{ "description": "Pomerium define runtime-configurable Pomerium settings\nthat do not fall into the category of deployment parameters", "properties": { "apiVersion": { "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources", "type": "string" }, "kind": { "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds", "type": "string" }, "metadata": { "type": "object" }, "spec": { "description": "PomeriumSpec defines Pomerium-specific configuration parameters.", "properties": { "accessLogFields": { "description": "AccessLogFields sets the access fields to log.", "items": { "type": "string" }, "type": "array" }, "allowUpgrades": { "description": "AllowUpgrades sets the allowed upgrade types.", "items": { "type": "string" }, "type": "array" }, "authenticate": { "description": "Authenticate sets authenticate service parameters.\nIf not specified, a Pomerium-hosted authenticate service would be used.", "properties": { "url": { "description": "AuthenticateURL is a dedicated domain URL\nthe non-authenticated persons would be referred to.\n\n
Ingress for this\n\t\tvirtual route, as it is handled by Pomerium internally. certificates.\n\t\tIf you use cert-manager with HTTP01 challenge,\n\t\tyou may use pomerium ingressClass to solve it.ca.crt containing a CA certificate.",
"items": {
"type": "string"
},
"type": "array"
},
"certificateAutoProvision": {
"description": "CertificateAutoProvision sets the certificate auto provision settings.\nThis is a fallback for routes that are not defined via Ingress or\nGateway resources. When configured, cert-manager certificate resources\nwill be created for any routes which have no matching TLS certificate.",
"properties": {
"clusterIssuer": {
"description": "The cert-manager ClusterIssuer that will be used for new certificates.\nCertificates will be created in the same namespace as the controller\npod.",
"minLength": 1,
"type": "string"
},
"issuer": {
"description": "The cert-manager Issuer that will be used for new certificates.\nCertificates will be created in the same namespace as the Issuer.",
"format": "namespace/name",
"minLength": 1,
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"certificates": {
"description": "Certificates is a list of secrets of type TLS to use",
"format": "namespace/name",
"items": {
"type": "string"
},
"type": "array"
},
"circuitBreakerThresholds": {
"description": "CircuitBreakerThresholds sets the circuit breaker thresholds settings.",
"properties": {
"maxConnectionPools": {
"description": "MaxConnectionPools sets the maximum number of connection pools per\ncluster that Envoy will concurrently support at once. If not specified,\nthe default is unlimited. Set this for clusters which create a large\nnumber of connection pools.",
"format": "int32",
"type": "integer"
},
"maxConnections": {
"description": "MaxConnections sets the maximum number of connections that Envoy will\nmake to the upstream cluster. If not specified, the default is 1024.",
"format": "int32",
"type": "integer"
},
"maxPendingRequests": {
"description": "MaxPendingRequests sets the maximum number of pending requests that\nEnvoy will allow to the upstream cluster. If not specified, the\ndefault is 1024. This limit is applied as a connection limit for\nnon-HTTP traffic.",
"format": "int32",
"type": "integer"
},
"maxRequests": {
"description": "MaxRequests sets the maximum number of parallel requests that Envoy\nwill make to the upstream cluster. If not specified, the default is\n1024. This limit does not apply to non-HTTP traffic.",
"format": "int32",
"type": "integer"
},
"maxRetries": {
"description": "MaxRetries sets the maximum number of parallel retries that Envoy\nwill allow to the upstream cluster. If not specified, the default is 3.",
"format": "int32",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"codecType": {
"description": "CodecType sets the Codec Type.",
"enum": [
"auto",
"http1",
"http2",
"http3"
],
"type": "string"
},
"cookie": {
"description": "Cookie defines Pomerium session cookie options.",
"properties": {
"domain": {
"description": "Domain defaults to the same host that set the cookie.\nIf you specify the domain explicitly, then subdomains would also be included.",
"type": "string"
},
"expire": {
"description": "Expire sets cookie and Pomerium session expiration time.\nOnce session expires, users would have to re-login.\nIf you change this parameter, existing sessions are not affected.\nSee Session Management\n(Enterprise) for a more fine-grained session controls.
\nDefaults to 14 hours.
