cue.dev/x/k8s.io@v0.12.0

api/admissionregistration/v1/schema.cue raw

   1package v1
   2
   3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
   4
   5// ApplyConfiguration defines the desired configuration values of an object.
   6#ApplyConfiguration: {
   7	// expression will be evaluated by CEL to create an apply configuration. ref:
   8	// https://github.com/google/cel-spec
   9	//
  10	// Apply configurations are declared in CEL using object initialization. For
  11	// example, this CEL expression returns an apply configuration to set a single
  12	// field:
  13	//
  14	// Object{
  15	// spec: Object.spec{
  16	// serviceAccountName: "example"
  17	// }
  18	// }
  19	//
  20	// Apply configurations may not modify atomic structs, maps or arrays due to the
  21	// risk of accidental deletion of values not included in the apply
  22	// configuration.
  23	//
  24	// CEL expressions have access to the object types needed to create apply configurations:
  25	//
  26	// - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
  27	// type of object field (such as 'Object.spec') -
  28	// 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
  29	// (such as 'Object.spec.containers')
  30	//
  31	// CEL expressions have access to the contents of the API request, organized
  32	// into CEL variables as well as some other useful variables:
  33	//
  34	// - 'object' - The object from the incoming request. The value is null for
  35	// DELETE requests. - 'oldObject' - The existing object. The value is null for
  36	// CREATE requests. - 'request' - Attributes of the API
  37	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
  38	// Parameter resource referred to by the policy binding being evaluated. Only
  39	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
  40	// object that the incoming object belongs to. The value is null for
  41	// cluster-scoped resources. - 'variables' - Map of composited variables, from
  42	// its name to its lazily evaluated value.
  43	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
  44	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
  45	// checks for the principal (user or service account) of the request.
  46	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
  47	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
  48	// 'authorizer' and configured with the
  49	// request resource.
  50	//
  51	// The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
  52	// always accessible from the root of the object. No other metadata properties
  53	// are accessible.
  54	//
  55	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
  56	"expression"?: string
  57}
  58
  59// AuditAnnotation describes how to produce an audit annotation for an API request.
  60#AuditAnnotation: {
  61	// key specifies the audit annotation key. The audit annotation keys of a
  62	// ValidatingAdmissionPolicy must be unique. The key must be a qualified name
  63	// ([A-Za-z0-9][-A-Za-z0-9_.]*) no more than 63 bytes in length.
  64	//
  65	// The key is combined with the resource name of the ValidatingAdmissionPolicy
  66	// to construct an audit annotation key: "{ValidatingAdmissionPolicy
  67	// name}/{key}".
  68	//
  69	// If an admission webhook uses the same resource name as this
  70	// ValidatingAdmissionPolicy and the same audit annotation key, the annotation
  71	// key will be identical. In this case, the first annotation written with the
  72	// key will be included in the audit event and all subsequent annotations with
  73	// the same key will be discarded.
  74	//
  75	// Required.
  76	"key"!: string
  77
  78	// valueExpression represents the expression which is evaluated by CEL to
  79	// produce an audit annotation value. The expression must evaluate to either a
  80	// string or null value. If the expression evaluates to a string, the audit
  81	// annotation is included with the string value. If the expression evaluates to
  82	// null or empty string the audit annotation will be omitted. The
  83	// valueExpression may be no longer than 5kb in length. If the result of the
  84	// valueExpression is more than 10kb in length, it will be truncated to 10kb.
  85	//
  86	// If multiple ValidatingAdmissionPolicyBinding resources match an API request,
  87	// then the valueExpression will be evaluated for each binding. All unique
  88	// values produced by the valueExpressions will be joined together in a
  89	// comma-separated list.
  90	//
  91	// Required.
  92	"valueExpression"!: string
  93}
  94
  95// ExpressionWarning is a warning information that targets a specific expression.
  96#ExpressionWarning: {
  97	// fieldRef is the path to the field that refers to the expression. For example,
  98	// the reference to the expression of the first item of validations is
  99	// "spec.validations[0].expression"
 100	"fieldRef"!: string
 101
 102	// warning contains the content of type checking information in a human-readable
 103	// form. Each line of the warning contains the type that the expression is
 104	// checked against, followed by the type check error from the compiler.
 105	"warning"!: string
 106}
 107
 108// JSONPatch defines a JSON Patch.
 109#JSONPatch: {
 110	// expression will be evaluated by CEL to create a [JSON
 111	// patch](https://jsonpatch.com/). ref: https://github.com/google/cel-spec
 112	//
 113	// expression must return an array of JSONPatch values.
 114	//
 115	// For example, this CEL expression returns a JSON patch to conditionally modify a value:
 116	//
 117	// [
 118	// JSONPatch{op: "test", path: "/spec/example", value: "Red"},
 119	// JSONPatch{op: "replace", path: "/spec/example", value: "Green"}
 120	// ]
 121	//
 122	// To define an object for the patch value, use Object types. For example:
 123	//
 124	// [
 125	// JSONPatch{
 126	// op: "add",
 127	// path: "/spec/selector",
 128	// value: Object.spec.selector{matchLabels: {"environment": "test"}}
 129	// }
 130	// ]
 131	//
 132	// To use strings containing '/' and '~' as JSONPatch path keys, use
 133	// "jsonpatch.escapeKey". For example:
 134	//
 135	// [
 136	// JSONPatch{
 137	// op: "add",
 138	// path: "/metadata/labels/" + jsonpatch.escapeKey("example.com/environment"),
 139	// value: "test"
 140	// },
 141	// ]
 142	//
 143	// CEL expressions have access to the types needed to create JSON patches and objects:
 144	//
 145	// - 'JSONPatch' - CEL type of JSON Patch operations. JSONPatch has the fields
 146	// 'op', 'from', 'path' and 'value'.
 147	// See [JSON patch](https://jsonpatch.com/) for more details. The 'value' field
 148	// may be set to any of: string,
 149	// integer, array, map or object. If set, the 'path' and 'from' fields must be set to a
 150	// [JSON pointer](https://datatracker.ietf.org/doc/html/rfc6901/) string, where
 151	// the 'jsonpatch.escapeKey()' CEL
 152	// function may be used to escape path keys containing '/' and '~'.
 153	// - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
 154	// type of object field (such as 'Object.spec') -
 155	// 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
 156	// (such as 'Object.spec.containers')
 157	//
 158	// CEL expressions have access to the contents of the API request, organized
 159	// into CEL variables as well as some other useful variables:
 160	//
 161	// - 'object' - The object from the incoming request. The value is null for
 162	// DELETE requests. - 'oldObject' - The existing object. The value is null for
 163	// CREATE requests. - 'request' - Attributes of the API
 164	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
 165	// Parameter resource referred to by the policy binding being evaluated. Only
 166	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
 167	// object that the incoming object belongs to. The value is null for
 168	// cluster-scoped resources. - 'variables' - Map of composited variables, from
 169	// its name to its lazily evaluated value.
 170	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
 171	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
 172	// checks for the principal (user or service account) of the request.
 173	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
 174	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
 175	// 'authorizer' and configured with the
 176	// request resource.
 177	//
 178	// CEL expressions have access to [Kubernetes CEL function
 179	// libraries](https://kubernetes.io/docs/reference/using-api/cel/#cel-options-language-features-and-libraries)
 180	// as well as:
 181	//
 182	// - 'jsonpatch.escapeKey' - Performs JSONPatch key escaping. '~' and '/' are
 183	// escaped as '~0' and `~1' respectively).
 184	//
 185	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
 186	"expression"?: string
 187}
 188
 189// MatchCondition represents a condition which must by fulfilled for a request
 190// to be sent to a webhook.
 191#MatchCondition: {
 192	// expression represents the expression which will be evaluated by CEL. Must
 193	// evaluate to bool. CEL expressions have access to the contents of the
 194	// AdmissionRequest and Authorizer, organized into CEL variables:
 195	//
 196	// 'object' - The object from the incoming request. The value is null for DELETE
 197	// requests. 'oldObject' - The existing object. The value is null for CREATE
 198	// requests. 'request' - Attributes of the admission
 199	// request(/pkg/apis/admission/types.go#AdmissionRequest). 'authorizer' - A CEL
 200	// Authorizer. May be used to perform authorization checks for the principal
 201	// (user or service account) of the request.
 202	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
 203	// 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
 204	// 'authorizer' and configured with the
 205	// request resource.
 206	// Documentation on CEL: https://kubernetes.io/docs/reference/using-api/cel/
 207	//
 208	// Required.
