",
"properties": { "properties": {
@@ -393,15 +531,11 @@
"additionalProperties": false "additionalProperties": false
}, },
"method": { "method": {
"default": "argocd",
"description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".", "description": "Method defines the method for writing back updated image versions.\nThis acts as the default if not overridden. If not specified, defaults to \"argocd\".",
"pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$", "pattern": "^(argocd|git|git:[a-zA-Z0-9][a-zA-Z0-9-._/:]*)$",
"type": "string" "type": "string"
} }
}, },
"required": [
"method"
],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
} }
@@ -53,10 +53,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -71,6 +67,12 @@
"providerId" "providerId"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -16,7 +16,8 @@
"description": "KeycloakClientSpec defines the desired state of KeycloakClient", "description": "KeycloakClientSpec defines the desired state of KeycloakClient",
"properties": { "properties": {
"clientId": { "clientId": {
"description": "ClientId is the client ID in Keycloak (defaults to metadata.name)", "description": "ClientId is the client ID in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string" "type": "string"
}, },
"clientSecretRef": { "clientSecretRef": {
@@ -61,7 +62,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak ClientRepresentation", "description": "Definition contains the Keycloak ClientRepresentation. Set the client ID\nvia spec.clientId.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -71,10 +72,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -84,12 +81,29 @@
"additionalProperties": false "additionalProperties": false
} }
}, },
"required": [
"clientId"
],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.clientId is immutable once set",
"rule": "!has(oldSelf.clientId) || self.clientId == oldSelf.clientId"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
"description": "KeycloakClientStatus defines the observed state of KeycloakClient", "description": "KeycloakClientStatus defines the observed state of KeycloakClient",
"properties": { "properties": {
"clientId": {
"description": "ClientID is the resolved client ID (clientId) in Keycloak",
"type": "string"
},
"clientUUID": { "clientUUID": {
"description": "ClientUUID is the Keycloak internal ID", "description": "ClientUUID is the Keycloak internal ID",
"type": "string" "type": "string"
@@ -30,20 +30,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak ClientScopeRepresentation", "description": "Definition contains the Keycloak ClientScopeRepresentation. Set the client\nscope name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the client scope name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,14 +55,29 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
"description": "KeycloakClientScopeStatus defines the observed state of KeycloakClientScope", "description": "KeycloakClientScopeStatus defines the observed state of KeycloakClientScope",
"properties": { "properties": {
"clientScopeName": {
"description": "ClientScopeName is the resolved client scope name in Keycloak",
"type": "string"
},
"conditions": { "conditions": {
"description": "Conditions represent the latest available observations", "description": "Conditions represent the latest available observations",
"items": { "items": {
@@ -29,21 +29,36 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Each secret\nvalue is wrapped as a single-element list to match ComponentRepresentation\nconfig (map[string][]string). Secret values take precedence over values\nspecified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"definition": { "definition": {
"description": "Definition contains the Keycloak ComponentRepresentation", "description": "Definition contains the Keycloak ComponentRepresentation. Set the component\nname via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the component name in Keycloak. Immutable once set. The\nproviderType is set in spec.definition.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,9 +69,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -141,6 +167,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks secret config values\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
@@ -16,7 +16,7 @@
"description": "KeycloakGroupSpec defines the desired state of KeycloakGroup", "description": "KeycloakGroupSpec defines the desired state of KeycloakGroup",
"properties": { "properties": {
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for top-level groups\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the cluster-scoped resource", "description": "Name of the cluster-scoped resource",
@@ -30,20 +30,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak GroupRepresentation", "description": "Definition contains the Keycloak GroupRepresentation. Set the group name\nvia spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the group name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"parentGroupRef": { "parentGroupRef": {
"description": "ParentGroupRef is a reference to a parent KeycloakGroup (for nested groups)", "description": "ParentGroupRef is a reference to a parent KeycloakGroup for nested groups.\nThe realm is derived from the parent chain, so realmRef and clusterRealmRef\nmust not be set alongside it.\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -53,15 +54,11 @@
"additionalProperties": false "additionalProperties": false
}, },
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm for top-level groups\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -72,9 +69,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or parentGroupRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.parentGroupRef) ? 1 : 0) == 1"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -140,6 +148,10 @@
"description": "GroupID is the Keycloak internal group ID", "description": "GroupID is the Keycloak internal group ID",
"type": "string" "type": "string"
}, },
"groupName": {
"description": "GroupName is the resolved group name in Keycloak",
"type": "string"
},
"instance": { "instance": {
"description": "Instance contains the resolved instance reference", "description": "Instance contains the resolved instance reference",
"properties": { "properties": {
@@ -15,6 +15,11 @@
"spec": { "spec": {
"description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider", "description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider",
"properties": { "properties": {
"alias": {
"description": "Alias is the identity provider alias in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
@@ -33,7 +38,7 @@
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.", "description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the Kubernetes Secret", "description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string" "type": "string"
} }
}, },
@@ -44,20 +49,30 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak IdentityProviderRepresentation", "description": "Definition contains the Keycloak IdentityProviderRepresentation. Set the\nalias via spec.alias.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"organizationRef": {
"description": "OrganizationRef references a KeycloakOrganization in the same namespace.\nThe organization's status.organizationID is injected as organizationId\non the identity provider. Requires Keycloak 26 or later. Do not set\norganizationId in definition; use this field instead.",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -85,14 +100,29 @@
} }
}, },
"required": [ "required": [
"alias",
"definition" "definition"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.alias is immutable once set",
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
"description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider", "description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider",
"properties": { "properties": {
"alias": {
"description": "Alias is the resolved identity provider alias in Keycloak",
"type": "string"
},
"conditions": { "conditions": {
"description": "Conditions represent the latest available observations", "description": "Conditions represent the latest available observations",
"items": { "items": {
@@ -164,10 +194,18 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks config.clientSecret\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
}, },
"organizationID": {
"description": "OrganizationID is the resolved Keycloak organization ID when\nspec.organizationRef is set.",
"type": "string"
},
"ready": { "ready": {
"description": "Ready indicates if the identity provider is ready", "description": "Ready indicates if the identity provider is ready",
"type": "boolean" "type": "boolean"
@@ -15,8 +15,22 @@
"spec": { "spec": {
"description": "KeycloakIdentityProviderMapperSpec defines the desired state of KeycloakIdentityProviderMapper", "description": "KeycloakIdentityProviderMapperSpec defines the desired state of KeycloakIdentityProviderMapper",
"properties": { "properties": {
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"definition": { "definition": {
"description": "Definition contains the Keycloak IdentityProviderMapperRepresentation.\nThe identityProviderAlias field is auto-injected from the parent\nKeycloakIdentityProvider at reconcile time and does not need to be set\nhere.", "description": "Definition contains the Keycloak IdentityProviderMapperRepresentation. The\nidentityProviderAlias field is injected from the parent KeycloakIdentityProvider\nat reconcile time. Set the mapper name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -26,10 +40,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -37,13 +47,25 @@
], ],
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
},
"name": {
"description": "Name is the mapper name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
} }
}, },
"required": [ "required": [
"definition", "definition",
"identityProviderRef" "identityProviderRef",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -30,20 +30,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak OrganizationRepresentation", "description": "Definition contains the Keycloak OrganizationRepresentation. Set the\norganization name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the organization name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,9 +55,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -146,6 +158,10 @@
"description": "OrganizationID is the Keycloak internal organization ID", "description": "OrganizationID is the Keycloak internal organization ID",
"type": "string" "type": "string"
}, },
"organizationName": {
"description": "OrganizationName is the resolved organization name in Keycloak",
"type": "string"
},
"ready": { "ready": {
"description": "Ready indicates if the organization is ready", "description": "Ready indicates if the organization is ready",
"type": "boolean" "type": "boolean"
@@ -21,10 +21,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -39,9 +35,19 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
}
}, },
"namespace": { "required": [
"description": "Namespace of the resource (optional, defaults to the same namespace)", "name"
],
"type": "object",
"additionalProperties": false
},
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string" "type": "string"
} }
}, },
@@ -52,15 +58,31 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak ProtocolMapperRepresentation", "description": "Definition contains the Keycloak ProtocolMapperRepresentation. Set the\nmapper name via spec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
},
"name": {
"description": "Name is the protocol mapper name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of clientRef or clientScopeRef must be set",
"rule": "has(self.clientRef) != has(self.clientScopeRef)"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -30,7 +30,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak RealmRepresentation", "description": "Definition contains the Keycloak RealmRepresentation. Set the realm name\nvia spec.realmName.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -40,10 +40,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -53,7 +49,8 @@
"additionalProperties": false "additionalProperties": false
}, },
"realmName": { "realmName": {
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)", "description": "RealmName is the name of the realm in Keycloak. It is immutable once set:\nrenaming a realm in Keycloak is destructive and would orphan it.",
"minLength": 1,
"type": "string" "type": "string"
}, },
"smtpSecretRef": { "smtpSecretRef": {
@@ -82,9 +79,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"realmName"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of instanceRef or clusterInstanceRef must be set",
"rule": "has(self.instanceRef) != has(self.clusterInstanceRef)"
},
{
"message": "spec.realmName is immutable once set",
"rule": "!has(oldSelf.realmName) || self.realmName == oldSelf.realmName"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -161,6 +169,10 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after SMTP credential merging). Keycloak masks\nsmtpServer.password on read, so this is the only way to detect that\nthe desired password changed and must be pushed.",
"type": "string"
},
"message": { "message": {
"description": "Message contains additional information", "description": "Message contains additional information",
"type": "string" "type": "string"
@@ -169,6 +181,10 @@
"description": "Ready indicates if the realm is ready", "description": "Ready indicates if the realm is ready",
"type": "boolean" "type": "boolean"
}, },
"realmName": {
"description": "RealmName is the resolved realm name in Keycloak",
"type": "string"
},
"resourcePath": { "resourcePath": {
"description": "ResourcePath is the Keycloak API path for this realm", "description": "ResourcePath is the Keycloak API path for this realm",
"type": "string" "type": "string"
@@ -15,6 +15,11 @@
"spec": { "spec": {