", "format": "duration", "type": "string" }, "httpOnly": { "description": "HTTPOnly if set tofalse, the cookie would be accessible from within the JavaScript.\nDefaults to true.",
"type": "boolean"
},
"name": {
"description": "Name sets the Pomerium session cookie name.\nDefaults to _pomerium",
"type": "string"
},
"sameSite": {
"description": "SameSite sets the SameSite option for cookies.\nDefaults to .",
"enum": [
"strict",
"lax",
"none"
],
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"dataBroker": {
"description": "DataBroker sets the databroker settings.",
"properties": {
"clusterLeaderId": {
"description": "ClusterLeaderID defines the cluster leader in a clustered databroker.",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"dns": {
"description": "DNS sets the dns settings.",
"properties": {
"failureRefreshRate": {
"description": "FailureRefreshRate is the rate at which DNS lookups are refreshed when requests are failing.",
"format": "duration",
"type": "string"
},
"lookupFamily": {
"description": "LookupFamily is the DNS IP address resolution policy.",
"enum": [
"auto",
"v4_only",
"v6_only",
"v4_preferred",
"all"
],
"type": "string"
},
"queryTimeout": {
"description": "QueryTimeout is the amount of time each name server is given to respond to a query on the first try of any given server.",
"format": "duration",
"type": "string"
},
"queryTries": {
"description": "QueryTries is the maximum number of query attempts the resolver will make before giving up. Each attempt may use a different name server.",
"format": "int32",
"type": "integer"
},
"refreshRate": {
"description": "RefreshRate is the rate at which DNS lookups are refreshed.",
"format": "duration",
"type": "string"
},
"udpMaxQueries": {
"description": "UDPMaxQueries caps the number of UDP based DNS queries on a single port.",
"format": "int32",
"type": "integer"
},
"useTcp": {
"description": "UseTCP uses TCP for all DNS queries instead of the default protocol UDP.",
"type": "boolean"
}
},
"type": "object",
"additionalProperties": false
},
"downstreamMtls": {
"description": "DownstreamMTLS sets the Downstream MTLS Settings.",
"properties": {
"ca": {
"description": "CA is a bundle of PEM-encoded X.509 certificates that will be treated as trust anchors when verifying client certificates.",
"format": "byte",
"type": "string"
},
"crl": {
"description": "CRL is a bundle of PEM-encoded certificate revocation lists to be consulted during certificate validation.",
"format": "byte",
"type": "string"
},
"enforcement": {
"description": "Enforcement controls Pomerium's behavior when a client does not present a trusted client certificate.",
"enum": [
"policy_with_default_deny",
"policy",
"reject_connection"
],
"type": "string"
},
"matchSubjectAltNames": {
"description": "Match Subject Alt Names can be used to add an additional constraint when validating client certificates.",
"properties": {
"dns": {
"type": "string"
},
"email": {
"type": "string"
},
"ipAddress": {
"type": "string"
},
"uri": {
"type": "string"
},
"userPrincipalName": {
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"maxVerifyDepth": {
"description": "MaxVerifyDepth sets a limit on the depth of a certificate chain presented by the client.",
"format": "int32",
"type": "integer"
}
},
"type": "object",
"additionalProperties": false
},
"envoyDynamicExtensions": {
"description": "EnvoyDynamicExtensions file paths to the extensions to be loaded by Envoy at runtime.",
"items": {
"type": "string"
},
"type": "array"
},
"headersWithUnderscoresAction": {
"description": "HeadersWithUnderscoresAction controls the behavior for a request with a\nheader name containing an underscore character. The default behavior is\nreject_request.",
"enum": [
"allow",
"reject_request",
"drop_header"
],
"type": "string"
},
"identityProvider": {
"description": "IdentityProvider configure single-sign-on authentication and user identity details\nby integrating with your Identity Provider",
"properties": {
"provider": {
"description": "Provider is the short-hand name of a built-in OpenID Connect (oidc) identity provider to be used for authentication.\nTo use a generic provider, set to oidc.",
"enum": [
"apple",
"auth0",
"azure",
"cognito",
"github",
"gitlab",
"google",
"hosted",
"oidc",
"okta",
"onelogin",
"ping"
],
"type": "string"
},
"refreshDirectory": {
"description": "RefreshDirectory is no longer supported,\nplease see Upgrade Guide.",
"properties": {
"interval": {
"description": "interval is the time that pomerium will sync your IDP directory.",
