Files
kubeconform/crdSchemas/master-standalone/cloudflareaccesspolicy-stable-v1alpha1.json
T
2026-08-18 19:18:31 +01:00

1015 lines
42 KiB
JSON

{
"description": "CloudflareAccessPolicy is the Schema for the cloudflareaccesspolicies API.\n\nCloudflareAccessPolicy manages a reusable account-level Cloudflare Access Policy.\nCloudflareAccessApplication attaches reusable policies to Gateway API targets.\n\nAccess rules are organized into implementation tiers based on IdP requirements:\n - P0: IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken (no IdP)\n - P1: Email, EmailList, EmailDomain, OIDCClaim (basic IdP required)\n - P2: GSuiteGroup (Google Workspace required)\n - P3: not in current product scope (Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.)\n\nStatus conditions:\n - Ready: policy is synced and service tokens are ready when configured\n - CredentialsValid: Cloudflare credentials have been validated\n - ServiceTokensReady: all service tokens have been created\n - PolicySynced: reusable Access policy exists in Cloudflare",
"properties": {
"apiVersion": {
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
"type": "string"
},
"kind": {
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
"type": "string"
},
"metadata": {
"type": "object"
},
"spec": {
"description": "CloudflareAccessPolicySpec defines a reusable Cloudflare Access policy.\n\nCloudflareAccessPolicySpec manages account-level reusable Access policies. Applications\nattach these policies through CloudflareAccessApplication policyRefs.",
"properties": {
"approvalGroups": {
"description": "ApprovalGroups defines who can approve access.",
"items": {
"description": "ApprovalGroup defines who can approve access requests for approval-required policies.\n\nApprovalGroup specifies approvers by email address or email list UUID. When a\npolicy requires approval, users matching this group can approve or deny access requests.",
"properties": {
"approvalsNeeded": {
"default": 1,
"description": "ApprovalsNeeded is number of approvals required.",
"minimum": 1,
"type": "integer"
},
"emailListUuid": {
"description": "EmailListUUID is a Cloudflare Access email list UUID whose members can approve.",
"maxLength": 36,
"type": "string"
},
"emails": {
"description": "Emails of approvers.",
"items": {
"type": "string"
},
"maxItems": 50,
"type": "array"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "at least one approver (emails or emailListUuid) must be specified",
"rule": "(has(self.emails) && size(self.emails) > 0) || has(self.emailListUuid)"
}
],
"additionalProperties": false
},
"maxItems": 10,
"type": "array"
},
"approvalRequired": {
"default": false,
"description": "ApprovalRequired requires approval from specific users.",
"type": "boolean"
},
"cloudflareRef": {
"description": "CloudflareRef references Cloudflare credentials.",
"properties": {
"accountId": {
"description": "AccountID is the Cloudflare account ID.",
"maxLength": 32,
"type": "string"
},
"accountName": {
"description": "AccountName is the Cloudflare account name (looked up via API).",
"maxLength": 255,
"type": "string"
},
"name": {
"description": "Name of the secret containing credentials.",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"namespace": {
"description": "Namespace of the secret (defaults to policy namespace).",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"decision": {
"default": "allow",
"description": "Decision is the policy action.",
"enum": [
"allow",
"deny",
"bypass",
"non_identity"
],
"type": "string"
},
"exclude": {
"description": "Exclude rules (if ANY match, policy does not apply).",
"items": {
"description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
"properties": {
"anyValidServiceToken": {
"description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
"type": "boolean"
},
"country": {
"description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
"properties": {
"codes": {
"description": "Codes are ISO 3166-1 alpha-2 country codes.",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"codes"
],
"type": "object",
"additionalProperties": false
},
"email": {
"description": "Email matches specific email addresses.\nSDK: EmailRule",
"properties": {
"addresses": {
"description": "Addresses to match.",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"addresses"
],
"type": "object",
"additionalProperties": false
},
"emailDomain": {
"description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
"properties": {
"domain": {
"description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
"maxLength": 253,
"minLength": 1,
"type": "string"
}
},
"required": [
"domain"
],
"type": "object",
"additionalProperties": false
},
"emailList": {
"description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
"properties": {
"id": {
"description": "ID of the Access list in Cloudflare.",
"maxLength": 36,
"type": "string"
},
"name": {
"description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
"maxLength": 255,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "id must be specified",
"rule": "has(self.id)"
}
],
"additionalProperties": false
},
"everyone": {
"description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
"type": "boolean"
},
"group": {
"description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
"properties": {
"id": {
"description": "ID is the Cloudflare Access Group ID.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"id"
],
"type": "object",
"additionalProperties": false
},
"gsuiteGroup": {
"description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