 209	"expression"!: string
 210
 211	// name is an identifier for this match condition, used for strategic merging of
 212	// MatchConditions, as well as providing an identifier for logging purposes. A
 213	// good name should be descriptive of the associated expression. Name must be a
 214	// qualified name consisting of alphanumeric characters, '-', '_' or '.', and
 215	// must start and end with an alphanumeric character (e.g. 'MyName', or
 216	// 'my.name', or '123-abc', regex used for validation is
 217	// '([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]') with an optional DNS subdomain
 218	// prefix and '/' (e.g. 'example.com/MyName')
 219	//
 220	// Required.
 221	"name"!: string
 222}
 223
 224// MatchResources decides whether to run the admission control policy on an
 225// object based on whether it meets the match criteria. The exclude rules take
 226// precedence over include rules (if a resource matches both, it is excluded)
 227#MatchResources: {
 228	// excludeResourceRules describes what operations on what resources/subresources
 229	// the ValidatingAdmissionPolicy should not care about. The exclude rules take
 230	// precedence over include rules (if a resource matches both, it is excluded)
 231	"excludeResourceRules"?: [...#NamedRuleWithOperations]
 232
 233	// matchPolicy defines how the "MatchResources" list is used to match incoming
 234	// requests. Allowed values are "Exact" or "Equivalent".
 235	//
 236	// - Exact: match a request only if it exactly matches a specified rule. For
 237	// example, if deployments can be modified via apps/v1, apps/v1beta1, and
 238	// extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
 239	// apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
 240	// or extensions/v1beta1 would not be sent to the ValidatingAdmissionPolicy.
 241	//
 242	// - Equivalent: match a request if modifies a resource listed in rules, even
 243	// via another API group or version. For example, if deployments can be
 244	// modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
 245	// included `apiGroups:["apps"], apiVersions:["v1"], resources:
 246	// ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
 247	// converted to apps/v1 and sent to the ValidatingAdmissionPolicy.
 248	//
 249	// Defaults to "Equivalent"
 250	"matchPolicy"?: string
 251
 252	// namespaceSelector decides whether to run the admission control policy on an
 253	// object based on whether the namespace for that object matches the selector.
 254	// If the object itself is a namespace, the matching is performed on
 255	// object.metadata.labels. If the object is another cluster scoped resource, it
 256	// never skips the policy.
 257	//
 258	// For example, to run the webhook on any objects whose namespace is not
 259	// associated with "runlevel" of "0" or "1"; you will set the selector as
 260	// follows: "namespaceSelector": {
 261	// "matchExpressions": [
 262	// {
 263	// "key": "runlevel",
 264	// "operator": "NotIn",
 265	// "values": [
 266	// "0",
 267	// "1"
 268	// ]
 269	// }
 270	// ]
 271	// }
 272	//
 273	// If instead you want to only run the policy on any objects whose namespace is
 274	// associated with the "environment" of "prod" or "staging"; you will set the
 275	// selector as follows: "namespaceSelector": {
 276	// "matchExpressions": [
 277	// {
 278	// "key": "environment",
 279	// "operator": "In",
 280	// "values": [
 281	// "prod",
 282	// "staging"
 283	// ]
 284	// }
 285	// ]
 286	// }
 287	//
 288	// See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
 289	// for more examples of label selectors.
 290	//
 291	// Default to the empty LabelSelector, which matches everything.
 292	"namespaceSelector"?: v1.#LabelSelector
 293
 294	// objectSelector decides whether to run the validation based on if the object
 295	// has matching labels. objectSelector is evaluated against both the oldObject
 296	// and newObject that would be sent to the cel validation, and is considered to
 297	// match if either object matches the selector. A null object (oldObject in the
 298	// case of create, or newObject in the case of delete) or an object that cannot
 299	// have labels (like a DeploymentRollback or a PodProxyOptions object) is not
 300	// considered to match. Use the object selector only if the webhook is opt-in,
 301	// because end users may skip the admission webhook by setting the labels.
 302	// Default to the empty LabelSelector, which matches everything.
 303	"objectSelector"?: v1.#LabelSelector
 304
 305	// resourceRules describes what operations on what resources/subresources the
 306	// ValidatingAdmissionPolicy matches. The policy cares about an operation if it
 307	// matches _any_ Rule.
 308	"resourceRules"?: [...#NamedRuleWithOperations]
 309}
 310
 311// MutatingAdmissionPolicy describes the definition of an admission mutation
 312// policy that mutates the object coming into admission chain.
 313#MutatingAdmissionPolicy: {
 314	// APIVersion defines the versioned schema of this representation of an object.
 315	// Servers should convert recognized schemas to the latest internal value, and
 316	// may reject unrecognized values. More info:
 317	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 318	"apiVersion": "admissionregistration.k8s.io/v1"
 319
 320	// Kind is a string value representing the REST resource this object represents.
 321	// Servers may infer this from the endpoint the client submits requests to.
 322	// Cannot be updated. In CamelCase. More info:
 323	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 324	"kind": "MutatingAdmissionPolicy"
 325
 326	// metadata is the standard object metadata; More info:
 327	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
 328	"metadata"?: v1.#ObjectMeta
 329
 330	// spec defines the desired behavior of the MutatingAdmissionPolicy.
 331	"spec"?: #MutatingAdmissionPolicySpec
 332}
 333
 334// MutatingAdmissionPolicyBinding binds the MutatingAdmissionPolicy with
 335// parametrized resources. MutatingAdmissionPolicyBinding and the optional
 336// parameter resource together define how cluster administrators configure
 337// policies for clusters.
 338//
 339// For a given admission request, each binding will cause its policy to be
 340// evaluated N times, where N is 1 for policies/bindings that don't use params,
 341// otherwise N is the number of parameters selected by the binding. Each
 342// evaluation is constrained by a [runtime cost
 343// budget](https://kubernetes.io/docs/reference/using-api/cel/#runtime-cost-budget).
 344//
 345// Adding/removing policies, bindings, or params can not affect whether a given
 346// (policy, binding, param) combination is within its own CEL budget.
 347#MutatingAdmissionPolicyBinding: {
 348	// APIVersion defines the versioned schema of this representation of an object.
 349	// Servers should convert recognized schemas to the latest internal value, and
 350	// may reject unrecognized values. More info:
 351	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 352	"apiVersion": "admissionregistration.k8s.io/v1"
 353
 354	// Kind is a string value representing the REST resource this object represents.
 355	// Servers may infer this from the endpoint the client submits requests to.
 356	// Cannot be updated. In CamelCase. More info:
 357	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 358	"kind": "MutatingAdmissionPolicyBinding"
 359
 360	// metadata is the standard object metadata; More info:
 361	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
 362	"metadata"?: v1.#ObjectMeta
 363
 364	// spec defines the desired behavior of the MutatingAdmissionPolicyBinding.
 365	"spec"?: #MutatingAdmissionPolicyBindingSpec
 366}
 367
 368// MutatingAdmissionPolicyBindingList is a list of MutatingAdmissionPolicyBinding.
 369#MutatingAdmissionPolicyBindingList: {
 370	// APIVersion defines the versioned schema of this representation of an object.
 371	// Servers should convert recognized schemas to the latest internal value, and
 372	// may reject unrecognized values. More info:
 373	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 374	"apiVersion": "admissionregistration.k8s.io/v1"
 375
 376	// List of PolicyBinding.
 377	"items"!: [...#MutatingAdmissionPolicyBinding]
 378
 379	// Kind is a string value representing the REST resource this object represents.
 380	// Servers may infer this from the endpoint the client submits requests to.
 381	// Cannot be updated. In CamelCase. More info:
 382	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 383	"kind": "MutatingAdmissionPolicyBindingList"
 384
 385	// metadata is the standard list metadata. More info:
 386	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 387	"metadata"?: v1.#ListMeta
 388}
 389
 390// MutatingAdmissionPolicyBindingSpec defines the specification of the
 391// MutatingAdmissionPolicyBinding.
 392#MutatingAdmissionPolicyBindingSpec: {
 393	// matchResources limits what resources match this binding and may be mutated by
 394	// it. Note that if matchResources matches a resource, the resource must also
 395	// match a policy's matchConstraints and matchConditions before the resource
 396	// may be mutated. When matchResources is unset, it does not constrain resource
 397	// matching, and only the policy's matchConstraints and matchConditions must
 398	// match for the resource to be mutated. Additionally,
 399	// matchResources.resourceRules are optional and do not constraint matching
 400	// when unset. Note that this is differs from MutatingAdmissionPolicy
 401	// matchConstraints, where resourceRules are required. The CREATE, UPDATE and
 402	// CONNECT operations are allowed. The DELETE operation may not be matched. '*'
 403	// matches CREATE, UPDATE and CONNECT.