"format": "duration",
"type": "string"
},
"timeout": {
"description": "timeout is the maximum time allowed each run.",
"format": "duration",
"type": "string"
}
},
"required": [
"interval",
"timeout"
],
"type": "object",
"additionalProperties": false
},
"requestParams": {
"additionalProperties": {
"type": "string"
},
"description": "RequestParams to be added as part of a sign-in request using OAuth2 code flow.",
"format": "namespace/name",
"type": "object"
},
"requestParamsSecret": {
"description": "RequestParamsSecret is a reference to a secret for additional parameters you'd prefer not to provide in plaintext.",
"format": "namespace/name",
"type": "string"
},
"scopes": {
"description": "Scopes Identity provider scopes correspond to access privilege scopes\nas defined in Section 3.3 of OAuth 2.0 RFC6749.",
"items": {
"type": "string"
},
"type": "array"
},
"secret": {
"description": "Secret containing IdP provider specific parameters.\nand must contain at least client_id and client_secret values.",
"format": "namespace/name",
"minLength": 1,
"type": "string"
},
"serviceAccountFromSecret": {
"description": "ServiceAccountFromSecret is no longer supported,\nsee Upgrade Guide.",
"type": "string"
},
"url": {
"description": "URL is the base path to an identity provider's OpenID connect discovery document.\nSee Identity Providers guides for details.",
"format": "uri",
"pattern": "^https://",
"type": "string"
}
},
"required": [
"provider"
],
"type": "object",
"x-kubernetes-validations": [
{
"fieldPath": ".secret",
"message": "secret is required unless provider is 'hosted'",
"reason": "FieldValueRequired",
"rule": "self.provider != 'hosted' ? has(self.secret) : true"
}
],
"additionalProperties": false
},
"idpAccessTokenAllowedAudiences": {
"description": "IDPAccessTokenAllowedAudiences specifies the\nidp access token allowed audiences\nlist.",
"items": {
"type": "string"
},
"type": "array"
},
"jwtClaimHeaders": {
"additionalProperties": {
"type": "string"
},
"description": "JWTClaimHeaders convert claims from the assertion token\ninto HTTP headers and adds them into JWT assertion header.\nPlease make sure to read\n\nGetting User Identity guide.",
"type": "object"
},
"mcpAllowedAsMetadataDomains": {
"description": "MCPAllowedASMetadataDomains specifies the allowed domains for upstream AS/PRM metadata URLs.\nSupports wildcard patterns like \"*.example.com\".\nThis restricts which domains Pomerium will contact during upstream OAuth discovery\n(resource_metadata from WWW-Authenticate, authorization_servers from PRM).\nSee MCP Settings.",
"items": {
"type": "string"
},
"type": "array"
},
"mcpAllowedClientIdDomains": {
"description": "MCPAllowedClientIDDomains specifies the allowed domains for MCP client ID metadata URLs.\nThis is required when MCP is enabled.\nSee MCP Settings.",
"items": {
"type": "string"
},
"type": "array"
},
"mergeSlashes": {
"description": "MergeSlashes controls whether adjacent slashes in the request URI path\nwill be merged into one. Defaults to true.",
"type": "boolean"
},
"normalizePath": {
"description": "NormalizePath controls whether request URI paths will be normalized\naccording to RFC 3986. Defaults to true.",
"type": "boolean"
},
"otel": {
"description": "OTEL sets the OpenTelemetry Tracing.",
"properties": {
"bspMaxExportBatchSize": {
"description": "BSPMaxExportBatchSize sets the maximum number of spans to export in a single batch",
"format": "int32",
"type": "integer"
},
"bspScheduleDelay": {
"description": "BSPScheduleDelay sets interval between two consecutive exports",
"format": "duration",
"type": "string"
},
"endpoint": {
"description": "An OTLP/gRPC or OTLP/HTTP base endpoint URL with optional port.\n
shared_secret\n\t\t- secures inter-Pomerium service communications.\n\tcookie_secret\n\t\t- encrypts Pomerium session browser cookie.\n\t\tSee also other Cookie parameters.\n\tsigning_key\n\t\tsigns Pomerium JWT assertion header. See\n\t\tGetting the user's identity\n\t\tguide.\n\t\nIn a default Pomerium installation manifest, they would be generated via a\none-time job\nand stored in a pomerium/bootstrap Secret.\nYou may re-run the job to rotate the secrets, or update the Secret values manually.\n
\nWhen defining the Secret in a manifest, put raw values in stringData so\nKubernetes base64-encodes them. Use data only when values are already\nbase64-encoded.\n
\nExample: stringData.shared_secret and stringData.cookie_secret are\nraw strings, while data.signing_key is base64-encoded.\n