"description": "KeycloakRequiredActionSpec defines the desired state of KeycloakRequiredAction", "description": "KeycloakRequiredActionSpec defines the desired state of KeycloakRequiredAction",
"properties": { "properties": {
"alias": {
"description": "Alias is the required action alias in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": { "properties": {
@@ -29,8 +34,22 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"configSecretRef": {
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"definition": { "definition": {
"description": "Definition contains the Keycloak RequiredActionProviderRepresentation", "description": "Definition contains the Keycloak RequiredActionProviderRepresentation. Set\nthe alias via spec.alias.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
@@ -40,10 +59,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -54,9 +69,20 @@
} }
}, },
"required": [ "required": [
"alias",
"definition" "definition"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.alias is immutable once set",
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -16,15 +16,11 @@
"description": "KeycloakRoleSpec defines the desired state of KeycloakRole", "description": "KeycloakRoleSpec defines the desired state of KeycloakRole",
"properties": { "properties": {
"clientRef": { "clientRef": {
"description": "ClientRef is a reference to a KeycloakClient for client-level roles\nIf not specified, the role is a realm-level role", "description": "ClientRef is a reference to a KeycloakClient for client-level roles.\nThe realm is derived from the referenced client, so realmRef and\nclusterRealmRef must not be set alongside it.\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -34,7 +30,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the cluster-scoped resource", "description": "Name of the cluster-scoped resource",
@@ -48,20 +44,21 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak RoleRepresentation", "description": "Definition contains the Keycloak RoleRepresentation. Set the role name via\nspec.name.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"name": {
"description": "Name is the role name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": { "realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified", "description": "RealmRef is a reference to a KeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": { "properties": {
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -72,9 +69,20 @@
} }
}, },
"required": [ "required": [
"definition" "definition",
"name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -28,10 +28,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -49,6 +45,12 @@
"name" "name"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "at most one of clientRef or clientId may be set",
"rule": "!(has(self.clientRef) && has(self.clientId))"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"roleRef": { "roleRef": {
@@ -57,10 +59,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -78,9 +76,19 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
}
}, },
"namespace": { "required": [
"description": "Namespace of the resource (optional, defaults to the same namespace)", "name"
],
"type": "object",
"additionalProperties": false
},
"serviceAccountRef": {
"description": "ServiceAccountRef references a KeycloakClient to assign roles to its\nauto-created service account user. This avoids needing an intermediate\nKeycloakUser CR for clients with serviceAccountsEnabled: true.",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string" "type": "string"
} }
}, },
@@ -96,10 +104,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -110,6 +114,12 @@
} }
}, },
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of userRef, groupRef, or serviceAccountRef must be set",
"rule": "(has(self.userRef) ? 1 : 0) + (has(self.groupRef) ? 1 : 0) + (has(self.serviceAccountRef) ? 1 : 0) == 1"
}
],
"additionalProperties": false "additionalProperties": false
} }
}, },
@@ -117,6 +127,12 @@
"subject" "subject"
], ],
"type": "object", "type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of role or roleRef must be set",
"rule": "has(self.role) != has(self.roleRef)"
}
],
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -21,10 +21,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -33,6 +29,16 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"clientRoles": {
"additionalProperties": {
"items": {
"type": "string"
},
"type": "array"
},
"description": "ClientRoles maps a client's clientId to the authoritative set of\nclient-level role names for this user. When omitted, client roles are not\nmanaged; when set, roles on clients absent from the map are removed.\nDo not combine with KeycloakRoleMapping resources targeting the same user.",
"type": "object"
},
"clusterRealmRef": { "clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users with cluster-scoped realms", "description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users with cluster-scoped realms",
"properties": { "properties": {
@@ -48,12 +54,19 @@
"additionalProperties": false "additionalProperties": false
}, },
"definition": { "definition": {
"description": "Definition contains the Keycloak UserRepresentation", "description": "Definition contains the Keycloak UserRepresentation. Set the username via\nspec.username; role and group assignments go in spec.realmRoles,\nspec.clientRoles, and spec.groups.",
"type": "object", "type": "object",
"x-kubernetes-preserve-unknown-fields": true "x-kubernetes-preserve-unknown-fields": true
}, },
"groups": {
"description": "Groups is the authoritative set of group names this user belongs to,\nreconciled via the Keycloak group-membership endpoints. When omitted,\ngroup memberships are not managed; an empty list removes all memberships.",
"items": {
"type": "string"
},
"type": "array"
},
"initialPassword": { "initialPassword": {
"description": "InitialPassword sets the initial password for the user (only on creation)", "description": "InitialPassword sets the initial password for the user (only on creation).\nFor managed credentials stored in a Kubernetes secret, use KeycloakUserCredential.",
"properties": { "properties": {
"temporary": { "temporary": {
"description": "Temporary indicates if the user must change password on first login", "description": "Temporary indicates if the user must change password on first login",
@@ -76,10 +89,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -88,34 +97,34 @@
"type": "object", "type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"userSecret": { "realmRoles": {
"description": "UserSecret configures where to store user credentials", "description": "RealmRoles is the authoritative set of realm-level role names for this\nuser, reconciled via the Keycloak role-mapping endpoints. When omitted,\nrealm roles are not managed; an empty list removes all realm roles.\nPointer types so an explicit empty value survives JSON round-trips.\nDo not combine with KeycloakRoleMapping resources targeting the same user.",
"properties": { "items": {
"generatePassword": {
"description": "GeneratePassword indicates whether to generate a password",
"type": "boolean"
},
"passwordKey": {
"description": "PasswordKey is the key for the password (defaults to \"password\")",
"type": "string" "type": "string"
}, },
"secretName": { "type": "array"
"description": "SecretName is the name of the Kubernetes secret to create",
"type": "string"
}, },
"usernameKey": { "username": {
"description": "UsernameKey is the key for the username in the secret (defaults to \"username\")", "description": "Username is the username in Keycloak. Required for regular realm users;\nomit it for service account users, which are identified by clientRef and\nwhose username is derived by Keycloak. Immutable once set.",
"minLength": 1,
"type": "string" "type": "string"
} }
}, },
"required": [ "type": "object",
"secretName" "x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
},
{
"message": "spec.username is required unless spec.clientRef is set (service account user)",
"rule": "has(self.clientRef) || (has(self.username) && size(self.username) > 0)"
},
{
"message": "spec.username is immutable once set",
"rule": "!has(oldSelf.username) || (has(self.username) && self.username == oldSelf.username)"
}
], ],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false "additionalProperties": false
}, },
"status": { "status": {
@@ -239,6 +248,10 @@
"userID": { "userID": {
"description": "UserID is the Keycloak internal user ID", "description": "UserID is the Keycloak internal user ID",
"type": "string" "type": "string"
},
"username": {
"description": "Username is the resolved username in Keycloak",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -21,10 +21,6 @@
"name": { "name": {
"description": "Name of the resource", "description": "Name of the resource",
"type": "string" "type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
} }
}, },
"required": [ "required": [
@@ -153,6 +153,53 @@
"description": "Claims specifies an expression that validate claims in order to authorize the request.", "description": "Claims specifies an expression that validate claims in order to authorize the request.",
"type": "string" "type": "string"
}, },
"managedApplicationSelector": {
"description": "ManagedApplicationSelector selects the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.\nThis field is optional and follows standard label selector semantics.\nAn empty ManagedApplicationSelector matches any ManagedApplication.",
"properties": {
"matchExpressions": {
"description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
"items": {
"description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
"properties": {
"key": {
"description": "key is the label key that the selector applies to.",
"type": "string"
},
"operator": {
"description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
"type": "string"
},
"values": {
"description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "atomic"
}
},
"required": [
"key",
"operator"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-type": "atomic"
},
"matchLabels": {
"additionalProperties": {
"type": "string"
},
"description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
"type": "object"
}
},
"type": "object",
"x-kubernetes-map-type": "atomic",
"additionalProperties": false
},
"managedApplications": { "managedApplications": {
"description": "ManagedApplications references the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.", "description": "ManagedApplications references the ManagedApplications that will gain access to the specified APIs.\nMultiple ManagedSubscriptions can select the same ManagedApplication.",
"items": { "items": {
@@ -292,6 +339,24 @@
}, },
"type": "array" "type": "array"
}, },
"resolvedManagedApplications": {
"description": "ResolvedManagedApplications is the list of ManagedApplications that were successfully resolved.",
"items": {
"description": "ResolvedManagedApplicationReference references a resolved ManagedApplication.",
"properties": {
"name": {
"description": "Name of the ManagedApplication.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"syncedAt": { "syncedAt": {
"format": "date-time", "format": "date-time",
"type": "string" "type": "string"
@@ -314,6 +379,24 @@
}, },
"type": "array" "type": "array"
}, },
"unresolvedManagedApplications": {
"description": "UnresolvedManagedApplications is the list of ManagedApplications that could not be resolved.",
"items": {
"description": "ResolvedManagedApplicationReference references a resolved ManagedApplication.",
"properties": {
"name": {
"description": "Name of the ManagedApplication.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"version": { "version": {
"type": "string" "type": "string"
} }
@@ -279,6 +279,13 @@
"errors": { "errors": {
"description": "ErrorPage holds the custom error middleware configuration.\nThis middleware returns a custom page in lieu of the default, according to configured ranges of HTTP Status codes.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/middlewares/errorpages/", "description": "ErrorPage holds the custom error middleware configuration.\nThis middleware returns a custom page in lieu of the default, according to configured ranges of HTTP Status codes.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/middlewares/errorpages/",
"properties": { "properties": {
"errorRequestHeaders": {
"description": "ErrorRequestHeaders defines the list of request headers forwarded to the error page service.\nWhen nil (not set), all original request headers are forwarded.\nSet to an empty list to forward no headers, or list specific headers to forward only those.",
"items": {
"type": "string"
},
"type": "array"
},
"query": { "query": {
"description": "Query defines the URL for the error page (hosted by service).\nThe {status} variable can be used in order to insert the status code in the URL.\nThe {originalStatus} variable can be used in order to insert the upstream status code in the URL.\nThe {url} variable can be used in order to insert the escaped request URL.", "description": "Query defines the URL for the error page (hosted by service).\nThe {status} variable can be used in order to insert the status code in the URL.\nThe {originalStatus} variable can be used in order to insert the upstream status code in the URL.\nThe {url} variable can be used in order to insert the escaped request URL.",
"type": "string" "type": "string"