 404	"matchResources"?: #MatchResources
 405
 406	// paramRef specifies the parameter resource used to configure the admission
 407	// control policy. It should point to a resource of the type specified in
 408	// spec.ParamKind of the bound MutatingAdmissionPolicy. If the policy specifies
 409	// a ParamKind and the resource referred to by ParamRef does not exist, this
 410	// binding is considered mis-configured and the FailurePolicy of the
 411	// MutatingAdmissionPolicy applied. If the policy does not specify a ParamKind
 412	// then this field is ignored, and the rules are evaluated without a param.
 413	"paramRef"?: #ParamRef
 414
 415	// policyName references a MutatingAdmissionPolicy name which the
 416	// MutatingAdmissionPolicyBinding binds to. If the referenced resource does not
 417	// exist, this binding is considered invalid and will be ignored Required.
 418	"policyName"?: string
 419}
 420
 421// MutatingAdmissionPolicyList is a list of MutatingAdmissionPolicy.
 422#MutatingAdmissionPolicyList: {
 423	// APIVersion defines the versioned schema of this representation of an object.
 424	// Servers should convert recognized schemas to the latest internal value, and
 425	// may reject unrecognized values. More info:
 426	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 427	"apiVersion": "admissionregistration.k8s.io/v1"
 428
 429	// List of ValidatingAdmissionPolicy.
 430	"items"!: [...#MutatingAdmissionPolicy]
 431
 432	// Kind is a string value representing the REST resource this object represents.
 433	// Servers may infer this from the endpoint the client submits requests to.
 434	// Cannot be updated. In CamelCase. More info:
 435	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 436	"kind": "MutatingAdmissionPolicyList"
 437
 438	// metadata is the standard list metadata. More info:
 439	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 440	"metadata"?: v1.#ListMeta
 441}
 442
 443// MutatingAdmissionPolicySpec defines the desired behavior of the admission policy.
 444#MutatingAdmissionPolicySpec: {
 445	// failurePolicy defines how to handle failures for the admission policy.
 446	// Failures can occur from CEL expression parse errors, type check errors,
 447	// runtime errors and invalid or mis-configured policy definitions or bindings.
 448	//
 449	// A policy is invalid if paramKind refers to a non-existent Kind. A binding is
 450	// invalid if paramRef.name refers to a non-existent resource.
 451	//
 452	// failurePolicy does not define how validations that evaluate to false are handled.
 453	//
 454	// Allowed values are Ignore or Fail. Defaults to Fail.
 455	"failurePolicy"?: string
 456
 457	// matchConditions is a list of conditions that must be met for a request to be
 458	// validated. Match conditions filter requests that have already been matched
 459	// by the matchConstraints. An empty list of matchConditions matches all
 460	// requests. There are a maximum of 64 match conditions allowed.
 461	//
 462	// If a parameter object is provided, it can be accessed via the `params` handle
 463	// in the same manner as validation expressions.
 464	//
 465	// The exact matching logic is (in order):
 466	// 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
 467	// 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
 468	// 3. If any matchCondition evaluates to an error (but none are FALSE):
 469	// - If failurePolicy=Fail, reject the request
 470	// - If failurePolicy=Ignore, the policy is skipped
 471	"matchConditions"?: [...#MatchCondition]
 472
 473	// matchConstraints specifies what resources this policy is designed to
 474	// validate. The MutatingAdmissionPolicy cares about a request if it matches
 475	// _all_ Constraints. However, in order to prevent clusters from being put into
 476	// an unstable state that cannot be recovered from via the API
 477	// MutatingAdmissionPolicy cannot match MutatingAdmissionPolicy and
 478	// MutatingAdmissionPolicyBinding. The CREATE, UPDATE and CONNECT operations
 479	// are allowed. The DELETE operation may not be matched. '*' matches CREATE,
 480	// UPDATE and CONNECT. Required.
 481	"matchConstraints"?: #MatchResources
 482
 483	// mutations contain operations to perform on matching objects. mutations may
 484	// not be empty; a minimum of one mutation is required. mutations are evaluated
 485	// in order, and are reinvoked according to the reinvocationPolicy. The
 486	// mutations of a policy are invoked for each binding of this policy and
 487	// reinvocation of mutations occurs on a per binding basis.
 488	"mutations"?: [...#Mutation]
 489
 490	// paramKind specifies the kind of resources used to parameterize this policy.
 491	// If absent, there are no parameters for this policy and the param CEL
 492	// variable will not be provided to validation expressions. If paramKind refers
 493	// to a non-existent kind, this policy definition is mis-configured and the
 494	// FailurePolicy is applied. If paramKind is specified but paramRef is unset in
 495	// MutatingAdmissionPolicyBinding, the params variable will be null.
 496	"paramKind"?: #ParamKind
 497
 498	// reinvocationPolicy indicates whether mutations may be called multiple times
 499	// per MutatingAdmissionPolicyBinding as part of a single admission evaluation.
 500	// Allowed values are "Never" and "IfNeeded".
 501	//
 502	// Never: These mutations will not be called more than once per binding in a
 503	// single admission evaluation.
 504	//
 505	// IfNeeded: These mutations may be invoked more than once per binding for a
 506	// single admission request and there is no guarantee of order with respect to
 507	// other admission plugins, admission webhooks, bindings of this policy and
 508	// admission policies. Mutations are only reinvoked when mutations change the
 509	// object after this mutation is invoked. Required.
 510	"reinvocationPolicy"?: string
 511
 512	// variables contain definitions of variables that can be used in composition of
 513	// other expressions. Each variable is defined as a named CEL expression. The
 514	// variables defined here will be available under `variables` in other
 515	// expressions of the policy except matchConditions because matchConditions are
 516	// evaluated before the rest of the policy.
 517	//
 518	// The expression of a variable can refer to other variables defined earlier in
 519	// the list but not those after. Thus, variables must be sorted by the order of
 520	// first appearance and acyclic.
 521	"variables"?: [...#Variable]
 522}
 523
 524// MutatingWebhook describes an admission webhook and the resources and operations it applies to.
 525#MutatingWebhook: {
 526	// admissionReviewVersions is an ordered list of preferred `AdmissionReview`
 527	// versions the Webhook expects. API server will try to use first version in
 528	// the list which it supports. If none of the versions specified in this list
 529	// supported by API server, validation will fail for this object. If a
 530	// persisted webhook configuration specifies allowed versions and does not
 531	// include any versions known to the API Server, calls to the webhook will fail
 532	// and be subject to the failure policy.
 533	"admissionReviewVersions"!: [...string]
 534
 535	// clientConfig defines how to communicate with the hook. Required
 536	"clientConfig"!: #WebhookClientConfig
 537
 538	// failurePolicy defines how unrecognized errors from the admission endpoint are
 539	// handled - allowed values are Ignore or Fail. Defaults to Fail.
 540	"failurePolicy"?: string
 541
 542	// matchConditions is a list of conditions that must be met for a request to be
 543	// sent to this webhook. Match conditions filter requests that have already
 544	// been matched by the rules, namespaceSelector, and objectSelector. An empty
 545	// list of matchConditions matches all requests. There are a maximum of 64
 546	// match conditions allowed.
 547	//
 548	// The exact matching logic is (in order):
 549	// 1. If ANY matchCondition evaluates to FALSE, the webhook is skipped.
 550	// 2. If ALL matchConditions evaluate to TRUE, the webhook is called.
 551	// 3. If any matchCondition evaluates to an error (but none are FALSE):
 552	// - If failurePolicy=Fail, reject the request
 553	// - If failurePolicy=Ignore, the error is ignored and the webhook is skipped
 554	"matchConditions"?: [...#MatchCondition]
 555
 556	// matchPolicy defines how the "rules" list is used to match incoming requests.
 557	// Allowed values are "Exact" or "Equivalent".
 558	//
 559	// - Exact: match a request only if it exactly matches a specified rule. For
 560	// example, if deployments can be modified via apps/v1, apps/v1beta1, and
 561	// extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
 562	// apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
 563	// or extensions/v1beta1 would not be sent to the webhook.
