{ "description": "Pomerium define runtime-configurable Pomerium settings\nthat do not fall into the category of deployment parameters", "properties": { "apiVersion": { "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources", "type": "string" }, "kind": { "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds", "type": "string" }, "metadata": { "type": "object" }, "spec": { "description": "PomeriumSpec defines Pomerium-specific configuration parameters.", "properties": { "accessLogFields": { "description": "AccessLogFields sets the access fields to log.", "items": { "type": "string" }, "type": "array" }, "allowUpgrades": { "description": "AllowUpgrades sets the allowed upgrade types.", "items": { "type": "string" }, "type": "array" }, "authenticate": { "description": "Authenticate sets authenticate service parameters.\nIf not specified, a Pomerium-hosted authenticate service would be used.", "properties": { "url": { "description": "AuthenticateURL is a dedicated domain URL\nthe non-authenticated persons would be referred to.\n\n

", "format": "uri", "pattern": "^https://", "type": "string" } }, "required": [ "url" ], "type": "object", "additionalProperties": false }, "authorizeLogFields": { "description": "AuthorizeLogFields sets the authorize fields to log.", "items": { "type": "string" }, "type": "array" }, "bearerTokenFormat": { "description": "BearerTokenFormat sets the Bearer Token Format.", "enum": [ "default", "idp_access_token", "idp_identity_token" ], "type": "string" }, "caSecrets": { "description": "CASecret should refer to k8s secrets with key ca.crt containing a CA certificate.", "items": { "type": "string" }, "type": "array" }, "certificateAutoProvision": { "description": "CertificateAutoProvision sets the certificate auto provision settings.\nThis is a fallback for routes that are not defined via Ingress or\nGateway resources. When configured, cert-manager certificate resources\nwill be created for any routes which have no matching TLS certificate.", "properties": { "clusterIssuer": { "description": "The cert-manager ClusterIssuer that will be used for new certificates.\nCertificates will be created in the same namespace as the controller\npod.", "minLength": 1, "type": "string" }, "issuer": { "description": "The cert-manager Issuer that will be used for new certificates.\nCertificates will be created in the same namespace as the Issuer.", "format": "namespace/name", "minLength": 1, "type": "string" } }, "type": "object", "additionalProperties": false }, "certificates": { "description": "Certificates is a list of secrets of type TLS to use", "format": "namespace/name", "items": { "type": "string" }, "type": "array" }, "circuitBreakerThresholds": { "description": "CircuitBreakerThresholds sets the circuit breaker thresholds settings.", "properties": { "maxConnectionPools": { "description": "MaxConnectionPools sets the maximum number of connection pools per\ncluster that Envoy will concurrently support at once. If not specified,\nthe default is unlimited. Set this for clusters which create a large\nnumber of connection pools.", "format": "int32", "type": "integer" }, "maxConnections": { "description": "MaxConnections sets the maximum number of connections that Envoy will\nmake to the upstream cluster. If not specified, the default is 1024.", "format": "int32", "type": "integer" }, "maxPendingRequests": { "description": "MaxPendingRequests sets the maximum number of pending requests that\nEnvoy will allow to the upstream cluster. If not specified, the\ndefault is 1024. This limit is applied as a connection limit for\nnon-HTTP traffic.", "format": "int32", "type": "integer" }, "maxRequests": { "description": "MaxRequests sets the maximum number of parallel requests that Envoy\nwill make to the upstream cluster. If not specified, the default is\n1024. This limit does not apply to non-HTTP traffic.", "format": "int32", "type": "integer" }, "maxRetries": { "description": "MaxRetries sets the maximum number of parallel retries that Envoy\nwill allow to the upstream cluster. If not specified, the default is 3.", "format": "int32", "type": "integer" } }, "type": "object", "additionalProperties": false }, "codecType": { "description": "CodecType sets the Codec Type.", "enum": [ "auto", "http1", "http2", "http3" ], "type": "string" }, "cookie": { "description": "Cookie defines Pomerium session cookie options.", "properties": { "domain": { "description": "Domain defaults to the same host that set the cookie.\nIf you specify the domain explicitly, then subdomains would also be included.", "type": "string" }, "expire": { "description": "Expire sets cookie and Pomerium session expiration time.\nOnce session expires, users would have to re-login.\nIf you change this parameter, existing sessions are not affected.\n

See Session Management\n(Enterprise) for a more fine-grained session controls.