"properties": {
"email": {
"description": "Email is the Google Workspace group email.",
"maxLength": 320,
"minLength": 1,
"type": "string"
},
"identityProviderId": {
"description": "IdentityProviderID in Cloudflare.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"email",
"identityProviderId"
],
"type": "object",
"additionalProperties": false
},
"ip": {
"description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
"properties": {
"ranges": {
"description": "Ranges are CIDR blocks (IPv4 or IPv6).",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"ranges"
],
"type": "object",
"additionalProperties": false
},
"ipList": {
"description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
"properties": {
"id": {
"description": "ID of the IP list in Cloudflare.",
"maxLength": 36,
"type": "string"
},
"name": {
"description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
"maxLength": 255,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "id must be specified",
"rule": "has(self.id)"
}
],
"additionalProperties": false
},
"oidcClaim": {
"description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
"properties": {
"claimName": {
"description": "ClaimName is the OIDC claim to match.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"claimValue": {
"description": "ClaimValue is the expected value.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"identityProviderId": {
"description": "IdentityProviderID in Cloudflare.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"claimName",
"claimValue",
"identityProviderId"
],
"type": "object",
"additionalProperties": false
},
"serviceToken": {
"description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
"properties": {
"name": {
"description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
"maxLength": 255,
"type": "string"
},
"tokenId": {
"description": "TokenID is the Cloudflare service token ID.",
"maxLength": 36,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "either tokenId or name must be specified",
"rule": "has(self.tokenId) || has(self.name)"
}
],
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one rule type must be specified",
"rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
}
],
"additionalProperties": false
},
"maxItems": 25,
"type": "array"
},
"include": {
"description": "Include rules (ANY must match for policy to apply).",
"items": {
"description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
"properties": {
"anyValidServiceToken": {
"description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
"type": "boolean"
},
"country": {
"description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
"properties": {
"codes": {
"description": "Codes are ISO 3166-1 alpha-2 country codes.",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"codes"
],
"type": "object",
"additionalProperties": false
},
"email": {
"description": "Email matches specific email addresses.\nSDK: EmailRule",
"properties": {
"addresses": {
"description": "Addresses to match.",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"addresses"
],
"type": "object",
"additionalProperties": false
},
"emailDomain": {
"description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
"properties": {
"domain": {
"description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
"maxLength": 253,
"minLength": 1,
"type": "string"
}
},
"required": [
"domain"
],
"type": "object",
"additionalProperties": false
},
"emailList": {
"description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
"properties": {
"id": {
"description": "ID of the Access list in Cloudflare.",
"maxLength": 36,
"type": "string"
},
"name": {
"description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
"maxLength": 255,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "id must be specified",
"rule": "has(self.id)"
}
],
"additionalProperties": false
},
"everyone": {
"description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
"type": "boolean"
},
"group": {
"description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
"properties": {
"id": {
"description": "ID is the Cloudflare Access Group ID.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"id"
],
"type": "object",
"additionalProperties": false
},
"gsuiteGroup": {
"description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
"properties": {
"email": {
"description": "Email is the Google Workspace group email.",
"maxLength": 320,
"minLength": 1,
"type": "string"
},
"identityProviderId": {
"description": "IdentityProviderID in Cloudflare.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"email",
"identityProviderId"
],
"type": "object",
"additionalProperties": false
},
"ip": {
"description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
"properties": {
"ranges": {
"description": "Ranges are CIDR blocks (IPv4 or IPv6).",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"ranges"
],
"type": "object",
"additionalProperties": false
},
"ipList": {
"description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
"properties": {
"id": {
"description": "ID of the IP list in Cloudflare.",
"maxLength": 36,
"type": "string"
},
"name": {
"description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
"maxLength": 255,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "id must be specified",
"rule": "has(self.id)"
}
],
"additionalProperties": false
},
"oidcClaim": {
"description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
"properties": {
"claimName": {
"description": "ClaimName is the OIDC claim to match.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"claimValue": {