 564	//
 565	// - Equivalent: match a request if modifies a resource listed in rules, even
 566	// via another API group or version. For example, if deployments can be
 567	// modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
 568	// included `apiGroups:["apps"], apiVersions:["v1"], resources:
 569	// ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
 570	// converted to apps/v1 and sent to the webhook.
 571	//
 572	// Defaults to "Equivalent"
 573	"matchPolicy"?: string
 574
 575	// name is the name of the admission webhook. Name should be fully qualified,
 576	// e.g., imagepolicy.kubernetes.io, where "imagepolicy" is the name of the
 577	// webhook, and kubernetes.io is the name of the organization. Required.
 578	"name"!: string
 579
 580	// namespaceSelector decides whether to run the webhook on an object based on
 581	// whether the namespace for that object matches the selector. If the object
 582	// itself is a namespace, the matching is performed on object.metadata.labels.
 583	// If the object is another cluster scoped resource, it never skips the
 584	// webhook.
 585	//
 586	// For example, to run the webhook on any objects whose namespace is not
 587	// associated with "runlevel" of "0" or "1"; you will set the selector as
 588	// follows: "namespaceSelector": {
 589	// "matchExpressions": [
 590	// {
 591	// "key": "runlevel",
 592	// "operator": "NotIn",
 593	// "values": [
 594	// "0",
 595	// "1"
 596	// ]
 597	// }
 598	// ]
 599	// }
 600	//
 601	// If instead you want to only run the webhook on any objects whose namespace is
 602	// associated with the "environment" of "prod" or "staging"; you will set the
 603	// selector as follows: "namespaceSelector": {
 604	// "matchExpressions": [
 605	// {
 606	// "key": "environment",
 607	// "operator": "In",
 608	// "values": [
 609	// "prod",
 610	// "staging"
 611	// ]
 612	// }
 613	// ]
 614	// }
 615	//
 616	// See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
 617	// for more examples of label selectors.
 618	//
 619	// Default to the empty LabelSelector, which matches everything.
 620	"namespaceSelector"?: v1.#LabelSelector
 621
 622	// objectSelector decides whether to run the webhook based on if the object has
 623	// matching labels. objectSelector is evaluated against both the oldObject and
 624	// newObject that would be sent to the webhook, and is considered to match if
 625	// either object matches the selector. A null object (oldObject in the case of
 626	// create, or newObject in the case of delete) or an object that cannot have
 627	// labels (like a DeploymentRollback or a PodProxyOptions object) is not
 628	// considered to match. Use the object selector only if the webhook is opt-in,
 629	// because end users may skip the admission webhook by setting the labels.
 630	// Default to the empty LabelSelector, which matches everything.
 631	"objectSelector"?: v1.#LabelSelector
 632
 633	// reinvocationPolicy indicates whether this webhook should be called multiple
 634	// times as part of a single admission evaluation. Allowed values are "Never"
 635	// and "IfNeeded".
 636	//
 637	// Never: the webhook will not be called more than once in a single admission evaluation.
 638	//
 639	// IfNeeded: the webhook will be called at least one additional time as part of
 640	// the admission evaluation if the object being admitted is modified by other
 641	// admission plugins after the initial webhook call. Webhooks that specify this
 642	// option *must* be idempotent, able to process objects they previously
 643	// admitted. Note: * the number of additional invocations is not guaranteed to
 644	// be exactly one. * if additional invocations result in further modifications
 645	// to the object, webhooks are not guaranteed to be invoked again. * webhooks
 646	// that use this option may be reordered to minimize the number of additional
 647	// invocations. * to validate an object after all mutations are guaranteed
 648	// complete, use a validating admission webhook instead.
 649	//
 650	// Defaults to "Never".
 651	"reinvocationPolicy"?: string
 652
 653	// rules describes what operations on what resources/subresources the webhook
 654	// cares about. The webhook cares about an operation if it matches _any_ Rule.
 655	// However, in order to prevent ValidatingAdmissionWebhooks and
 656	// MutatingAdmissionWebhooks from putting the cluster in a state which cannot
 657	// be recovered from without completely disabling the plugin,
 658	// ValidatingAdmissionWebhooks and MutatingAdmissionWebhooks are never called
 659	// on admission requests for ValidatingWebhookConfiguration and
 660	// MutatingWebhookConfiguration objects.
 661	"rules"?: [...#RuleWithOperations]
 662
 663	// sideEffects states whether this webhook has side effects. Acceptable values
 664	// are: None, NoneOnDryRun (webhooks created via v1beta1 may also specify Some
 665	// or Unknown). Webhooks with side effects MUST implement a reconciliation
 666	// system, since a request may be rejected by a future step in the admission
 667	// chain and the side effects therefore need to be undone. Requests with the
 668	// dryRun attribute will be auto-rejected if they match a webhook with
 669	// sideEffects == Unknown or Some.
 670	"sideEffects"!: string
 671
 672	// timeoutSeconds specifies the timeout for this webhook. After the timeout
 673	// passes, the webhook call will be ignored or the API call will fail based on
 674	// the failure policy. The timeout value must be between 1 and 30 seconds.
 675	// Default to 10 seconds.
 676	"timeoutSeconds"?: int32 & int
 677}
 678
 679// MutatingWebhookConfiguration describes the configuration of and admission
 680// webhook that accept or reject and may change the object.
 681#MutatingWebhookConfiguration: {
 682	// APIVersion defines the versioned schema of this representation of an object.
 683	// Servers should convert recognized schemas to the latest internal value, and
 684	// may reject unrecognized values. More info:
 685	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 686	"apiVersion": "admissionregistration.k8s.io/v1"
 687
 688	// Kind is a string value representing the REST resource this object represents.
 689	// Servers may infer this from the endpoint the client submits requests to.
 690	// Cannot be updated. In CamelCase. More info:
 691	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 692	"kind": "MutatingWebhookConfiguration"
 693
 694	// metadata is the standard object metadata; More info:
 695	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
 696	"metadata"?: v1.#ObjectMeta
 697
 698	// webhooks is a list of webhooks and the affected resources and operations.
 699	"webhooks"?: [...#MutatingWebhook]
 700}
 701
 702// MutatingWebhookConfigurationList is a list of MutatingWebhookConfiguration.
 703#MutatingWebhookConfigurationList: {
 704	// APIVersion defines the versioned schema of this representation of an object.
 705	// Servers should convert recognized schemas to the latest internal value, and
 706	// may reject unrecognized values. More info:
 707	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 708	"apiVersion": "admissionregistration.k8s.io/v1"
 709
 710	// List of MutatingWebhookConfiguration.
 711	"items"!: [...#MutatingWebhookConfiguration]
 712
 713	// Kind is a string value representing the REST resource this object represents.
 714	// Servers may infer this from the endpoint the client submits requests to.
 715	// Cannot be updated. In CamelCase. More info:
 716	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 717	"kind": "MutatingWebhookConfigurationList"
 718
 719	// metadata is the standard list metadata. More info:
 720	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 721	"metadata"?: v1.#ListMeta
 722}
 723
 724// Mutation specifies the CEL expression which is used to apply the Mutation.
 725#Mutation: {
 726	// applyConfiguration defines the desired configuration values of an object. The
 727	// configuration is applied to the admission object using [structured merge
 728	// diff](https://github.com/kubernetes-sigs/structured-merge-diff). A CEL
 729	// expression is used to create apply configuration.
 730	"applyConfiguration"?: #ApplyConfiguration
 731
 732	// jsonPatch defines a [JSON patch](https://jsonpatch.com/) operation to perform
 733	// a mutation to the object. A CEL expression is used to create the JSON patch.
 734	"jsonPatch"?: #JSONPatch
 735
 736	// patchType indicates the patch strategy used. Allowed values are
 737	// "ApplyConfiguration" and "JSONPatch". Required.
 738	"patchType"!: string
 739}
 740
 741// NamedRuleWithOperations is a tuple of Operations and Resources with ResourceNames.
 742#NamedRuleWithOperations: {
 743	// apiGroups is the API groups the resources belong to. '*' is all groups. If
 744	// '*' is present, the length of the slice must be one. Required.
 745	"apiGroups"?: [...string]
 746
 747	// apiVersions is the API versions the resources belong to. '*' is all versions.
 748	// If '*' is present, the length of the slice must be one. Required.
 749	"apiVersions"?: [...string]
 750
 751	// operations is the operations the admission hook cares about - CREATE, UPDATE,
 752	// DELETE, CONNECT or * for all of those operations and any future admission
 753	// operations that are added. If '*' is present, the length of the slice must
 754	// be one. Required.