@@ -339,7 +339,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -480,7 +480,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -535,7 +535,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -826,7 +826,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -881,7 +881,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -288,7 +288,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -429,7 +429,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -484,7 +484,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1006,7 +1006,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1061,7 +1061,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1265,7 +1265,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -1334,7 +1334,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1393,7 +1393,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1690,7 +1690,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1749,7 +1749,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1940,7 +1940,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2208,6 +2208,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2329,6 +2333,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2419,6 +2427,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2483,6 +2495,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2621,6 +2637,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2685,6 +2705,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3056,6 +3080,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3120,6 +3148,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3238,8 +3270,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -3298,7 +3338,7 @@
"type": "boolean" "type": "boolean"
}, },
"disableCompaction": { "disableCompaction": {
"description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.41.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.41.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.", "description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.42.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.42.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.",
"type": "boolean" "type": "boolean"
}, },
"dnsConfig": { "dnsConfig": {
@@ -3619,7 +3659,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3887,6 +3927,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4008,6 +4052,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4098,6 +4146,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4162,6 +4214,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4300,6 +4356,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4364,6 +4424,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4735,6 +4799,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4799,6 +4867,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4917,8 +4989,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -5588,7 +5668,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5729,7 +5809,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5784,7 +5864,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5969,7 +6049,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6028,7 +6108,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6437,7 +6517,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6578,7 +6658,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6633,7 +6713,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6888,7 +6968,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -6952,7 +7032,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7011,7 +7091,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7295,10 +7375,23 @@
"additionalProperties": false "additionalProperties": false
}, },
"retention": { "retention": {
"description": "retention defines how long to retain the Prometheus data.\n\nDefault: \"24h\" if `spec.retention` and `spec.retentionSize` are empty.", "description": "retention defines how long to retain the Prometheus data.\n\nDefault: \"24h\" if `spec.retention`, `spec.retentionSize` and\n`spec.retentionPercentage` are empty.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$", "pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string" "type": "string"
}, },
"retentionPercentage": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "retentionPercentage defines the maximum percentage of the data volume's\ncapacity used by the Prometheus data.\n\nThe value is a number between 0 and 100. If set to 0, percentage-based\nretention is disabled.\n\nIt requires Prometheus >= v3.11.0 and is ignored by older versions.",
"pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
"x-kubernetes-int-or-string": true
},
"retentionSize": { "retentionSize": {
"description": "retentionSize defines the maximum number of bytes used by the Prometheus data.", "description": "retentionSize defines the maximum number of bytes used by the Prometheus data.",
"pattern": "(^0|([0-9]*[.])?[0-9]+((K|M|G|T|E|P)i?)?B)$", "pattern": "(^0|([0-9]*[.])?[0-9]+((K|M|G|T|E|P)i?)?B)$",
@@ -7681,7 +7774,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7740,7 +7833,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8052,7 +8145,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -8365,6 +8458,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -8404,7 +8502,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8428,7 +8526,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8619,7 +8717,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8643,7 +8741,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8876,6 +8974,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -8986,7 +9133,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9045,7 +9192,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9354,8 +9501,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -9597,7 +9752,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9656,7 +9811,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9867,8 +10022,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -10087,6 +10250,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -10104,6 +10272,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -10180,6 +10353,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -10244,6 +10422,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -10266,6 +10449,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -10305,7 +10493,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -10329,7 +10517,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -10834,6 +11022,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -10904,6 +11097,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -10932,6 +11130,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11025,6 +11228,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11068,6 +11276,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -11103,6 +11316,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11144,6 +11362,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11328,6 +11551,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -11345,6 +11573,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11514,7 +11747,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11580,7 +11813,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1015,7 +1015,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1074,7 +1074,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1261,7 +1261,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1529,6 +1529,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1650,6 +1654,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1740,6 +1748,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -1804,6 +1816,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1942,6 +1958,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2006,6 +2026,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2377,6 +2401,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2441,6 +2469,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2559,8 +2591,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -2914,7 +2954,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3182,6 +3222,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3303,6 +3347,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3393,6 +3441,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3457,6 +3509,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3595,6 +3651,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3659,6 +3719,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4030,6 +4094,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4094,6 +4162,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4212,8 +4284,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -4980,7 +5060,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5121,7 +5201,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5176,7 +5256,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5431,7 +5511,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -5495,7 +5575,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5554,7 +5634,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6089,7 +6169,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6148,7 +6228,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6460,7 +6540,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -6739,6 +6819,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -6778,7 +6863,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6802,7 +6887,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6993,7 +7078,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7017,7 +7102,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7250,6 +7335,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -7497,7 +7631,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7556,7 +7690,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7767,8 +7901,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -7987,6 +8129,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -8004,6 +8151,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8080,6 +8232,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -8144,6 +8301,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8166,6 +8328,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -8205,7 +8372,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8229,7 +8396,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8734,6 +8901,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -8804,6 +8976,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8832,6 +9009,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8925,6 +9107,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8968,6 +9155,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -9003,6 +9195,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -9044,6 +9241,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -9228,6 +9430,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -9245,6 +9452,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -9414,7 +9626,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9480,7 +9692,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -211,7 +211,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -352,7 +352,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -407,7 +407,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -603,7 +603,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -658,7 +658,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -980,7 +980,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1121,7 +1121,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1176,7 +1176,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1368,6 +1368,7 @@
"services": { "services": {
"description": "services defines a list of services for which targets are retrieved. If omitted, all services are scraped.", "description": "services defines a list of services for which targets are retrieved. If omitted, all services are scraped.",
"items": { "items": {
"minLength": 1,
"type": "string" "type": "string"
}, },
"type": "array", "type": "array",
@@ -1381,6 +1382,7 @@
"tags": { "tags": {
"description": "tags defines an optional list of tags used to filter nodes for a given service. Services must contain all tags in the list.\nStarting with Consul 1.14, it is recommended to use `filter` with the `ServiceTags` selector instead.", "description": "tags defines an optional list of tags used to filter nodes for a given service. Services must contain all tags in the list.\nStarting with Consul 1.14, it is recommended to use `filter` with the `ServiceTags` selector instead.",
"items": { "items": {
"minLength": 1,
"type": "string" "type": "string"
}, },
"type": "array", "type": "array",
@@ -1396,7 +1398,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1451,7 +1453,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1654,7 +1656,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1795,7 +1797,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1850,7 +1852,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2031,7 +2033,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2086,7 +2088,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2381,7 +2383,6 @@
}, },
"host": { "host": {
"description": "host defines the address of the docker daemon.", "description": "host defines the address of the docker daemon.",
"minLength": 1,
"pattern": "^[a-zA-Z][a-zA-Z0-9+.-]*://.+$", "pattern": "^[a-zA-Z][a-zA-Z0-9+.-]*://.+$",
"type": "string" "type": "string"
}, },
@@ -2408,7 +2409,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2549,7 +2550,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2604,7 +2605,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2785,7 +2786,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2840,7 +2841,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3109,7 +3110,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3250,7 +3251,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3305,7 +3306,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3495,7 +3496,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3550,7 +3551,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3836,7 +3837,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3891,7 +3892,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4126,7 +4127,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4267,7 +4268,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4322,7 +4323,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4501,7 +4502,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4556,7 +4557,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4879,7 +4880,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5020,7 +5021,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5075,7 +5076,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5249,9 +5250,7 @@