"description": "ClaimValue is the expected value.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"identityProviderId": {
"description": "IdentityProviderID in Cloudflare.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"claimName",
"claimValue",
"identityProviderId"
],
"type": "object",
"additionalProperties": false
},
"serviceToken": {
"description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
"properties": {
"name": {
"description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
"maxLength": 255,
"type": "string"
},
"tokenId": {
"description": "TokenID is the Cloudflare service token ID.",
"maxLength": 36,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "either tokenId or name must be specified",
"rule": "has(self.tokenId) || has(self.name)"
}
],
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one rule type must be specified",
"rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
}
],
"additionalProperties": false
},
"maxItems": 25,
"minItems": 1,
"type": "array"
},
"name": {
"description": "Name is the Cloudflare Access policy display name.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"purposeJustificationPrompt": {
"description": "PurposeJustificationPrompt is the prompt shown to user.",
"maxLength": 1024,
"type": "string"
},
"purposeJustificationRequired": {
"default": false,
"description": "PurposeJustificationRequired requires user to provide justification.",
"type": "boolean"
},
"require": {
"description": "Require rules (ALL must match for policy to apply).",
"items": {
"description": "AccessRule defines identity matching criteria for Access policies.\n\nAccessRule specifies conditions that identify users or services. Rules are organized\ninto implementation tiers based on IdP requirements:\n - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken\n - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim\n - P2 (Google Workspace): GSuiteGroup\n - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.\n\nSDK types map directly to cloudflare-go v6 SDK: IPRule, IPListRule, CountryRule,\nEveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule,\nEmailListRule, AccessOIDCClaimRule, GSuiteGroupRule.",
"properties": {
"anyValidServiceToken": {
"description": "AnyValidServiceToken matches any valid service token.\nSDK: AnyValidServiceTokenRule",
"type": "boolean"
},
"country": {
"description": "Country matches source country codes (ISO 3166-1 alpha-2).\nSDK: CountryRule",
"properties": {
"codes": {
"description": "Codes are ISO 3166-1 alpha-2 country codes.",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"codes"
],
"type": "object",
"additionalProperties": false
},
"email": {
"description": "Email matches specific email addresses.\nSDK: EmailRule",
"properties": {
"addresses": {
"description": "Addresses to match.",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"addresses"
],
"type": "object",
"additionalProperties": false
},
"emailDomain": {
"description": "EmailDomain matches email domain suffix.\nSDK: DomainRule",
"properties": {
"domain": {
"description": "Domain suffix (e.g., \"example.com\").\nMax 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.",
"maxLength": 253,
"minLength": 1,
"type": "string"
}
},
"required": [
"domain"
],
"type": "object",
"additionalProperties": false
},
"emailList": {
"description": "EmailList references a Cloudflare Access email list.\nSDK: EmailListRule",
"properties": {
"id": {
"description": "ID of the Access list in Cloudflare.",
"maxLength": 36,
"type": "string"
},
"name": {
"description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
"maxLength": 255,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "id must be specified",
"rule": "has(self.id)"
}
],
"additionalProperties": false
},
"everyone": {
"description": "Everyone matches all users (use with caution).\nSDK: EveryoneRule",
"type": "boolean"
},
"group": {
"description": "Group matches a Cloudflare Access Group by ID.\nSDK: GroupRule",
"properties": {
"id": {
"description": "ID is the Cloudflare Access Group ID.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"id"
],
"type": "object",
"additionalProperties": false
},
"gsuiteGroup": {
"description": "GSuiteGroup matches Google Workspace groups.\nSDK: GSuiteGroupRule",
"properties": {
"email": {
"description": "Email is the Google Workspace group email.",
"maxLength": 320,
"minLength": 1,
"type": "string"
},
"identityProviderId": {
"description": "IdentityProviderID in Cloudflare.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"email",
"identityProviderId"
],
"type": "object",
"additionalProperties": false
},
"ip": {
"description": "IP matches source IP CIDR ranges.\nSDK: IPRule",
"properties": {
"ranges": {
"description": "Ranges are CIDR blocks (IPv4 or IPv6).",
"items": {
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"ranges"
],
"type": "object",
"additionalProperties": false
},
"ipList": {
"description": "IPList references a Cloudflare IP List.\nSDK: IPListRule",
"properties": {
"id": {
"description": "ID of the IP list in Cloudflare.",
"maxLength": 36,
"type": "string"
},
"name": {
"description": "Name is not supported for lookup in v1alpha1. Specify id instead.\nDeprecated: use id.",
"maxLength": 255,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "id must be specified",
"rule": "has(self.id)"
}
],
"additionalProperties": false
},
"oidcClaim": {
"description": "OIDCClaim matches OIDC token claims.\nSDK: AccessOIDCClaimRule",
"properties": {
"claimName": {