 755	"operations"?: [...string]
 756
 757	// resourceNames is an optional white list of names that the rule applies to. An
 758	// empty set means that everything is allowed.
 759	"resourceNames"?: [...string]
 760
 761	// resources is a list of resources this rule applies to.
 762	//
 763	// For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
 764	// '*' means all resources, but not subresources. 'pods/*' means all
 765	// subresources of pods. '*/scale' means all scale subresources. '*/*' means
 766	// all resources and their subresources.
 767	//
 768	// If wildcard is present, the validation rule will ensure resources do not overlap with each other.
 769	//
 770	// Depending on the enclosing object, subresources might not be allowed. Required.
 771	"resources"?: [...string]
 772
 773	// scope specifies the scope of this rule. Valid values are "Cluster",
 774	// "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
 775	// will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
 776	// means that only namespaced resources will match this rule. "*" means that
 777	// there are no scope restrictions. Subresources match the scope of their
 778	// parent resource. Default is "*".
 779	"scope"?: string
 780}
 781
 782// ParamKind is a tuple of Group Kind and Version.
 783#ParamKind: {
 784	// apiVersion is the API group version the resources belong to. In format of
 785	// "group/version". Required.
 786	"apiVersion"?: string
 787
 788	// kind is the API kind the resources belong to. Required.
 789	"kind"?: string
 790}
 791
 792// ParamRef describes how to locate the params to be used as input to
 793// expressions of rules applied by a policy binding.
 794#ParamRef: {
 795	// name is the name of the resource being referenced.
 796	//
 797	// One of `name` or `selector` must be set, but `name` and `selector` are
 798	// mutually exclusive properties. If one is set, the other must be unset.
 799	//
 800	// A single parameter used for all admission requests can be configured by
 801	// setting the `name` field, leaving `selector` blank, and setting namespace if
 802	// `paramKind` is namespace-scoped.
 803	"name"?: string
 804
 805	// namespace is the namespace of the referenced resource. Allows limiting the
 806	// search for params to a specific namespace. Applies to both `name` and
 807	// `selector` fields.
 808	//
 809	// A per-namespace parameter may be used by specifying a namespace-scoped
 810	// `paramKind` in the policy and leaving this field empty.
 811	//
 812	// - If `paramKind` is cluster-scoped, this field MUST be unset. Setting this
 813	// field results in a configuration error.
 814	//
 815	// - If `paramKind` is namespace-scoped, the namespace of the object being
 816	// evaluated for admission will be used when this field is left unset. Take
 817	// care that if this is left empty the binding must not match any
 818	// cluster-scoped resources, which will result in an error.
 819	"namespace"?: string
 820
 821	// parameterNotFoundAction controls the behavior of the binding when the
 822	// resource exists, and name or selector is valid, but there are no parameters
 823	// matched by the binding. If the value is set to `Allow`, then no matched
 824	// parameters will be treated as successful validation by the binding. If set
 825	// to `Deny`, then no matched parameters will be subject to the `failurePolicy`
 826	// of the policy.
 827	//
 828	// Allowed values are `Allow` or `Deny`
 829	//
 830	// Required
 831	"parameterNotFoundAction"?: string
 832
 833	// selector can be used to match multiple param objects based on their labels.
 834	// Supply selector: {} to match all resources of the ParamKind.
 835	//
 836	// If multiple params are found, they are all evaluated with the policy
 837	// expressions and the results are ANDed together.
 838	//
 839	// One of `name` or `selector` must be set, but `name` and `selector` are
 840	// mutually exclusive properties. If one is set, the other must be unset.
 841	"selector"?: v1.#LabelSelector
 842}
 843
 844// RuleWithOperations is a tuple of Operations and Resources. It is recommended
 845// to make sure that all the tuple expansions are valid.
 846#RuleWithOperations: {
 847	// apiGroups is the API groups the resources belong to. '*' is all groups. If
 848	// '*' is present, the length of the slice must be one. Required.
 849	"apiGroups"?: [...string]
 850
 851	// apiVersions is the API versions the resources belong to. '*' is all versions.
 852	// If '*' is present, the length of the slice must be one. Required.
 853	"apiVersions"?: [...string]
 854
 855	// operations is the operations the admission hook cares about - CREATE, UPDATE,
 856	// DELETE, CONNECT or * for all of those operations and any future admission
 857	// operations that are added. If '*' is present, the length of the slice must
 858	// be one. Required.
 859	"operations"?: [...string]
 860
 861	// resources is a list of resources this rule applies to.
 862	//
 863	// For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
 864	// '*' means all resources, but not subresources. 'pods/*' means all
 865	// subresources of pods. '*/scale' means all scale subresources. '*/*' means
 866	// all resources and their subresources.
 867	//
 868	// If wildcard is present, the validation rule will ensure resources do not overlap with each other.
 869	//
 870	// Depending on the enclosing object, subresources might not be allowed. Required.
 871	"resources"?: [...string]
 872
 873	// scope specifies the scope of this rule. Valid values are "Cluster",
 874	// "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
 875	// will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
 876	// means that only namespaced resources will match this rule. "*" means that
 877	// there are no scope restrictions. Subresources match the scope of their
 878	// parent resource. Default is "*".
 879	"scope"?: string
 880}
 881
 882// ServiceReference holds a reference to Service.legacy.k8s.io
 883#ServiceReference: {
 884	// name is the name of the service. Required
 885	"name"!: string
 886
 887	// namespace is the namespace of the service. Required
 888	"namespace"!: string
 889
 890	// path is an optional URL path which will be sent in any request to this service.
 891	"path"?: string
 892
 893	// port is the port on the service that hosts the webhook. Default to 443 for
 894	// backward compatibility. `port` should be a valid port number (1-65535,
 895	// inclusive).
 896	"port"?: int32 & int
 897}
 898
 899// TypeChecking contains results of type checking the expressions in the ValidatingAdmissionPolicy
 900#TypeChecking: {
 901	// expressionWarnings contains the type checking warnings for each expression.
 902	"expressionWarnings"?: [...#ExpressionWarning]
 903}
 904
 905// ValidatingAdmissionPolicy describes the definition of an admission validation
 906// policy that accepts or rejects an object without changing it.
 907#ValidatingAdmissionPolicy: {
 908	// APIVersion defines the versioned schema of this representation of an object.
 909	// Servers should convert recognized schemas to the latest internal value, and
 910	// may reject unrecognized values. More info:
 911	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 912	"apiVersion": "admissionregistration.k8s.io/v1"
 913
 914	// Kind is a string value representing the REST resource this object represents.
 915	// Servers may infer this from the endpoint the client submits requests to.
 916	// Cannot be updated. In CamelCase. More info:
 917	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 918	"kind": "ValidatingAdmissionPolicy"
 919
 920	// metadata is the standard object metadata; More info:
 921	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
 922	"metadata"?: v1.#ObjectMeta
 923
 924	// spec defines the desired behavior of the ValidatingAdmissionPolicy.
 925	"spec"?: #ValidatingAdmissionPolicySpec
 926
 927	// status represents the current status of the ValidatingAdmissionPolicy,
 928	// including warnings that are useful to determine if the policy behaves in the
 929	// expected way. Populated by the system. Read-only.
 930	"status"?: #ValidatingAdmissionPolicyStatus
 931}
 932
 933// ValidatingAdmissionPolicyBinding binds the ValidatingAdmissionPolicy with
 934// paramerized resources. ValidatingAdmissionPolicyBinding and parameter CRDs
 935// together define how cluster administrators configure policies for clusters.
 936//
 937// For a given admission request, each binding will cause its policy to be
 938// evaluated N times, where N is 1 for policies/bindings that don't use params,
 939// otherwise N is the number of parameters selected by the binding.
 940//
 941// The CEL expressions of a policy must have a computed CEL cost below the
 942// maximum CEL budget. Each evaluation of the policy is given an independent
 943// CEL cost budget. Adding/removing policies, bindings, or params can not
 944// affect whether a given (policy, binding, param) combination is within its
 945// own CEL budget.
 946#ValidatingAdmissionPolicyBinding: {
 947	// APIVersion defines the versioned schema of this representation of an object.
 948	// Servers should convert recognized schemas to the latest internal value, and
 949	// may reject unrecognized values. More info:
 950	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 951	"apiVersion": "admissionregistration.k8s.io/v1"
 952
 953	// Kind is a string value representing the REST resource this object represents.
 954	// Servers may infer this from the endpoint the client submits requests to.