"role": { "role": {
"description": "role defines the Hetzner role of entities that should be discovered.", "description": "role defines the Hetzner role of entities that should be discovered.",
"enum": [ "enum": [
"hcloud",
"Hcloud", "Hcloud",
"robot",
"Robot" "Robot"
], ],
"type": "string" "type": "string"
@@ -5266,7 +5265,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5321,7 +5320,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5559,7 +5558,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5700,7 +5699,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5755,7 +5754,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5929,7 +5928,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5984,7 +5983,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6169,7 +6168,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6310,7 +6309,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6365,7 +6364,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6546,7 +6545,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6601,7 +6600,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6851,6 +6850,7 @@
"names": { "names": {
"description": "names defines a list of namespaces where to watch for resources.\nIf empty and `ownNamespace` isn't true, Prometheus watches for resources in all namespaces.", "description": "names defines a list of namespaces where to watch for resources.\nIf empty and `ownNamespace` isn't true, Prometheus watches for resources in all namespaces.",
"items": { "items": {
"minLength": 1,
"type": "string" "type": "string"
}, },
"type": "array", "type": "array",
@@ -6878,7 +6878,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7019,7 +7019,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7074,7 +7074,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7295,7 +7295,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7350,7 +7350,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7590,7 +7590,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7731,7 +7731,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7786,7 +7786,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7965,7 +7965,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8020,7 +8020,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8297,7 +8297,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8438,7 +8438,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8493,7 +8493,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8708,7 +8708,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8763,7 +8763,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8935,7 +8935,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9076,7 +9076,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9131,7 +9131,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9322,7 +9322,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9377,7 +9377,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9730,7 +9730,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9871,7 +9871,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9926,7 +9926,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10115,7 +10115,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10170,7 +10170,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10293,7 +10293,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10434,7 +10434,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10489,7 +10489,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10654,11 +10654,8 @@
"description": "availability defines the availability of the endpoint to connect to.", "description": "availability defines the availability of the endpoint to connect to.",
"enum": [ "enum": [
"Public", "Public",
"public",
"Admin", "Admin",
"admin", "Internal"
"Internal",
"internal"
], ],
"type": "string" "type": "string"
}, },
@@ -10747,7 +10744,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10802,7 +10799,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11187,7 +11184,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11328,7 +11325,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11383,7 +11380,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11569,7 +11566,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11624,7 +11621,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11962,7 +11959,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -12017,7 +12014,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -12237,7 +12234,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -12292,7 +12289,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -267,7 +267,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -408,7 +408,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -463,7 +463,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -747,7 +747,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -806,7 +806,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -938,7 +938,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1206,6 +1206,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1327,6 +1331,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1417,6 +1425,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -1481,6 +1493,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1619,6 +1635,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -1683,6 +1703,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2054,6 +2078,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2118,6 +2146,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2236,8 +2268,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -2433,7 +2473,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2492,7 +2532,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2728,7 +2768,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2996,6 +3036,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3117,6 +3161,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3207,6 +3255,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3271,6 +3323,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3409,6 +3465,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3473,6 +3533,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3844,6 +3908,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3908,6 +3976,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4026,8 +4098,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -4536,7 +4616,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4677,7 +4757,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4732,7 +4812,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4987,7 +5067,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -5051,7 +5131,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5110,7 +5190,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5556,7 +5636,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -5687,6 +5767,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -5726,7 +5811,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -5750,7 +5835,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -5941,7 +6026,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -5965,7 +6050,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6198,6 +6283,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -6447,8 +6581,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -6667,6 +6809,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -6684,6 +6831,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -6760,6 +6912,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -6824,6 +6981,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -6846,6 +7008,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -6885,7 +7052,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6909,7 +7076,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7414,6 +7581,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -7484,6 +7656,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7512,6 +7689,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7605,6 +7787,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7648,6 +7835,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -7683,6 +7875,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7724,6 +7921,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7908,6 +8110,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -7925,6 +8132,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8080,7 +8292,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8146,7 +8358,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -0,0 +1,202 @@
{
"description": "Tier defines the centralized resiliency and scaling policy for a class of\napplications (e.g. critical, standard, best-effort). Workloads opt in by\ncarrying the label `platform.olb42.com/tier: <tier name>` \u2014 no per-app\nHPA/PDB/toleration configuration is required. The tier-controller watches\nNode state and applies each Tier's policy to every workload selected by\nthat label.",
"properties": {
"apiVersion": {
"type": "string"
},
"kind": {
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"properties": {
"capacity": {
"description": "How replica counts for this tier react to a change in ready/schedulable node count.",
"properties": {
"minReplicasFloor": {
"default": 1,
"description": "Replica count this tier's workloads are never scaled below by\nthe controller, regardless of how many nodes are lost.",
"format": "int32",
"minimum": 0,
"type": "integer"
},
"replicaLossPerNode": {
"default": 0,
"description": "Replicas to shed per node lost (unexpected loss) or cordoned\n(intentional maintenance), before floor is applied. 0 means the\nworkload's replica count is never reduced by node loss alone.",
"format": "int32",
"minimum": 0,
"type": "integer"
},
"scaleToZeroOnCordon": {
"default": false,
"description": "Same as scaleToZeroOnNodeLoss, but for the intentional\ncordon/drain path.",
"type": "boolean"
},
"scaleToZeroOnNodeLoss": {
"default": false,
"description": "If true, workloads in this tier are scaled to 0 replicas on\nunexpected node loss, freeing capacity for higher tiers.\nminReplicasFloor is ignored when this is true.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"deletionCostBase": {
"default": 0,
"description": "Baseline value stamped as the\ncontroller.kubernetes.io/pod-deletion-cost annotation on pods of\nthis tier. Higher values are removed later during a voluntary\nscale-down, so this should be set relative to the other tiers'\nvalues (e.g. critical=1000, standard=500, best-effort=0).",
"format": "int32",
"type": "integer"
},
"disruption": {
"description": "Voluntary-disruption budget applied to workloads in this tier.",
"properties": {
"pdbMinAvailable": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "Value for the PodDisruptionBudget's spec.minAvailable the\ncontroller manages for each workload in this tier. Accepts an\nabsolute number or a percentage string (e.g. \"50%\"), matching\nnative PDB semantics.",
"x-kubernetes-int-or-string": true
}
},
"type": "object",
"additionalProperties": false
},
"priorityClassName": {
"description": "Name of the PriorityClass the controller ensures exists and stamps\nonto pods of workloads carrying this tier. Acts as the native\npreemption safety net independent of the controller's own\nreconcile latency.",
"minLength": 1,
"type": "string"
},
"priorityValue": {
"description": "Value used when the controller creates the PriorityClass named\nabove, if it does not already exist. Higher preempts lower.\nIgnored if a PriorityClass with that name already exists.",
"format": "int32",
"type": "integer"
},
"reschedule": {
"description": "Controls how quickly pods of this tier are rescheduled off a node\nthat has gone NotReady/Unreachable, overriding the cluster default\n(node.kubernetes.io/not-ready and .../unreachable tolerationSeconds,\nnormally 300s).",
"properties": {
"fastTolerationSeconds": {
"description": "tolerationSeconds the controller stamps for the not-ready and\nunreachable node taints on this tier's pods. Omit to leave the\ncluster default in place.",
"format": "int32",
"minimum": 0,
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"resources": {
"description": "Optional hook into a resource right-sizing mechanism (e.g. Attune)\nduring a degraded-capacity window. Left empty, this tier's pod\nresource requests are never adjusted by the controller.",
"properties": {
"resizerRef": {
"description": "Reference to the object the controller annotates/patches to request a resize pass (e.g. an AttunePolicy).",
"properties": {
"apiVersion": {
"type": "string"
},
"kind": {
"type": "string"
},
"name": {
"type": "string"
},
"namespace": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"shrinkOnDegradedCapacity": {
"default": false,
"description": "If true, the controller signals the configured right-sizer\n(see resizerRef) to reduce this tier's resource requests while\ncluster capacity is reduced. Requires in-place pod resize\nsupport (Kubernetes 1.32+) on the cluster.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"storage": {
"description": "Longhorn-specific behavior during the graceful cordon path. No effect on the unexpected node-loss path.",
"properties": {
"preMigrateLonghorn": {
"default": false,
"description": "If true, the controller triggers Longhorn replica migration off\nthe cordoning node and waits for volume health before allowing\nthe drain to proceed, for volumes backing this tier's workloads.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"priorityClassName"
],
"type": "object",
"additionalProperties": false
},
"status": {
"properties": {
"appliedWorkloadCount": {
"description": "Number of workloads currently selected by this tier's label across the cluster.",
"format": "int32",
"type": "integer"
},
"conditions": {
"items": {
"properties": {
"lastTransitionTime": {
"format": "date-time",
"type": "string"
},
"message": {
"type": "string"
},
"observedGeneration": {
"format": "int64",
"type": "integer"
},
"reason": {
"type": "string"