ca.crt containing CA certificate\nthat, if specified, would be used to populate sslrootcert parameter of the connection string.",
"format": "namespace/name",
"minLength": 1,
"type": "string"
},
"secret": {
"description": "Secret specifies a name of a Secret that must contain\nconnection key. See\nDSN Format and Parameters.\nDo not set sslrootcert, sslcert and sslkey via connection string,\nuse tlsSecret and caSecret CRD options instead.",
"format": "namespace/name",
"minLength": 1,
"type": "string"
},
"tlsSecret": {
"description": "TLSSecret should refer to a k8s secret of type kubernetes.io/tls\nand allows to specify an optional client certificate and key,\nby constructing sslcert and sslkey connection string\n\nparameter values.",
"format": "namespace/name",
"minLength": 1,
"type": "string"
}
},
"required": [
"secret"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
},
"timeouts": {
"description": "Timeout specifies the global timeouts for all routes.",
"properties": {
"idle": {
"description": "Idle specifies the time at which a downstream or upstream connection will be terminated if there are no active streams.",
"format": "duration",
"type": "string"
},
"read": {
"description": "Read specifies the amount of time for the entire request stream to be received from the client.",
"format": "duration",
"type": "string"
},
"write": {
"description": "Write specifies max stream duration is the maximum time that a stream\u2019s lifetime will span.\nAn HTTP request/response exchange fully consumes a single stream.\nTherefore, this value must be greater than read_timeout as it covers both request and response time.",
"format": "duration",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"useProxyProtocol": {
"description": "UseProxyProtocol enables Proxy Protocol support.",
"type": "boolean"
}
},
"required": [
"secrets"
],
"type": "object",
"x-kubernetes-validations": [
{
"fieldPath": ".authenticate",
"message": "authenticate is required if identityProvider is set",
"reason": "FieldValueRequired",
"rule": "!has(self.identityProvider) || has(self.authenticate)"
},
{
"fieldPath": ".identityProvider",
"message": "identityProvider is required if authenticate is set",
"reason": "FieldValueRequired",
"rule": "!has(self.authenticate) || has(self.identityProvider)"
}
],
"additionalProperties": false
},
"status": {
"description": "PomeriumStatus represents configuration and Ingress status.",
"properties": {
"certificateAutoProvisionStatus": {
"description": "Status of certificate auto provisioning.",
"properties": {
"dataBrokerLastUpdated": {
"format": "date-time",
"type": "string"
}
},
"type": "object",
"additionalProperties": false
},
"ingress": {
"additionalProperties": {
"description": "ResourceStatus represents the outcome of the latest attempt to reconcile\nrelevant Kubernetes resource with Pomerium.",
"properties": {
"error": {
"description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
"type": "string"
},
"observedAt": {
"description": "ObservedAt is when last reconciliation attempt was made.",
"format": "date-time",
"type": "string"
},
"observedGeneration": {
"description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.",
"format": "int64",
"type": "integer"
},
"reconciled": {
"description": "Reconciled is whether this object generation was successfully synced with pomerium.",
"type": "boolean"
},
"warnings": {
"description": "Warnings while parsing the resource.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"reconciled"
],
"type": "object",
"additionalProperties": false
},
"description": "Routes provide per-Ingress status.",
"type": "object"
},
"settingsStatus": {
"description": "SettingsStatus represent most recent main configuration reconciliation status.",
"properties": {
"error": {
"description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.",
"type": "string"
},
"observedAt": {
"description": "ObservedAt is when last reconciliation attempt was made.",
"format": "date-time",
"type": "string"
},
"observedGeneration": {
"description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.",
"format": "int64",
"type": "integer"
},
"reconciled": {
"description": "Reconciled is whether this object generation was successfully synced with pomerium.",
"type": "boolean"
},
"warnings": {
"description": "Warnings while parsing the resource.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"reconciled"
],
"type": "object",
"additionalProperties": false
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}