 955	// Cannot be updated. In CamelCase. More info:
 956	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 957	"kind": "ValidatingAdmissionPolicyBinding"
 958
 959	// metadata is the standard object metadata; More info:
 960	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
 961	"metadata"?: v1.#ObjectMeta
 962
 963	// spec defines the desired behavior of the ValidatingAdmissionPolicyBinding.
 964	"spec"!: #ValidatingAdmissionPolicyBindingSpec
 965}
 966
 967// ValidatingAdmissionPolicyBindingList is a list of ValidatingAdmissionPolicyBinding.
 968#ValidatingAdmissionPolicyBindingList: {
 969	// APIVersion defines the versioned schema of this representation of an object.
 970	// Servers should convert recognized schemas to the latest internal value, and
 971	// may reject unrecognized values. More info:
 972	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 973	"apiVersion": "admissionregistration.k8s.io/v1"
 974
 975	// List of PolicyBinding.
 976	"items"!: [...#ValidatingAdmissionPolicyBinding]
 977
 978	// Kind is a string value representing the REST resource this object represents.
 979	// Servers may infer this from the endpoint the client submits requests to.
 980	// Cannot be updated. In CamelCase. More info:
 981	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 982	"kind": "ValidatingAdmissionPolicyBindingList"
 983
 984	// metadata is the standard list metadata. More info:
 985	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 986	"metadata"?: v1.#ListMeta
 987}
 988
 989// ValidatingAdmissionPolicyBindingSpec is the specification of the
 990// ValidatingAdmissionPolicyBinding.
 991#ValidatingAdmissionPolicyBindingSpec: {
 992	// matchResources declares what resources match this binding and will be
 993	// validated by it. Note that this is intersected with the policy's
 994	// matchConstraints, so only requests that are matched by the policy can be
 995	// selected by this. If this is unset, all resources matched by the policy are
 996	// validated by this binding When resourceRules is unset, it does not constrain
 997	// resource matching. If a resource is matched by the other fields of this
 998	// object, it will be validated. Note that this is differs from
 999	// ValidatingAdmissionPolicy matchConstraints, where resourceRules are
1000	// required.
1001	"matchResources"?: #MatchResources
1002
1003	// paramRef specifies the parameter resource used to configure the admission
1004	// control policy. It should point to a resource of the type specified in
1005	// ParamKind of the bound ValidatingAdmissionPolicy. If the policy specifies a
1006	// ParamKind and the resource referred to by ParamRef does not exist, this
1007	// binding is considered mis-configured and the FailurePolicy of the
1008	// ValidatingAdmissionPolicy applied. If the policy does not specify a
1009	// ParamKind then this field is ignored, and the rules are evaluated without a
1010	// param.
1011	"paramRef"?: #ParamRef
1012
1013	// policyName references a ValidatingAdmissionPolicy name which the
1014	// ValidatingAdmissionPolicyBinding binds to. If the referenced resource does
1015	// not exist, this binding is considered invalid and will be ignored Required.
1016	"policyName"!: string
1017
1018	// validationActions declares how Validations of the referenced
1019	// ValidatingAdmissionPolicy are enforced. If a validation evaluates to false
1020	// it is always enforced according to these actions.
1021	//
1022	// Failures defined by the ValidatingAdmissionPolicy's FailurePolicy are
1023	// enforced according to these actions only if the FailurePolicy is set to
1024	// Fail, otherwise the failures are ignored. This includes compilation errors,
1025	// runtime errors and misconfigurations of the policy.
1026	//
1027	// validationActions is declared as a set of action values. Order does not
1028	// matter. validationActions may not contain duplicates of the same action.
1029	//
1030	// The supported actions values are:
1031	//
1032	// "Deny" specifies that a validation failure results in a denied request.
1033	//
1034	// "Warn" specifies that a validation failure is reported to the request client
1035	// in HTTP Warning headers, with a warning code of 299. Warnings can be sent
1036	// both for allowed or denied admission responses.
1037	//
1038	// "Audit" specifies that a validation failure is included in the published
1039	// audit event for the request. The audit event will contain a
1040	// `validation.policy.admission.k8s.io/validation_failure` audit annotation
1041	// with a value containing the details of the validation failures, formatted as
1042	// a JSON list of objects, each with the following fields: - message: The
1043	// validation failure message string - policy: The resource name of the
1044	// ValidatingAdmissionPolicy - binding: The resource name of the
1045	// ValidatingAdmissionPolicyBinding - expressionIndex: The index of the failed
1046	// validations in the ValidatingAdmissionPolicy - validationActions: The
1047	// enforcement actions enacted for the validation failure Example audit
1048	// annotation: `"validation.policy.admission.k8s.io/validation_failure":
1049	// "[{\"message\": \"Invalid value\", {\"policy\": \"policy.example.com\",
1050	// {\"binding\": \"policybinding.example.com\", {\"expressionIndex\": \"1\",
1051	// {\"validationActions\": [\"Audit\"]}]"`
1052	//
1053	// Clients should expect to handle additional values by ignoring any values not recognized.
1054	//
1055	// "Deny" and "Warn" may not be used together since this combination needlessly
1056	// duplicates the validation failure both in the API response body and the HTTP
1057	// warning headers.
1058	//
1059	// Required.
1060	"validationActions"!: [...string]
1061}
1062
1063// ValidatingAdmissionPolicyList is a list of ValidatingAdmissionPolicy.
1064#ValidatingAdmissionPolicyList: {
1065	// APIVersion defines the versioned schema of this representation of an object.
1066	// Servers should convert recognized schemas to the latest internal value, and
1067	// may reject unrecognized values. More info:
1068	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1069	"apiVersion": "admissionregistration.k8s.io/v1"
1070
1071	// List of ValidatingAdmissionPolicy.
1072	"items"!: [...#ValidatingAdmissionPolicy]
1073
1074	// Kind is a string value representing the REST resource this object represents.
1075	// Servers may infer this from the endpoint the client submits requests to.
1076	// Cannot be updated. In CamelCase. More info:
1077	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1078	"kind": "ValidatingAdmissionPolicyList"
1079
1080	// metadata is the standard list metadata. More info:
1081	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1082	"metadata"?: v1.#ListMeta
1083}
1084
1085// ValidatingAdmissionPolicySpec is the specification of the desired behavior of
1086// the AdmissionPolicy.
1087#ValidatingAdmissionPolicySpec: {
1088	// auditAnnotations contains CEL expressions which are used to produce audit
1089	// annotations for the audit event of the API request. validations and
1090	// auditAnnotations may not both be empty; a least one of validations or
1091	// auditAnnotations is required.
1092	"auditAnnotations"?: [...#AuditAnnotation]
1093
1094	// failurePolicy defines how to handle failures for the admission policy.
1095	// Failures can occur from CEL expression parse errors, type check errors,
1096	// runtime errors and invalid or mis-configured policy definitions or bindings.
1097	//
1098	// A policy is invalid if spec.paramKind refers to a non-existent Kind. A
1099	// binding is invalid if spec.paramRef.name refers to a non-existent resource.
1100	//
1101	// failurePolicy does not define how validations that evaluate to false are handled.
1102	//
1103	// When failurePolicy is set to Fail, ValidatingAdmissionPolicyBinding
1104	// validationActions define how failures are enforced.
1105	//
1106	// Allowed values are Ignore or Fail. Defaults to Fail.
1107	"failurePolicy"?: string
1108
1109	// matchConditions is a list of conditions that must be met for a request to be
1110	// validated. Match conditions filter requests that have already been matched
1111	// by the rules, namespaceSelector, and objectSelector. An empty list of
1112	// matchConditions matches all requests. There are a maximum of 64 match
1113	// conditions allowed.
1114	//
1115	// If a parameter object is provided, it can be accessed via the `params` handle
1116	// in the same manner as validation expressions.
1117	//
1118	// The exact matching logic is (in order):
1119	// 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
1120	// 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
1121	// 3. If any matchCondition evaluates to an error (but none are FALSE):
1122	// - If failurePolicy=Fail, reject the request
1123	// - If failurePolicy=Ignore, the policy is skipped
1124	"matchConditions"?: [...#MatchCondition]
1125
1126	// matchConstraints specifies what resources this policy is designed to
1127	// validate. The AdmissionPolicy cares about a request if it matches _all_
1128	// Constraints. However, in order to prevent clusters from being put into an
1129	// unstable state that cannot be recovered from via the API
1130	// ValidatingAdmissionPolicy cannot match ValidatingAdmissionPolicy and
1131	// ValidatingAdmissionPolicyBinding. Required.