},
"status": {
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"type": "string"
}
},
"required": [
"type",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"observedGeneration": {
"format": "int64",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"spec"
],
"type": "object"
}
@@ -24,6 +24,8 @@
}, },
"exposeName": { "exposeName": {
"description": "ExposeName is the name of the service to expose.\nBy default it uses <namespace>-<name>.", "description": "ExposeName is the name of the service to expose.\nBy default it uses <namespace>-<name>.",
"maxLength": 253,
"pattern": "^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$",
"type": "string" "type": "string"
}, },
"healthCheck": { "healthCheck": {
@@ -1090,7 +1090,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1231,7 +1231,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1286,7 +1286,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1455,7 +1455,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1510,7 +1510,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1909,7 +1909,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1964,7 +1964,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2191,7 +2191,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2266,6 +2266,11 @@
"description": "clusterLabel defines the identifier that uniquely identifies the Alertmanager cluster.\nYou should only set it when the Alertmanager cluster includes Alertmanager instances which are external to this Alertmanager resource. In practice, the addresses of the external instances are provided via the `.spec.additionalPeers` field.", "description": "clusterLabel defines the identifier that uniquely identifies the Alertmanager cluster.\nYou should only set it when the Alertmanager cluster includes Alertmanager instances which are external to this Alertmanager resource. In practice, the addresses of the external instances are provided via the `.spec.additionalPeers` field.",
"type": "string" "type": "string"
}, },
"clusterPeerName": {
"description": "clusterPeerName defines the name that this Alertmanager instance uses to\nadvertise itself to other cluster peers (the `--cluster.peer-name` flag,\navailable since Alertmanager v0.30.0).\n\nIf not set, the operator defaults to the pod's name (`$(POD_NAME)`),\nwhich is injected via the Kubernetes downward API. Setting this field\nlets you override that default with either a literal value or a string\nreferencing environment variables that are already available in the\nAlertmanager container (for example `$(POD_NAME).$(NAMESPACE)`).\n\n/ It requires Alertmanager >= 0.30.0.",
"minLength": 1,
"type": "string"
},
"clusterPeerTimeout": { "clusterPeerTimeout": {
"description": "clusterPeerTimeout defines the timeout for cluster peering.", "description": "clusterPeerTimeout defines the timeout for cluster peering.",
"pattern": "^(0|(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$", "pattern": "^(0|(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
@@ -2289,7 +2294,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2344,7 +2349,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2458,7 +2463,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2524,7 +2529,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2691,7 +2696,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2959,6 +2964,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3080,6 +3089,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3170,6 +3183,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3234,6 +3251,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3372,6 +3393,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3436,6 +3461,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3807,6 +3836,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3871,6 +3904,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3989,8 +4026,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -4235,7 +4280,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4503,6 +4548,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4624,6 +4673,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4714,6 +4767,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4778,6 +4835,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4916,6 +4977,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4980,6 +5045,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -5351,6 +5420,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -5415,6 +5488,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -5533,8 +5610,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -5841,7 +5926,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -5976,6 +6061,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -6015,7 +6105,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6039,7 +6129,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6230,7 +6320,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6254,7 +6344,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6487,6 +6577,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -6712,8 +6851,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -6932,6 +7079,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -6949,6 +7101,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7025,6 +7182,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -7089,6 +7251,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7111,6 +7278,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -7150,7 +7322,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7174,7 +7346,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7679,6 +7851,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -7749,6 +7926,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7777,6 +7959,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7870,6 +8057,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7913,6 +8105,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -7948,6 +8145,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7989,6 +8191,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8173,6 +8380,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -8190,6 +8402,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8357,7 +8574,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8423,7 +8640,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -401,7 +401,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -542,7 +542,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -597,7 +597,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -770,7 +770,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -825,7 +825,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1112,7 +1112,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1167,7 +1167,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1427,7 +1427,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1568,7 +1568,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1623,7 +1623,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1796,7 +1796,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1851,7 +1851,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2153,7 +2153,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2294,7 +2294,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2349,7 +2349,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2522,7 +2522,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2577,7 +2577,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2948,7 +2948,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3089,7 +3089,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3144,7 +3144,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3317,7 +3317,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3372,7 +3372,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3760,7 +3760,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3901,7 +3901,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3956,7 +3956,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4129,7 +4129,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4184,7 +4184,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4576,7 +4576,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4717,7 +4717,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4772,7 +4772,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4945,7 +4945,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5000,7 +5000,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5438,7 +5438,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5579,7 +5579,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5634,7 +5634,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5807,7 +5807,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5862,7 +5862,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6368,7 +6368,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6509,7 +6509,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6564,7 +6564,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6737,7 +6737,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6792,7 +6792,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7139,7 +7139,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7280,7 +7280,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7335,7 +7335,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7508,7 +7508,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7563,7 +7563,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7713,7 +7713,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -7979,7 +7979,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8120,7 +8120,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8175,7 +8175,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8348,7 +8348,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8403,7 +8403,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8746,7 +8746,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8887,7 +8887,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8942,7 +8942,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9115,7 +9115,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9170,7 +9170,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9461,7 +9461,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9602,7 +9602,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9657,7 +9657,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9830,7 +9830,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9885,7 +9885,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10160,7 +10160,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10301,7 +10301,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10356,7 +10356,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10529,7 +10529,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10584,7 +10584,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10930,7 +10930,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11071,7 +11071,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11126,7 +11126,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11299,7 +11299,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11354,7 +11354,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -339,7 +339,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -480,7 +480,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -535,7 +535,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -826,7 +826,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -881,7 +881,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -288,7 +288,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -429,7 +429,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -484,7 +484,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1006,7 +1006,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1061,7 +1061,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1265,7 +1265,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -1334,7 +1334,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1393,7 +1393,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1690,7 +1690,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1749,7 +1749,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1940,7 +1940,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2208,6 +2208,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2329,6 +2333,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2419,6 +2427,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2483,6 +2495,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2621,6 +2637,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2685,6 +2705,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3056,6 +3080,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3120,6 +3148,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3238,8 +3270,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -3298,7 +3338,7 @@
"type": "boolean" "type": "boolean"
}, },
"disableCompaction": { "disableCompaction": {
"description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.41.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.41.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.", "description": "disableCompaction when true, the Prometheus compaction is disabled.\n\nWhen `spec.thanos.objectStorageConfig` or `spec.thanos.objectStorageConfigFile` are defined, the operator's\ndefault handling depends on the Prometheus and Thanos sidecar versions:\n - With Prometheus < v3.9.0 or a Thanos sidecar < v0.42.0, block compaction is disabled to avoid race\n conditions during block uploads (as the Thanos documentation recommends).\n - With Prometheus >= v3.9.0 and a Thanos sidecar >= v0.42.0, local compaction is kept enabled and coordinated\n with the sidecar through the shipper meta file (`--storage.tsdb.delay-compact-file.path`), so blocks are only\n compacted after they have been uploaded.\nSetting this field to true always disables local compaction regardless of the versions.",
"type": "boolean" "type": "boolean"
}, },
"dnsConfig": { "dnsConfig": {