\n

Defaults to 14 hours.

", "format": "duration", "type": "string" }, "httpOnly": { "description": "HTTPOnly if set to false, the cookie would be accessible from within the JavaScript.\nDefaults to true.", "type": "boolean" }, "name": { "description": "Name sets the Pomerium session cookie name.\nDefaults to _pomerium", "type": "string" }, "sameSite": { "description": "SameSite sets the SameSite option for cookies.\nDefaults to .", "enum": [ "strict", "lax", "none" ], "type": "string" } }, "type": "object", "additionalProperties": false }, "dataBroker": { "description": "DataBroker sets the databroker settings.", "properties": { "clusterLeaderId": { "description": "ClusterLeaderID defines the cluster leader in a clustered databroker.", "type": "string" } }, "type": "object", "additionalProperties": false }, "dns": { "description": "DNS sets the dns settings.", "properties": { "failureRefreshRate": { "description": "FailureRefreshRate is the rate at which DNS lookups are refreshed when requests are failing.", "format": "duration", "type": "string" }, "lookupFamily": { "description": "LookupFamily is the DNS IP address resolution policy.", "enum": [ "auto", "v4_only", "v6_only", "v4_preferred", "all" ], "type": "string" }, "queryTimeout": { "description": "QueryTimeout is the amount of time each name server is given to respond to a query on the first try of any given server.", "format": "duration", "type": "string" }, "queryTries": { "description": "QueryTries is the maximum number of query attempts the resolver will make before giving up. Each attempt may use a different name server.", "format": "int32", "type": "integer" }, "refreshRate": { "description": "RefreshRate is the rate at which DNS lookups are refreshed.", "format": "duration", "type": "string" }, "udpMaxQueries": { "description": "UDPMaxQueries caps the number of UDP based DNS queries on a single port.", "format": "int32", "type": "integer" }, "useTcp": { "description": "UseTCP uses TCP for all DNS queries instead of the default protocol UDP.", "type": "boolean" } }, "type": "object", "additionalProperties": false }, "downstreamMtls": { "description": "DownstreamMTLS sets the Downstream MTLS Settings.", "properties": { "ca": { "description": "CA is a bundle of PEM-encoded X.509 certificates that will be treated as trust anchors when verifying client certificates.", "format": "byte", "type": "string" }, "crl": { "description": "CRL is a bundle of PEM-encoded certificate revocation lists to be consulted during certificate validation.", "format": "byte", "type": "string" }, "enforcement": { "description": "Enforcement controls Pomerium's behavior when a client does not present a trusted client certificate.", "enum": [ "policy_with_default_deny", "policy", "reject_connection" ], "type": "string" }, "matchSubjectAltNames": { "description": "Match Subject Alt Names can be used to add an additional constraint when validating client certificates.", "properties": { "dns": { "type": "string" }, "email": { "type": "string" }, "ipAddress": { "type": "string" }, "uri": { "type": "string" }, "userPrincipalName": { "type": "string" } }, "type": "object", "additionalProperties": false }, "maxVerifyDepth": { "description": "MaxVerifyDepth sets a limit on the depth of a certificate chain presented by the client.", "format": "int32", "type": "integer" } }, "type": "object", "additionalProperties": false }, "envoyDynamicExtensions": { "description": "EnvoyDynamicExtensions file paths to the extensions to be loaded by Envoy at runtime.", "items": { "type": "string" }, "type": "array" }, "headersWithUnderscoresAction": { "description": "HeadersWithUnderscoresAction controls the behavior for a request with a\nheader name containing an underscore character. The default behavior is\nreject_request.", "enum": [ "allow", "reject_request", "drop_header" ], "type": "string" }, "identityProvider": { "description": "IdentityProvider configure single-sign-on authentication and user identity details\nby integrating with your Identity Provider", "properties": { "provider": { "description": "Provider is the short-hand name of a built-in OpenID Connect (oidc) identity provider to be used for authentication.\nTo use a generic provider, set to oidc.", "enum": [ "apple", "auth0", "azure", "cognito", "github", "gitlab", "google", "hosted", "oidc", "okta", "onelogin", "ping" ], "type": "string" }, "refreshDirectory": { "description": "RefreshDirectory is no longer supported,\nplease see Upgrade Guide.", "properties": { "interval": { "description": "interval is the time that pomerium will sync your IDP directory.", "format": "duration", "type": "string" }, "timeout": { "description": "timeout is the maximum time allowed each run.", "format": "duration", "type": "string" } }, "required": [ "interval", "timeout" ], "type": "object", "additionalProperties": false }, "requestParams": { "additionalProperties": { "type": "string" }, "description": "RequestParams to be added as part of a sign-in request using OAuth2 code flow.", "format": "namespace/name", "type": "object" }, "requestParamsSecret": { "description": "RequestParamsSecret is a reference to a secret for additional parameters you'd prefer not to provide in plaintext.", "format": "namespace/name", "type": "string" }, "scopes": { "description": "Scopes Identity provider scopes correspond to access privilege scopes\nas defined in Section 3.3 of OAuth 2.0 RFC6749.", "items": { "type": "string" }, "type": "array" }, "secret": { "description": "Secret containing IdP provider specific parameters.\nand must contain at least client_id and client_secret values.", "format": "namespace/name", "minLength": 1, "type": "string" }, "serviceAccountFromSecret": { "description": "ServiceAccountFromSecret is no longer supported,\nsee Upgrade Guide.", "type": "string" }, "url": { "description": "URL is the base path to an identity provider's OpenID connect discovery document.\nSee Identity Providers guides for details.", "format": "uri", "pattern": "^https://", "type": "string" } }, "required": [ "provider" ], "type": "object", "x-kubernetes-validations": [ { "fieldPath": ".secret", "message": "secret is required unless provider is 'hosted'", "reason": "FieldValueRequired", "rule": "self.provider != 'hosted' ? has(self.secret) : true" } ], "additionalProperties": false }, "idpAccessTokenAllowedAudiences": { "description": "IDPAccessTokenAllowedAudiences specifies the\nidp access token allowed audiences\nlist.", "items": { "type": "string" }, "type": "array" }, "jwtClaimHeaders": { "additionalProperties": { "type": "string" }, "description": "JWTClaimHeaders convert claims from the assertion token\ninto HTTP headers and adds them into JWT assertion header.\nPlease make sure to read\n\nGetting User Identity guide.", "type": "object" }, "mcpAllowedAsMetadataDomains": { "description": "MCPAllowedASMetadataDomains specifies the allowed domains for upstream AS/PRM metadata URLs.