1132	"matchConstraints"?: #MatchResources
1133
1134	// paramKind specifies the kind of resources used to parameterize this policy.
1135	// If absent, there are no parameters for this policy and the param CEL
1136	// variable will not be provided to validation expressions. If ParamKind refers
1137	// to a non-existent kind, this policy definition is mis-configured and the
1138	// FailurePolicy is applied. If paramKind is specified but paramRef is unset in
1139	// ValidatingAdmissionPolicyBinding, the params variable will be null.
1140	"paramKind"?: #ParamKind
1141
1142	// validations contain CEL expressions which is used to apply the validation.
1143	// Validations and AuditAnnotations may not both be empty; a minimum of one
1144	// Validations or AuditAnnotations is required.
1145	"validations"?: [...#Validation]
1146
1147	// variables contain definitions of variables that can be used in composition of
1148	// other expressions. Each variable is defined as a named CEL expression. The
1149	// variables defined here will be available under `variables` in other
1150	// expressions of the policy except MatchConditions because MatchConditions are
1151	// evaluated before the rest of the policy.
1152	//
1153	// The expression of a variable can refer to other variables defined earlier in
1154	// the list but not those after. Thus, Variables must be sorted by the order of
1155	// first appearance and acyclic.
1156	"variables"?: [...#Variable]
1157}
1158
1159// ValidatingAdmissionPolicyStatus represents the status of an admission validation policy.
1160#ValidatingAdmissionPolicyStatus: {
1161	// conditions represent the latest available observations of a policy's current state.
1162	"conditions"?: [...v1.#Condition]
1163
1164	// observedGeneration is the generation observed by the controller.
1165	"observedGeneration"?: int64 & int
1166
1167	// typeChecking contains the results of type checking for each expression.
1168	// Presence of this field indicates the completion of the type checking.
1169	"typeChecking"?: #TypeChecking
1170}
1171
1172// ValidatingWebhook describes an admission webhook and the resources and operations it applies to.
1173#ValidatingWebhook: {
1174	// admissionReviewVersions is an ordered list of preferred `AdmissionReview`
1175	// versions the Webhook expects. API server will try to use first version in
1176	// the list which it supports. If none of the versions specified in this list
1177	// supported by API server, validation will fail for this object. If a
1178	// persisted webhook configuration specifies allowed versions and does not
1179	// include any versions known to the API Server, calls to the webhook will fail
1180	// and be subject to the failure policy.
1181	"admissionReviewVersions"!: [...string]
1182
1183	// clientConfig defines how to communicate with the hook. Required
1184	"clientConfig"!: #WebhookClientConfig
1185
1186	// failurePolicy defines how unrecognized errors from the admission endpoint are
1187	// handled - allowed values are Ignore or Fail. Defaults to Fail.
1188	"failurePolicy"?: string
1189
1190	// matchConditions is a list of conditions that must be met for a request to be
1191	// sent to this webhook. Match conditions filter requests that have already
1192	// been matched by the rules, namespaceSelector, and objectSelector. An empty
1193	// list of matchConditions matches all requests. There are a maximum of 64
1194	// match conditions allowed.
1195	//
1196	// The exact matching logic is (in order):
1197	// 1. If ANY matchCondition evaluates to FALSE, the webhook is skipped.
1198	// 2. If ALL matchConditions evaluate to TRUE, the webhook is called.
1199	// 3. If any matchCondition evaluates to an error (but none are FALSE):
1200	// - If failurePolicy=Fail, reject the request
1201	// - If failurePolicy=Ignore, the error is ignored and the webhook is skipped
1202	"matchConditions"?: [...#MatchCondition]
1203
1204	// matchPolicy defines how the "rules" list is used to match incoming requests.
1205	// Allowed values are "Exact" or "Equivalent".
1206	//
1207	// - Exact: match a request only if it exactly matches a specified rule. For
1208	// example, if deployments can be modified via apps/v1, apps/v1beta1, and
1209	// extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
1210	// apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
1211	// or extensions/v1beta1 would not be sent to the webhook.
1212	//
1213	// - Equivalent: match a request if modifies a resource listed in rules, even
1214	// via another API group or version. For example, if deployments can be
1215	// modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
1216	// included `apiGroups:["apps"], apiVersions:["v1"], resources:
1217	// ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
1218	// converted to apps/v1 and sent to the webhook.
1219	//
1220	// Defaults to "Equivalent"
1221	"matchPolicy"?: string
1222
1223	// name is the name of the admission webhook. Name should be fully qualified,
1224	// e.g., imagepolicy.kubernetes.io, where "imagepolicy" is the name of the
1225	// webhook, and kubernetes.io is the name of the organization. Required.
1226	"name"!: string
1227
1228	// namespaceSelector decides whether to run the webhook on an object based on
1229	// whether the namespace for that object matches the selector. If the object
1230	// itself is a namespace, the matching is performed on object.metadata.labels.
1231	// If the object is another cluster scoped resource, it never skips the
1232	// webhook.
1233	//
1234	// For example, to run the webhook on any objects whose namespace is not
1235	// associated with "runlevel" of "0" or "1"; you will set the selector as
1236	// follows: "namespaceSelector": {
1237	// "matchExpressions": [
1238	// {
1239	// "key": "runlevel",
1240	// "operator": "NotIn",
1241	// "values": [
1242	// "0",
1243	// "1"
1244	// ]
1245	// }
1246	// ]
1247	// }
1248	//
1249	// If instead you want to only run the webhook on any objects whose namespace is
1250	// associated with the "environment" of "prod" or "staging"; you will set the
1251	// selector as follows: "namespaceSelector": {
1252	// "matchExpressions": [
1253	// {
1254	// "key": "environment",
1255	// "operator": "In",
1256	// "values": [
1257	// "prod",
1258	// "staging"
1259	// ]
1260	// }
1261	// ]
1262	// }
1263	//
1264	// See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels
1265	// for more examples of label selectors.
1266	//
1267	// Default to the empty LabelSelector, which matches everything.
1268	"namespaceSelector"?: v1.#LabelSelector
1269
1270	// objectSelector decides whether to run the webhook based on if the object has
1271	// matching labels. objectSelector is evaluated against both the oldObject and
1272	// newObject that would be sent to the webhook, and is considered to match if
1273	// either object matches the selector. A null object (oldObject in the case of
1274	// create, or newObject in the case of delete) or an object that cannot have
1275	// labels (like a DeploymentRollback or a PodProxyOptions object) is not
1276	// considered to match. Use the object selector only if the webhook is opt-in,
1277	// because end users may skip the admission webhook by setting the labels.
1278	// Default to the empty LabelSelector, which matches everything.
1279	"objectSelector"?: v1.#LabelSelector
1280
1281	// rules describes what operations on what resources/subresources the webhook
1282	// cares about. The webhook cares about an operation if it matches _any_ Rule.
1283	// However, in order to prevent ValidatingAdmissionWebhooks and
1284	// MutatingAdmissionWebhooks from putting the cluster in a state which cannot
1285	// be recovered from without completely disabling the plugin,
1286	// ValidatingAdmissionWebhooks and MutatingAdmissionWebhooks are never called
1287	// on admission requests for ValidatingWebhookConfiguration and
1288	// MutatingWebhookConfiguration objects.
1289	"rules"?: [...#RuleWithOperations]
1290
1291	// sideEffects states whether this webhook has side effects. Acceptable values
1292	// are: None, NoneOnDryRun (webhooks created via v1beta1 may also specify Some
1293	// or Unknown). Webhooks with side effects MUST implement a reconciliation
1294	// system, since a request may be rejected by a future step in the admission
1295	// chain and the side effects therefore need to be undone. Requests with the
1296	// dryRun attribute will be auto-rejected if they match a webhook with
1297	// sideEffects == Unknown or Some.
1298	"sideEffects"!: string
1299
1300	// timeoutSeconds specifies the timeout for this webhook. After the timeout
1301	// passes, the webhook call will be ignored or the API call will fail based on
1302	// the failure policy. The timeout value must be between 1 and 30 seconds.
1303	// Default to 10 seconds.
1304	"timeoutSeconds"?: int32 & int
1305}
1306
1307// ValidatingWebhookConfiguration describes the configuration of and admission
1308// webhook that accept or reject and object without changing it.
1309#ValidatingWebhookConfiguration: {
1310	// APIVersion defines the versioned schema of this representation of an object.