@@ -3619,7 +3659,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3887,6 +3927,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4008,6 +4052,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4098,6 +4146,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4162,6 +4214,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4300,6 +4356,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4364,6 +4424,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4735,6 +4799,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4799,6 +4867,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4917,8 +4989,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -5588,7 +5668,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5729,7 +5809,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5784,7 +5864,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5969,7 +6049,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6028,7 +6108,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6437,7 +6517,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6578,7 +6658,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6633,7 +6713,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6888,7 +6968,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -6952,7 +7032,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7011,7 +7091,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7295,10 +7375,23 @@
"additionalProperties": false "additionalProperties": false
}, },
"retention": { "retention": {
"description": "retention defines how long to retain the Prometheus data.\n\nDefault: \"24h\" if `spec.retention` and `spec.retentionSize` are empty.", "description": "retention defines how long to retain the Prometheus data.\n\nDefault: \"24h\" if `spec.retention`, `spec.retentionSize` and\n`spec.retentionPercentage` are empty.",
"pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$", "pattern": "^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$",
"type": "string" "type": "string"
}, },
"retentionPercentage": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "retentionPercentage defines the maximum percentage of the data volume's\ncapacity used by the Prometheus data.\n\nThe value is a number between 0 and 100. If set to 0, percentage-based\nretention is disabled.\n\nIt requires Prometheus >= v3.11.0 and is ignored by older versions.",
"pattern": "^(\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\+|-)?(([0-9]+(\\.[0-9]*)?)|(\\.[0-9]+))))?$",
"x-kubernetes-int-or-string": true
},
"retentionSize": { "retentionSize": {
"description": "retentionSize defines the maximum number of bytes used by the Prometheus data.", "description": "retentionSize defines the maximum number of bytes used by the Prometheus data.",
"pattern": "(^0|([0-9]*[.])?[0-9]+((K|M|G|T|E|P)i?)?B)$", "pattern": "(^0|([0-9]*[.])?[0-9]+((K|M|G|T|E|P)i?)?B)$",
@@ -7681,7 +7774,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7740,7 +7833,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8052,7 +8145,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -8365,6 +8458,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -8404,7 +8502,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8428,7 +8526,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8619,7 +8717,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8643,7 +8741,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8876,6 +8974,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -8986,7 +9133,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9045,7 +9192,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9354,8 +9501,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -9597,7 +9752,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9656,7 +9811,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9867,8 +10022,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -10087,6 +10250,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -10104,6 +10272,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -10180,6 +10353,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -10244,6 +10422,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -10266,6 +10449,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -10305,7 +10493,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -10329,7 +10517,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -10834,6 +11022,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -10904,6 +11097,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -10932,6 +11130,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11025,6 +11228,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11068,6 +11276,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -11103,6 +11316,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11144,6 +11362,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11328,6 +11551,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -11345,6 +11573,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -11514,7 +11747,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11580,7 +11813,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1015,7 +1015,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1074,7 +1074,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1261,7 +1261,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1529,6 +1529,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1650,6 +1654,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1740,6 +1748,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -1804,6 +1816,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1942,6 +1958,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2006,6 +2026,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2377,6 +2401,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2441,6 +2469,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2559,8 +2591,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -2914,7 +2954,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3182,6 +3222,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3303,6 +3347,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3393,6 +3441,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3457,6 +3509,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3595,6 +3651,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3659,6 +3719,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4030,6 +4094,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -4094,6 +4162,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4212,8 +4284,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -4980,7 +5060,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5121,7 +5201,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5176,7 +5256,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5431,7 +5511,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -5495,7 +5575,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5554,7 +5634,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6089,7 +6169,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6148,7 +6228,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6460,7 +6540,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -6739,6 +6819,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -6778,7 +6863,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6802,7 +6887,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6993,7 +7078,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7017,7 +7102,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7250,6 +7335,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -7497,7 +7631,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7556,7 +7690,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7767,8 +7901,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -7987,6 +8129,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -8004,6 +8151,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8080,6 +8232,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -8144,6 +8301,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8166,6 +8328,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -8205,7 +8372,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8229,7 +8396,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -8734,6 +8901,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -8804,6 +8976,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8832,6 +9009,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8925,6 +9107,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8968,6 +9155,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -9003,6 +9195,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -9044,6 +9241,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -9228,6 +9430,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -9245,6 +9452,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -9414,7 +9626,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9480,7 +9692,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -211,7 +211,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -352,7 +352,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -407,7 +407,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -603,7 +603,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -658,7 +658,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -980,7 +980,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1121,7 +1121,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1176,7 +1176,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1368,6 +1368,7 @@
"services": { "services": {
"description": "services defines a list of services for which targets are retrieved. If omitted, all services are scraped.", "description": "services defines a list of services for which targets are retrieved. If omitted, all services are scraped.",
"items": { "items": {
"minLength": 1,
"type": "string" "type": "string"
}, },
"type": "array", "type": "array",
@@ -1381,6 +1382,7 @@
"tags": { "tags": {
"description": "tags defines an optional list of tags used to filter nodes for a given service. Services must contain all tags in the list.\nStarting with Consul 1.14, it is recommended to use `filter` with the `ServiceTags` selector instead.", "description": "tags defines an optional list of tags used to filter nodes for a given service. Services must contain all tags in the list.\nStarting with Consul 1.14, it is recommended to use `filter` with the `ServiceTags` selector instead.",
"items": { "items": {
"minLength": 1,
"type": "string" "type": "string"
}, },
"type": "array", "type": "array",
@@ -1396,7 +1398,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1451,7 +1453,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1654,7 +1656,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1795,7 +1797,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1850,7 +1852,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2031,7 +2033,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2086,7 +2088,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2381,7 +2383,6 @@
}, },
"host": { "host": {
"description": "host defines the address of the docker daemon.", "description": "host defines the address of the docker daemon.",
"minLength": 1,
"pattern": "^[a-zA-Z][a-zA-Z0-9+.-]*://.+$", "pattern": "^[a-zA-Z][a-zA-Z0-9+.-]*://.+$",
"type": "string" "type": "string"
}, },
@@ -2408,7 +2409,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2549,7 +2550,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2604,7 +2605,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2785,7 +2786,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2840,7 +2841,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3109,7 +3110,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3250,7 +3251,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3305,7 +3306,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3495,7 +3496,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3550,7 +3551,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3836,7 +3837,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -3891,7 +3892,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4126,7 +4127,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4267,7 +4268,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4322,7 +4323,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4501,7 +4502,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4556,7 +4557,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4879,7 +4880,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5020,7 +5021,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5075,7 +5076,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5249,9 +5250,7 @@
"role": { "role": {
"description": "role defines the Hetzner role of entities that should be discovered.", "description": "role defines the Hetzner role of entities that should be discovered.",
"enum": [ "enum": [
"hcloud",
"Hcloud", "Hcloud",
"robot",
"Robot" "Robot"
], ],
"type": "string" "type": "string"
@@ -5266,7 +5265,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5321,7 +5320,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5559,7 +5558,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5700,7 +5699,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5755,7 +5754,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5929,7 +5928,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5984,7 +5983,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6169,7 +6168,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6310,7 +6309,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6365,7 +6364,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6546,7 +6545,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6601,7 +6600,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -6851,6 +6850,7 @@
"names": { "names": {
"description": "names defines a list of namespaces where to watch for resources.\nIf empty and `ownNamespace` isn't true, Prometheus watches for resources in all namespaces.", "description": "names defines a list of namespaces where to watch for resources.\nIf empty and `ownNamespace` isn't true, Prometheus watches for resources in all namespaces.",