\nSupports wildcard patterns like \"*.example.com\".\nThis restricts which domains Pomerium will contact during upstream OAuth discovery\n(resource_metadata from WWW-Authenticate, authorization_servers from PRM).\nSee MCP Settings.", "items": { "type": "string" }, "type": "array" }, "mcpAllowedClientIdDomains": { "description": "MCPAllowedClientIDDomains specifies the allowed domains for MCP client ID metadata URLs.\nThis is required when MCP is enabled.\nSee MCP Settings.", "items": { "type": "string" }, "type": "array" }, "mergeSlashes": { "description": "MergeSlashes controls whether adjacent slashes in the request URI path\nwill be merged into one. Defaults to true.", "type": "boolean" }, "normalizePath": { "description": "NormalizePath controls whether request URI paths will be normalized\naccording to RFC 3986. Defaults to true.", "type": "boolean" }, "otel": { "description": "OTEL sets the OpenTelemetry Tracing.", "properties": { "bspMaxExportBatchSize": { "description": "BSPMaxExportBatchSize sets the maximum number of spans to export in a single batch", "format": "int32", "type": "integer" }, "bspScheduleDelay": { "description": "BSPScheduleDelay sets interval between two consecutive exports", "format": "duration", "type": "string" }, "endpoint": { "description": "An OTLP/gRPC or OTLP/HTTP base endpoint URL with optional port.
Example: `http://localhost:4318`", "type": "string" }, "headers": { "additionalProperties": { "type": "string" }, "description": "Extra headers", "type": "object" }, "logLevel": { "description": "LogLevel sets the log level for the OpenTelemetry SDK.", "enum": [ "trace", "debug", "info", "warn", "error" ], "type": "string" }, "protocol": { "description": "Valid values are `\"grpc\"` or `\"http/protobuf\"`.", "enum": [ "grpc", "http/protobuf" ], "type": "string" }, "resourceAttributes": { "additionalProperties": { "type": "string" }, "description": "ResourceAttributes sets the additional attributes to be added to the trace.", "type": "object" }, "sampling": { "description": "Sampling sets sampling probability between [0, 1].", "format": "number", "type": "string" }, "timeout": { "description": "Export request timeout duration", "format": "duration", "type": "string" } }, "required": [ "endpoint", "protocol" ], "type": "object", "additionalProperties": false }, "passIdentityHeaders": { "description": "PassIdentityHeaders sets the pass identity headers option.", "type": "boolean" }, "pathWithEscapedSlashesAction": { "description": "PathWithEscapedSlashesAction controls the behavior for a request with an\nescaped slash or backslash character in the URI path. This operation will\noccur before path normalization and the merge slashes operation. The\ndefault behavior is reject_request.", "enum": [ "keep_unchanged", "reject_request", "unescape_and_redirect", "unescape_and_forward" ], "type": "string" }, "programmaticRedirectDomains": { "description": "ProgrammaticRedirectDomains specifies a list of domains that can be used for\nprogrammatic redirects.", "items": { "type": "string" }, "type": "array" }, "runtimeFlags": { "additionalProperties": { "type": "boolean" }, "description": "RuntimeFlags sets the runtime flags to enable/disable certain features.", "type": "object" }, "secrets": { "description": "Secrets references a Secret with Pomerium bootstrap parameters.\n\n