1311	// Servers should convert recognized schemas to the latest internal value, and
1312	// may reject unrecognized values. More info:
1313	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1314	"apiVersion": "admissionregistration.k8s.io/v1"
1315
1316	// Kind is a string value representing the REST resource this object represents.
1317	// Servers may infer this from the endpoint the client submits requests to.
1318	// Cannot be updated. In CamelCase. More info:
1319	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1320	"kind": "ValidatingWebhookConfiguration"
1321
1322	// metadata is the standard object metadata; More info:
1323	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
1324	"metadata"?: v1.#ObjectMeta
1325
1326	// webhooks is a list of webhooks and the affected resources and operations.
1327	"webhooks"?: [...#ValidatingWebhook]
1328}
1329
1330// ValidatingWebhookConfigurationList is a list of ValidatingWebhookConfiguration.
1331#ValidatingWebhookConfigurationList: {
1332	// APIVersion defines the versioned schema of this representation of an object.
1333	// Servers should convert recognized schemas to the latest internal value, and
1334	// may reject unrecognized values. More info:
1335	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1336	"apiVersion": "admissionregistration.k8s.io/v1"
1337
1338	// List of ValidatingWebhookConfiguration.
1339	"items"!: [...#ValidatingWebhookConfiguration]
1340
1341	// Kind is a string value representing the REST resource this object represents.
1342	// Servers may infer this from the endpoint the client submits requests to.
1343	// Cannot be updated. In CamelCase. More info:
1344	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1345	"kind": "ValidatingWebhookConfigurationList"
1346
1347	// metadata is the standard list metadata. More info:
1348	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1349	"metadata"?: v1.#ListMeta
1350}
1351
1352// Validation specifies the CEL expression which is used to apply the validation.
1353#Validation: {
1354	// expression represents the expression which will be evaluated by CEL. ref:
1355	// https://github.com/google/cel-spec CEL expressions have access to the
1356	// contents of the API request/response, organized into CEL variables as well
1357	// as some other useful variables:
1358	//
1359	// - 'object' - The object from the incoming request. The value is null for
1360	// DELETE requests. - 'oldObject' - The existing object. The value is null for
1361	// CREATE requests. - 'request' - Attributes of the API
1362	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
1363	// Parameter resource referred to by the policy binding being evaluated. Only
1364	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
1365	// object that the incoming object belongs to. The value is null for
1366	// cluster-scoped resources. - 'variables' - Map of composited variables, from
1367	// its name to its lazily evaluated value.
1368	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
1369	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
1370	// checks for the principal (user or service account) of the request.
1371	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
1372	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
1373	// 'authorizer' and configured with the
1374	// request resource.
1375	//
1376	// The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
1377	// always accessible from the root of the object. No other metadata properties
1378	// are accessible.
1379	//
1380	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are
1381	// accessible. Accessible property names are escaped according to the following
1382	// rules when accessed in the expression: - '__' escapes to '__underscores__' -
1383	// '.' escapes to '__dot__' - '-' escapes to '__dash__' - '/' escapes to
1384	// '__slash__' - Property names that exactly match a CEL RESERVED keyword
1385	// escape to '__{keyword}__'. The keywords are:
1386	// "true", "false", "null", "in", "as", "break", "const", "continue", "else",
1387	// "for", "function", "if",
1388	// "import", "let", "loop", "package", "namespace", "return".
1389	// Examples:
1390	// - Expression accessing a property named "namespace": {"Expression": "object.__namespace__ > 0"}
1391	// - Expression accessing a property named "x-prop": {"Expression": "object.x__dash__prop > 0"}
1392	// - Expression accessing a property named "redact__d": {"Expression":
1393	// "object.redact__underscores__d > 0"}
1394	//
1395	// Equality on arrays with list type of 'set' or 'map' ignores element order,
1396	// i.e. [1, 2] == [2, 1]. Concatenation on arrays with x-kubernetes-list-type
1397	// use the semantics of the list type:
1398	// - 'set': `X + Y` performs a union where the array positions of all elements
1399	// in `X` are preserved and
1400	// non-intersecting elements in `Y` are appended, retaining their partial order.
1401	// - 'map': `X + Y` performs a merge where the array positions of all keys in
1402	// `X` are preserved but the values
1403	// are overwritten by values in `Y` when the key sets of `X` and `Y` intersect. Elements in `Y` with
1404	// non-intersecting keys are appended, retaining their partial order.
1405	// Required.
1406	"expression"!: string
1407
1408	// message represents the message displayed when validation fails. The message
1409	// is required if the Expression contains line breaks. The message must not
1410	// contain line breaks. If unset, the message is "failed rule: {Rule}". e.g.
1411	// "must be a URL with the host matching spec.host" If the Expression contains
1412	// line breaks. Message is required. The message must not contain line breaks.
1413	// If unset, the message is "failed Expression: {Expression}".
1414	"message"?: string
1415
1416	// messageExpression declares a CEL expression that evaluates to the validation
1417	// failure message that is returned when this rule fails. Since
1418	// messageExpression is used as a failure message, it must evaluate to a
1419	// string. If both message and messageExpression are present on a validation,
1420	// then messageExpression will be used if validation fails. If
1421	// messageExpression results in a runtime error, the runtime error is logged,
1422	// and the validation failure message is produced as if the messageExpression
1423	// field were unset. If messageExpression evaluates to an empty string, a
1424	// string with only spaces, or a string that contains line breaks, then the
1425	// validation failure message will also be produced as if the messageExpression
1426	// field were unset, and the fact that messageExpression produced an empty
1427	// string/string with only spaces/string with line breaks will be logged.
1428	// messageExpression has access to all the same variables as the `expression`
1429	// except for 'authorizer' and 'authorizer.requestResource'. Example: "object.x
1430	// must be less than max ("+string(params.max)+")"
1431	"messageExpression"?: string
1432
1433	// reason represents a machine-readable description of why this validation
1434	// failed. If this is the first validation in the list to fail, this reason, as
1435	// well as the corresponding HTTP response code, are used in the HTTP response
1436	// to the client. The currently supported reasons are: "Unauthorized",
1437	// "Forbidden", "Invalid", "RequestEntityTooLarge". If not set,
1438	// StatusReasonInvalid is used in the response to the client.
1439	"reason"?: string
1440}
1441
1442// Variable is the definition of a variable that is used for composition. A
1443// variable is defined as a named expression.
1444#Variable: {
1445	// expression is the expression that will be evaluated as the value of the
1446	// variable. The CEL expression has access to the same identifiers as the CEL
1447	// expressions in Validation.
1448	"expression"!: string
1449
1450	// name is the name of the variable. The name must be a valid CEL identifier and
1451	// unique among all variables. The variable can be accessed in other
1452	// expressions through `variables` For example, if name is "foo", the variable
1453	// will be available as `variables.foo`
1454	"name"!: string
1455}
1456
1457// WebhookClientConfig contains the information to make a TLS connection with the webhook
1458#WebhookClientConfig: {
1459	// caBundle is a PEM encoded CA bundle which will be used to validate the
1460	// webhook's server certificate. If unspecified, system trust roots on the
1461	// apiserver are used.
1462	"caBundle"?: string
1463
1464	// service is a reference to the service for this webhook. Either `service` or
1465	// `url` must be specified.
1466	//
1467	// If the webhook is running within the cluster, then you should use `service`.
1468	"service"?: #ServiceReference
1469
1470	// url gives the location of the webhook, in standard URL form
1471	// (`scheme://host:port/path`). Exactly one of `url` or `service` must be
1472	// specified.
1473	//
1474	// The `host` should not refer to a service running in the cluster; use the
1475	// `service` field instead. The host might be resolved via external DNS in some
1476	// apiservers (e.g., `kube-apiserver` cannot resolve in-cluster DNS as that
1477	// would be a layering violation). `host` may also be an IP address.
1478	//
1479	// Please note that using `localhost` or `127.0.0.1` as a `host` is risky unless
1480	// you take great care to run this webhook on all hosts which run an apiserver
1481	// which might need to make calls to this webhook. Such installs are likely to
1482	// be non-portable, i.e., not easy to turn up in a new cluster.
1483	//
1484	// The scheme must be "https"; the URL must begin with "https://".
1485	//
1486	// A path is optional, and if present may be any string permissible in a URL.
1487	// You may use the path to pass an arbitrary string to the webhook, for
1488	// example, a cluster identifier.
1489	//
1490	// Attempting to use a user or basic auth e.g. "user:password@" is not allowed.
1491	// Fragments ("#...") and query parameters ("?...") are not allowed, either.
1492	"url"?: string
1493}