"items": { "items": {
"minLength": 1,
"type": "string" "type": "string"
}, },
"type": "array", "type": "array",
@@ -6878,7 +6878,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7019,7 +7019,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7074,7 +7074,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7295,7 +7295,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7350,7 +7350,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7590,7 +7590,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7731,7 +7731,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7786,7 +7786,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -7965,7 +7965,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8020,7 +8020,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8297,7 +8297,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8438,7 +8438,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8493,7 +8493,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8708,7 +8708,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8763,7 +8763,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8935,7 +8935,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9076,7 +9076,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9131,7 +9131,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9322,7 +9322,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9377,7 +9377,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9730,7 +9730,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9871,7 +9871,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -9926,7 +9926,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10115,7 +10115,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10170,7 +10170,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10293,7 +10293,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10434,7 +10434,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10489,7 +10489,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10654,11 +10654,8 @@
"description": "availability defines the availability of the endpoint to connect to.", "description": "availability defines the availability of the endpoint to connect to.",
"enum": [ "enum": [
"Public", "Public",
"public",
"Admin", "Admin",
"admin", "Internal"
"Internal",
"internal"
], ],
"type": "string" "type": "string"
}, },
@@ -10747,7 +10744,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -10802,7 +10799,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11187,7 +11184,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11328,7 +11325,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11383,7 +11380,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11569,7 +11566,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11624,7 +11621,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -11962,7 +11959,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -12017,7 +12014,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -12237,7 +12234,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -12292,7 +12289,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -267,7 +267,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -408,7 +408,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -463,7 +463,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -747,7 +747,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -806,7 +806,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -938,7 +938,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -1206,6 +1206,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1327,6 +1331,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1417,6 +1425,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -1481,6 +1493,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -1619,6 +1635,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -1683,6 +1703,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2054,6 +2078,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -2118,6 +2146,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -2236,8 +2268,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -2433,7 +2473,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2492,7 +2532,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2728,7 +2768,7 @@
"description": "Selects a key of a ConfigMap.", "description": "Selects a key of a ConfigMap.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -2996,6 +3036,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3117,6 +3161,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3207,6 +3255,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3271,6 +3323,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3409,6 +3465,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3473,6 +3533,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -3844,6 +3908,10 @@
"grpc": { "grpc": {
"description": "GRPC specifies a GRPC HealthCheckRequest.", "description": "GRPC specifies a GRPC HealthCheckRequest.",
"properties": { "properties": {
"mode": {
"description": "mode specifies the connection mode for the gRPC health probe.\nSet to \"TLS\" to use TLS without certificate verification.\nSet to \"Plaintext\" to use a plaintext (insecure) connection explicitly.\nIf not specified, the probe uses a plaintext (insecure) connection.",
"type": "string"
},
"port": { "port": {
"description": "Port number of the gRPC service. Number must be in the range 1 to 65535.", "description": "Port number of the gRPC service. Number must be in the range 1 to 65535.",
"format": "int32", "format": "int32",
@@ -3908,6 +3976,10 @@
"description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.", "description": "Name or number of the port to access on the container.\nNumber must be in the range 1 to 65535.\nName must be an IANA_SVC_NAME.",
"x-kubernetes-int-or-string": true "x-kubernetes-int-or-string": true
}, },
"protocol": {
"description": "Protocol selects the wire protocol for the probe connection.\nNil defaults to HTTP/1.1.",
"type": "string"
},
"scheme": { "scheme": {
"description": "Scheme to use for connecting to the host.\nDefaults to HTTP.", "description": "Scheme to use for connecting to the host.\nDefaults to HTTP.",
"type": "string" "type": "string"
@@ -4026,8 +4098,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -4536,7 +4616,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4677,7 +4757,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4732,7 +4812,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -4987,7 +5067,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"externalId": { "externalId": {
"description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.33.0. Currently not supported by Thanos.", "description": "externalId defines the external ID used when assuming an AWS role. Can only be used with roleArn.\nIt requires Prometheus >= v3.11.0 or Alertmanager >= v0.34.0. Currently not supported by Thanos.",
"minLength": 1, "minLength": 1,
"type": "string" "type": "string"
}, },
@@ -5051,7 +5131,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5110,7 +5190,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -5556,7 +5636,7 @@
"type": "integer" "type": "integer"
}, },
"seLinuxChangePolicy": { "seLinuxChangePolicy": {
"description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\"MountOption\" value is allowed only when SELinuxMount feature gate is enabled.\n\nIf not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used.\nIf not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes\nand \"Recursive\" for all other volumes.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.", "description": "seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.\nIt has no effect on nodes that do not support SELinux or to volumes does not support SELinux.\nValid values are \"MountOption\" and \"Recursive\".\n\n\"Recursive\" means relabeling of all files on all Pod volumes by the container runtime.\nThis may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.\n\n\"MountOption\" mounts all eligible Pod volumes with `-o context` mount option.\nThis requires all Pods that share the same volume to use the same SELinux label.\nIt is not possible to share the same volume among privileged and unprivileged Pods.\nEligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes\nwhose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their\nCSIDriver instance. Other volumes are always re-labelled recursively.\n\nIf not specified, \"MountOption\" is used.\n\nThis field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.\n\nAll Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.\nNote that this field cannot be set when spec.os.name is windows.",
"type": "string" "type": "string"
}, },
"seLinuxOptions": { "seLinuxOptions": {
@@ -5687,6 +5767,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -5726,7 +5811,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -5750,7 +5835,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -5941,7 +6026,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -5965,7 +6050,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6198,6 +6283,55 @@
"description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim", "description": "currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using.\nWhen unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim",
"type": "string" "type": "string"
}, },
"healthStatus": {
"description": "healthStatus contains the latest controller-reported health information\nfor the volume bound to this claim.",
"properties": {
"healthConditions": {
"description": "conditions is the set of adverse conditions reported by\nthe CSI controller plugin. An empty list means no adverse condition.\nAt most 16 conditions may be reported.",
"items": {
"description": "VolumeHealthCondition represents an adverse health condition reported for a volume.",
"properties": {
"message": {
"description": "message is a human-readable description.\nMaximum permitted length of a message is 1024 bytes.",
"type": "string"
},
"reason": {
"description": "reason is a brief CamelCase machine-parseable reason.\nTogether with status it forms the unique identity of a condition entry.\nMaximum permitted length of a reason is 256 bytes.",
"type": "string"
},
"status": {
"description": "status is the machine-parseable health category.\nPossible values:\n- \"Inaccessible\": the volume cannot be accessed.\n- \"DataLoss\": data loss has been detected on the volume.\n- \"Degraded\": the volume is functioning with reduced capability.",
"enum": [
"DataLoss",
"Degraded",
"Inaccessible"
],
"type": "string"
}
},
"required": [
"reason",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"status",
"reason"
],
"x-kubernetes-list-type": "map"
},
"lastTransitionTime": {
"description": "lastTransitionTime is when the current set of conditions first appeared.",
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"modifyVolumeStatus": { "modifyVolumeStatus": {
"description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.", "description": "ModifyVolumeStatus represents the status object of ControllerModifyVolume operation.\nWhen this is unset, there is no ModifyVolume operation being attempted.",
"properties": { "properties": {
@@ -6447,8 +6581,16 @@
"items": { "items": {
"description": "VolumeMount describes a mounting of a Volume within a container.", "description": "VolumeMount describes a mounting of a Volume within a container.",
"properties": { "properties": {
"bindMountOptions": {
"description": "bindMountOptions is the list of additional bind mount options to apply when\nmounting this volume into the container. Allowed values are noexec,\nnodev, and nosuid. These are Linux mount options and have no effect on\nWindows nodes.\nThis field is not supported with image volumes.\nThis is an alpha field and requires enabling the VolumeBindMountOptions feature gate.",
"items": {
"type": "string"
},
"type": "array",
"x-kubernetes-list-type": "set"
},
"mountPath": { "mountPath": {
"description": "Path within the container at which the volume should be mounted. Must\nnot contain ':'.", "description": "Path within the container at which the volume should be mounted.",
"type": "string" "type": "string"
}, },
"mountPropagation": { "mountPropagation": {
@@ -6667,6 +6809,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items if unspecified, each key-value pair in the Data field of the referenced\nConfigMap will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the ConfigMap,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -6684,6 +6831,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -6760,6 +6912,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "Items is a list of downward API volume file", "description": "Items is a list of downward API volume file",
"items": { "items": {
@@ -6824,6 +6981,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -6846,6 +7008,11 @@
"description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir", "description": "medium represents what type of storage medium should back this directory.\nThe default is \"\" which means to use the node's default medium.\nMust be an empty string (default) or Memory.\nMore info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir",
"type": "string" "type": "string"
}, },
"mode": {
"description": "mode specifies the permission bits for the emptyDir directory, in numeric\nnotation (e.g., 0755, 01777). Must be a value between 0000 and 01777.\nIf not specified, defaults to 0777.\nThis might be in conflict with other options that affect the file\nmode, like fsGroup. If fsGroup is specified, the fsGroup permissions\nwill override the mode specified here.\nThis field has no effect on Windows.\nThis field is alpha and requires EmptyDirVolumeMode featuregate to be enabled.",
"format": "int32",
"type": "integer"
},
"sizeLimit": { "sizeLimit": {
"anyOf": [ "anyOf": [
{ {
@@ -6885,7 +7052,7 @@
"x-kubernetes-list-type": "atomic" "x-kubernetes-list-type": "atomic"
}, },
"dataSource": { "dataSource": {