\n

\n

\n

\nIn a default Pomerium installation manifest, they would be generated via a\none-time job\nand stored in a pomerium/bootstrap Secret.\nYou may re-run the job to rotate the secrets, or update the Secret values manually.\n

\n

\nWhen defining the Secret in a manifest, put raw values in stringData so\nKubernetes base64-encodes them. Use data only when values are already\nbase64-encoded.\n

\n

\nExample: stringData.shared_secret and stringData.cookie_secret are\nraw strings, while data.signing_key is base64-encoded.\n

", "format": "namespace/name", "minLength": 1, "type": "string" }, "setResponseHeaders": { "additionalProperties": { "type": "string" }, "description": "SetResponseHeaders specifies a mapping of HTTP Header to be added globally to all managed routes and pomerium's authenticate service.\nSee Set Response Headers", "type": "object" }, "ssh": { "description": "SSH sets the ssh settings.", "properties": { "hostKeySecrets": { "items": { "type": "string" }, "type": "array" }, "userCaKeySecret": { "type": "string" } }, "type": "object", "additionalProperties": false }, "storage": { "description": "Storage defines persistent storage for sessions and other data.\nSee Storage for details.\nIf no storage is specified, Pomerium would use a transient in-memory storage (not recommended for production).", "properties": { "file": { "description": "File specifies file storage options.", "properties": { "path": { "description": "Path defines the local file system path to store data.", "minLength": 1, "type": "string" } }, "required": [ "path" ], "type": "object", "additionalProperties": false }, "postgres": { "description": "Postgres specifies PostgreSQL database connection parameters", "properties": { "caSecret": { "description": "CASecret should refer to a k8s secret with key ca.crt containing CA certificate\nthat, if specified, would be used to populate sslrootcert parameter of the connection string.", "format": "namespace/name", "minLength": 1, "type": "string" }, "secret": { "description": "Secret specifies a name of a Secret that must contain\nconnection key. See\nDSN Format and Parameters.\nDo not set sslrootcert, sslcert and sslkey via connection string,\nuse tlsSecret and caSecret CRD options instead.", "format": "namespace/name", "minLength": 1, "type": "string" }, "tlsSecret": { "description": "TLSSecret should refer to a k8s secret of type kubernetes.io/tls\nand allows to specify an optional client certificate and key,\nby constructing sslcert and sslkey connection string\n\nparameter values.", "format": "namespace/name", "minLength": 1, "type": "string" } }, "required": [ "secret" ], "type": "object", "additionalProperties": false } }, "type": "object", "additionalProperties": false }, "timeouts": { "description": "Timeout specifies the global timeouts for all routes.", "properties": { "idle": { "description": "Idle specifies the time at which a downstream or upstream connection will be terminated if there are no active streams.", "format": "duration", "type": "string" }, "read": { "description": "Read specifies the amount of time for the entire request stream to be received from the client.", "format": "duration", "type": "string" }, "write": { "description": "Write specifies max stream duration is the maximum time that a stream\u2019s lifetime will span.\nAn HTTP request/response exchange fully consumes a single stream.\nTherefore, this value must be greater than read_timeout as it covers both request and response time.", "format": "duration", "type": "string" } }, "type": "object", "additionalProperties": false }, "useProxyProtocol": { "description": "UseProxyProtocol enables Proxy Protocol support.", "type": "boolean" } }, "required": [ "secrets" ], "type": "object", "x-kubernetes-validations": [ { "fieldPath": ".authenticate", "message": "authenticate is required if identityProvider is set", "reason": "FieldValueRequired", "rule": "!has(self.identityProvider) || has(self.authenticate)" }, { "fieldPath": ".identityProvider", "message": "identityProvider is required if authenticate is set", "reason": "FieldValueRequired", "rule": "!has(self.authenticate) || has(self.identityProvider)" } ], "additionalProperties": false }, "status": { "description": "PomeriumStatus represents configuration and Ingress status.", "properties": { "certificateAutoProvisionStatus": { "description": "Status of certificate auto provisioning.", "properties": { "dataBrokerLastUpdated": { "format": "date-time", "type": "string" } }, "type": "object", "additionalProperties": false }, "ingress": { "additionalProperties": { "description": "ResourceStatus represents the outcome of the latest attempt to reconcile\nrelevant Kubernetes resource with Pomerium.", "properties": { "error": { "description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.", "type": "string" }, "observedAt": { "description": "ObservedAt is when last reconciliation attempt was made.", "format": "date-time", "type": "string" }, "observedGeneration": { "description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.", "format": "int64", "type": "integer" }, "reconciled": { "description": "Reconciled is whether this object generation was successfully synced with pomerium.", "type": "boolean" }, "warnings": { "description": "Warnings while parsing the resource.", "items": { "type": "string" }, "type": "array" } }, "required": [ "reconciled" ], "type": "object", "additionalProperties": false }, "description": "Routes provide per-Ingress status.", "type": "object" }, "settingsStatus": { "description": "SettingsStatus represent most recent main configuration reconciliation status.", "properties": { "error": { "description": "Error that prevented latest observedGeneration to be synchronized with Pomerium.", "type": "string" }, "observedAt": { "description": "ObservedAt is when last reconciliation attempt was made.", "format": "date-time", "type": "string" }, "observedGeneration": { "description": "ObservedGeneration represents the .metadata.generation that was last presented to Pomerium.", "format": "int64", "type": "integer" }, "reconciled": { "description": "Reconciled is whether this object generation was successfully synced with pomerium.", "type": "boolean" }, "warnings": { "description": "Warnings while parsing the resource.", "items": { "type": "string" }, "type": "array" } }, "required": [ "reconciled" ], "type": "object", "additionalProperties": false } }, "type": "object", "additionalProperties": false } }, "type": "object" }