"description": "ClaimName is the OIDC claim to match.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"claimValue": {
"description": "ClaimValue is the expected value.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"identityProviderId": {
"description": "IdentityProviderID in Cloudflare.",
"maxLength": 36,
"minLength": 1,
"type": "string"
}
},
"required": [
"claimName",
"claimValue",
"identityProviderId"
],
"type": "object",
"additionalProperties": false
},
"serviceToken": {
"description": "ServiceToken matches a specific service token by ID.\nSDK: ServiceTokenRule",
"properties": {
"name": {
"description": "Name references an entry in spec.serviceTokens. The controller replaces it\nwith the created Cloudflare service token ID during policy sync.",
"maxLength": 255,
"type": "string"
},
"tokenId": {
"description": "TokenID is the Cloudflare service token ID.",
"maxLength": 36,
"type": "string"
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "either tokenId or name must be specified",
"rule": "has(self.tokenId) || has(self.name)"
}
],
"additionalProperties": false
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one rule type must be specified",
"rule": "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"
}
],
"additionalProperties": false
},
"maxItems": 25,
"type": "array"
},
"serviceTokens": {
"description": "ServiceTokens for machine-to-machine authentication.",
"items": {
"description": "ServiceTokenConfig defines configuration for Cloudflare Access service tokens.\n\nServiceTokenConfig enables machine-to-machine authentication. The controller creates\nthe service token in Cloudflare and stores the credentials (client ID and secret) in\nthe referenced Kubernetes Secret. The secret is only visible at creation time.",
"properties": {
"duration": {
"default": "8760h",
"description": "Duration is the token validity period using Go duration format.\nOnly hours (h) supported by Cloudflare API. Use \"8760h\" for 1 year.",
"pattern": "^[0-9]+h$",
"type": "string"
},
"name": {
"description": "Name is the token display name.",
"maxLength": 255,
"minLength": 1,
"type": "string"
},
"secretRef": {
"description": "SecretRef stores the generated token credentials.",
"properties": {
"name": {
"description": "Name of the Secret.",
"maxLength": 253,
"minLength": 1,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
}
},
"required": [
"name",
"secretRef"
],
"type": "object",
"additionalProperties": false
},
"maxItems": 10,
"type": "array"
},
"sessionDuration": {
"description": "SessionDuration overrides application session duration for this policy.",
"maxLength": 32,
"pattern": "^([0-9]+(ns|us|ms|s|m|h))+$",
"type": "string"
}
},
"required": [
"cloudflareRef",
"decision",
"include",
"name"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "include rules are required",
"rule": "size(self.include) > 0"
}
],
"additionalProperties": false
},
"status": {
"description": "CloudflareAccessPolicyStatus defines the observed state of a CloudflareAccessPolicy resource.",
"properties": {
"accountId": {
"description": "AccountID is the Cloudflare account ID used for this policy.",
"type": "string"
},
"appCount": {
"description": "AppCount is the number of Access Applications currently using this policy.",
"format": "int64",
"type": "integer"
},
"conditions": {
"description": "Conditions describe current state.",
"items": {
"description": "Condition contains details for one aspect of the current state of this API Resource.",
"properties": {
"lastTransitionTime": {
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
"format": "date-time",
"type": "string"
},
"message": {
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
"maxLength": 32768,
"type": "string"
},
"observedGeneration": {
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
"format": "int64",
"minimum": 0,
"type": "integer"
},
"reason": {
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
"maxLength": 1024,
"minLength": 1,
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
"type": "string"
},
"status": {
"description": "status of the condition, one of True, False, Unknown.",
"enum": [
"True",
"False",
"Unknown"
],
"type": "string"
},
"type": {
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
"maxLength": 316,
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
"type": "string"
}
},
"required": [
"lastTransitionTime",
"message",
"reason",
"status",
"type"
],
"type": "object",
"additionalProperties": false
},
"type": "array",
"x-kubernetes-list-map-keys": [
"type"
],
"x-kubernetes-list-type": "map"
},
"credentialSecretRef": {
"description": "CredentialSecretRef is the resolved credentials Secret used for cleanup.\nThe namespace is always stored explicitly.",
"properties": {
"name": {
"description": "Name of the secret.",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"namespace": {
"description": "Namespace of the secret. Defaults to the resource's namespace if empty.",
"maxLength": 63,
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"observedGeneration": {
"description": "ObservedGeneration is the last generation processed.",
"format": "int64",
"type": "integer"
},
"policyId": {
"description": "PolicyID is the Cloudflare Access reusable policy ID.",
"type": "string"
},
"reusable": {
"description": "Reusable reports whether Cloudflare returned this policy as reusable.",
"type": "boolean"
},
"serviceTokenIds": {
"additionalProperties": {
"type": "string"
},
"description": "ServiceTokenIDs maps token names to Cloudflare IDs.",
"type": "object"
}
},
"type": "object",
"additionalProperties": false
}
},
"type": "object"
}