"description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\nWhen the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,\nand dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.", "description": "dataSource field can be used to specify either:\n* An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)\n* An existing PVC (PersistentVolumeClaim)\nIf the provisioner or an external controller can support the specified data source,\nit will create a new volume based on the contents of the specified data source.\ndataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be\ncopied to dataSource when dataSourceRef.namespace is not specified.\nIf the namespace is specified, then dataSourceRef will not be copied to dataSource.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -6909,7 +7076,7 @@
"additionalProperties": false "additionalProperties": false
}, },
"dataSourceRef": { "dataSourceRef": {
"description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.", "description": "dataSourceRef specifies the object from which to populate the volume with data, if a non-empty\nvolume is desired. This may be any object from a non-empty API group (non\ncore object) or a PersistentVolumeClaim object.\nWhen this field is specified, volume binding will only succeed if the type of\nthe specified object matches some installed volume populator or dynamic\nprovisioner.\nThis field will replace the functionality of the dataSource field and as such\nif both fields are non-empty, they must have the same value. For backwards\ncompatibility, when namespace isn't specified in dataSourceRef,\nboth fields (dataSource and dataSourceRef) will be set to the same\nvalue automatically if one of them is empty and the other is non-empty.\nWhen namespace is specified in dataSourceRef,\ndataSource isn't set to the same value and must be empty.\nThere are three important differences between dataSource and dataSourceRef:\n* While dataSource only allows two specific types of objects, dataSourceRef\n allows any non-core object, as well as PersistentVolumeClaim objects.\n* While dataSource ignores disallowed values (dropping them), dataSourceRef\n preserves all values, and generates an error if a disallowed value is\n specified.\n* While dataSource only allows local objects, dataSourceRef allows objects\n in any namespaces.\n(Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.",
"properties": { "properties": {
"apiGroup": { "apiGroup": {
"description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.", "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
@@ -7414,6 +7581,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"sources": { "sources": {
"description": "sources is the list of volume projections. Each entry in this list\nhandles one source.", "description": "sources is the list of volume projections. Each entry in this list\nhandles one source.",
"items": { "items": {
@@ -7484,6 +7656,11 @@
"signerName": { "signerName": {
"description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.", "description": "Select all ClusterTrustBundles that match this signer name.\nMutually-exclusive with name. The contents of all selected\nClusterTrustBundles will be unified and deduplicated.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7512,6 +7689,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7605,6 +7787,11 @@
"type": "object", "type": "object",
"x-kubernetes-map-type": "atomic", "x-kubernetes-map-type": "atomic",
"additionalProperties": false "additionalProperties": false
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7648,6 +7835,11 @@
"description": "Kubelet's generated CSRs will be addressed to this signer.", "description": "Kubelet's generated CSRs will be addressed to this signer.",
"type": "string" "type": "string"
}, },
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"userAnnotations": { "userAnnotations": {
"additionalProperties": { "additionalProperties": {
"type": "string" "type": "string"
@@ -7683,6 +7875,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7724,6 +7921,11 @@
"path": { "path": {
"description": "path is the path relative to the mount point of the file to project the\ntoken into.", "description": "path is the path relative to the mount point of the file to project the\ntoken into.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -7908,6 +8110,11 @@
"format": "int32", "format": "int32",
"type": "integer" "type": "integer"
}, },
"defaultUser": {
"description": "defaultUser is Optional: The owner UID of the created files by default.\nThe defaultUser field is only used as a fallback when the item-level user field is unset.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
},
"items": { "items": {
"description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.", "description": "items If unspecified, each key-value pair in the Data field of the referenced\nSecret will be projected into the volume as a file whose name is the\nkey and content is the value. If specified, the listed keys will be\nprojected into the specified paths, and unlisted keys will not be\npresent. If a key is specified which is not present in the Secret,\nthe volume setup will error unless it is marked optional. Paths must be\nrelative and may not contain the '..' path or start with '..'.",
"items": { "items": {
@@ -7925,6 +8132,11 @@
"path": { "path": {
"description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.", "description": "path is the relative path of the file to map the key to.\nMay not be an absolute path.\nMay not contain the path element '..'.\nMay not start with the string '..'.",
"type": "string" "type": "string"
},
"user": {
"description": "user is Optional: The owner UID of the created file.\nIf specified, the item-level user field takes precedence over defaultUser.\n(Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled.",
"format": "int64",
"type": "integer"
} }
}, },
"required": [ "required": [
@@ -8080,7 +8292,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -8146,7 +8358,7 @@
"description": "configMap defines the ConfigMap containing data to use for the targets.", "description": "configMap defines the ConfigMap containing data to use for the targets.",
"properties": { "properties": {
"key": { "key": {
"description": "The key to select.", "description": "The key to select from the ConfigMap's Data field.\nKeys in the BinaryData field are not currently propagated to container env vars.",
"type": "string" "type": "string"
}, },
"name": { "name": {
@@ -0,0 +1,202 @@
{
"description": "Tier defines the centralized resiliency and scaling policy for a class of\napplications (e.g. critical, standard, best-effort). Workloads opt in by\ncarrying the label `platform.olb42.com/tier: <tier name>` \u2014 no per-app\nHPA/PDB/toleration configuration is required. The tier-controller watches\nNode state and applies each Tier's policy to every workload selected by\nthat label.",
"properties": {
"apiVersion": {
"type": "string"
},
"kind": {
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"properties": {
"capacity": {
"description": "How replica counts for this tier react to a change in ready/schedulable node count.",
"properties": {
"minReplicasFloor": {
"default": 1,
"description": "Replica count this tier's workloads are never scaled below by\nthe controller, regardless of how many nodes are lost.",
"format": "int32",
"minimum": 0,
"type": "integer"
},
"replicaLossPerNode": {
"default": 0,
"description": "Replicas to shed per node lost (unexpected loss) or cordoned\n(intentional maintenance), before floor is applied. 0 means the\nworkload's replica count is never reduced by node loss alone.",
"format": "int32",
"minimum": 0,
"type": "integer"
},
"scaleToZeroOnCordon": {
"default": false,
"description": "Same as scaleToZeroOnNodeLoss, but for the intentional\ncordon/drain path.",
"type": "boolean"
},
"scaleToZeroOnNodeLoss": {
"default": false,
"description": "If true, workloads in this tier are scaled to 0 replicas on\nunexpected node loss, freeing capacity for higher tiers.\nminReplicasFloor is ignored when this is true.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"deletionCostBase": {
"default": 0,
"description": "Baseline value stamped as the\ncontroller.kubernetes.io/pod-deletion-cost annotation on pods of\nthis tier. Higher values are removed later during a voluntary\nscale-down, so this should be set relative to the other tiers'\nvalues (e.g. critical=1000, standard=500, best-effort=0).",
"format": "int32",
"type": "integer"
},
"disruption": {
"description": "Voluntary-disruption budget applied to workloads in this tier.",
"properties": {
"pdbMinAvailable": {
"anyOf": [
{
"type": "integer"
},
{
"type": "string"
}
],
"description": "Value for the PodDisruptionBudget's spec.minAvailable the\ncontroller manages for each workload in this tier. Accepts an\nabsolute number or a percentage string (e.g. \"50%\"), matching\nnative PDB semantics.",
"x-kubernetes-int-or-string": true
}
},
"type": "object",
"additionalProperties": false
},
"priorityClassName": {
"description": "Name of the PriorityClass the controller ensures exists and stamps\nonto pods of workloads carrying this tier. Acts as the native\npreemption safety net independent of the controller's own\nreconcile latency.",
"minLength": 1,
"type": "string"
},
"priorityValue": {
"description": "Value used when the controller creates the PriorityClass named\nabove, if it does not already exist. Higher preempts lower.\nIgnored if a PriorityClass with that name already exists.",
"format": "int32",
"type": "integer"
},
"reschedule": {
"description": "Controls how quickly pods of this tier are rescheduled off a node\nthat has gone NotReady/Unreachable, overriding the cluster default\n(node.kubernetes.io/not-ready and .../unreachable tolerationSeconds,\nnormally 300s).",
"properties": {
"fastTolerationSeconds": {
"description": "tolerationSeconds the controller stamps for the not-ready and\nunreachable node taints on this tier's pods. Omit to leave the\ncluster default in place.",
"format": "int32",
"minimum": 0,
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"resources": {
"description": "Optional hook into a resource right-sizing mechanism (e.g. Attune)\nduring a degraded-capacity window. Left empty, this tier's pod\nresource requests are never adjusted by the controller.",
"properties": {
"resizerRef": {
"description": "Reference to the object the controller annotates/patches to request a resize pass (e.g. an AttunePolicy).",
"properties": {
"apiVersion": {
"type": "string"
},
"kind": {
"type": "string"
},
"name": {
"type": "string"
},
"namespace": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"shrinkOnDegradedCapacity": {
"default": false,
"description": "If true, the controller signals the configured right-sizer\n(see resizerRef) to reduce this tier's resource requests while\ncluster capacity is reduced. Requires in-place pod resize\nsupport (Kubernetes 1.32+) on the cluster.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"storage": {
"description": "Longhorn-specific behavior during the graceful cordon path. No effect on the unexpected node-loss path.",
"properties": {
"preMigrateLonghorn": {
"default": false,
"description": "If true, the controller triggers Longhorn replica migration off\nthe cordoning node and waits for volume health before allowing\nthe drain to proceed, for volumes backing this tier's workloads.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"priorityClassName"
],
"type": "object",
"additionalProperties": false
},
"status": {
"properties": {
"appliedWorkloadCount": {
"description": "Number of workloads currently selected by this tier's label across the cluster.",
"format": "int32",
"type": "integer"
},
"conditions": {
"items": {
"properties": {
"lastTransitionTime": {
"format": "date-time",
"type": "string"
},
"message": {
"type": "string"
},
"observedGeneration": {
"format": "int64",
"type": "integer"
},
"reason": {
"type": "string"
},
"status": {
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"type": "string"
}
},
"required": [
"type",
"status"
],
"type": "object",
"additionalProperties": false
},
"type": "array"
},
"observedGeneration": {
"format": "int64",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
}
},
"required": [
"spec"
],
"type": "object"
}
@@ -279,6 +279,13 @@
"errors": { "errors": {
"description": "ErrorPage holds the custom error middleware configuration.\nThis middleware returns a custom page in lieu of the default, according to configured ranges of HTTP Status codes.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/middlewares/errorpages/", "description": "ErrorPage holds the custom error middleware configuration.\nThis middleware returns a custom page in lieu of the default, according to configured ranges of HTTP Status codes.\nMore info: https://doc.traefik.io/traefik/v3.7/reference/routing-configuration/http/middlewares/errorpages/",
"properties": { "properties": {
"errorRequestHeaders": {
"description": "ErrorRequestHeaders defines the list of request headers forwarded to the error page service.\nWhen nil (not set), all original request headers are forwarded.\nSet to an empty list to forward no headers, or list specific headers to forward only those.",
"items": {
"type": "string"
},
"type": "array"
},
"query": { "query": {
"description": "Query defines the URL for the error page (hosted by service).\nThe {status} variable can be used in order to insert the status code in the URL.\nThe {originalStatus} variable can be used in order to insert the upstream status code in the URL.\nThe {url} variable can be used in order to insert the escaped request URL.", "description": "Query defines the URL for the error page (hosted by service).\nThe {status} variable can be used in order to insert the status code in the URL.\nThe {originalStatus} variable can be used in order to insert the upstream status code in the URL.\nThe {url} variable can be used in order to insert the escaped request URL.",
"type": "string" "type": "string"