1package v1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// ApplyConfiguration defines the desired configuration values of an object.
6#ApplyConfiguration: {
7 // expression will be evaluated by CEL to create an apply configuration. ref:
8 // https://github.com/google/cel-spec
9 //
10 // Apply configurations are declared in CEL using object initialization. For
11 // example, this CEL expression returns an apply configuration to set a single
12 // field:
13 //
14 // Object{
15 // spec: Object.spec{
16 // serviceAccountName: "example"
17 // }
18 // }
19 //
20 // Apply configurations may not modify atomic structs, maps or arrays due to the
21 // risk of accidental deletion of values not included in the apply
22 // configuration.
23 //
24 // CEL expressions have access to the object types needed to create apply configurations:
25 //
26 // - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
27 // type of object field (such as 'Object.spec') -
28 // 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
29 // (such as 'Object.spec.containers')
30 //
31 // CEL expressions have access to the contents of the API request, organized
32 // into CEL variables as well as some other useful variables:
33 //
34 // - 'object' - The object from the incoming request. The value is null for
35 // DELETE requests. - 'oldObject' - The existing object. The value is null for
36 // CREATE requests. - 'request' - Attributes of the API
37 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
38 // Parameter resource referred to by the policy binding being evaluated. Only
39 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
40 // object that the incoming object belongs to. The value is null for
41 // cluster-scoped resources. - 'variables' - Map of composited variables, from
42 // its name to its lazily evaluated value.
43 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
44 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
45 // checks for the principal (user or service account) of the request.
46 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
47 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
48 // 'authorizer' and configured with the
49 // request resource.
50 //
51 // The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
52 // always accessible from the root of the object. No other metadata properties
53 // are accessible.
54 //
55 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
56 "expression"?: string
57}
58
59// AuditAnnotation describes how to produce an audit annotation for an API request.
60#AuditAnnotation: {
61 // key specifies the audit annotation key. The audit annotation keys of a
62 // ValidatingAdmissionPolicy must be unique. The key must be a qualified name
63 // ([A-Za-z0-9][-A-Za-z0-9_.]*) no more than 63 bytes in length.
64 //
65 // The key is combined with the resource name of the ValidatingAdmissionPolicy
66 // to construct an audit annotation key: "{ValidatingAdmissionPolicy
67 // name}/{key}".
68 //
69 // If an admission webhook uses the same resource name as this
70 // ValidatingAdmissionPolicy and the same audit annotation key, the annotation
71 // key will be identical. In this case, the first annotation written with the
72 // key will be included in the audit event and all subsequent annotations with
73 // the same key will be discarded.
74 //
75 // Required.
76 "key"!: string
77
78 // valueExpression represents the expression which is evaluated by CEL to
79 // produce an audit annotation value. The expression must evaluate to either a
80 // string or null value. If the expression evaluates to a string, the audit
81 // annotation is included with the string value. If the expression evaluates to
82 // null or empty string the audit annotation will be omitted. The
83 // valueExpression may be no longer than 5kb in length. If the result of the
84 // valueExpression is more than 10kb in length, it will be truncated to 10kb.
85 //
86 // If multiple ValidatingAdmissionPolicyBinding resources match an API request,
87 // then the valueExpression will be evaluated for each binding. All unique
88 // values produced by the valueExpressions will be joined together in a
89 // comma-separated list.
90 //
91 // Required.
92 "valueExpression"!: string
93}
94
95// ExpressionWarning is a warning information that targets a specific expression.
96#ExpressionWarning: {
97 // fieldRef is the path to the field that refers to the expression. For example,
98 // the reference to the expression of the first item of validations is
99 // "spec.validations[0].expression"
100 "fieldRef"!: string
101
102 // warning contains the content of type checking information in a human-readable
103 // form. Each line of the warning contains the type that the expression is
104 // checked against, followed by the type check error from the compiler.
105 "warning"!: string
106}
107
108// JSONPatch defines a JSON Patch.
109#JSONPatch: {
110 // expression will be evaluated by CEL to create a [JSON
111 // patch](https://jsonpatch.com/). ref: https://github.com/google/cel-spec
112 //
113 // expression must return an array of JSONPatch values.
114 //
115 // For example, this CEL expression returns a JSON patch to conditionally modify a value:
116 //
117 // [
118 // JSONPatch{op: "test", path: "/spec/example", value: "Red"},
119 // JSONPatch{op: "replace", path: "/spec/example", value: "Green"}
120 // ]
121 //
122 // To define an object for the patch value, use Object types. For example:
123 //
124 // [
125 // JSONPatch{
126 // op: "add",
127 // path: "/spec/selector",
128 // value: Object.spec.selector{matchLabels: {"environment": "test"}}
129 // }
130 // ]
131 //
132 // To use strings containing '/' and '~' as JSONPatch path keys, use
133 // "jsonpatch.escapeKey". For example:
134 //
135 // [
136 // JSONPatch{
137 // op: "add",
138 // path: "/metadata/labels/" + jsonpatch.escapeKey("example.com/environment"),
139 // value: "test"
140 // },
141 // ]
142 //
143 // CEL expressions have access to the types needed to create JSON patches and objects:
144 //
145 // - 'JSONPatch' - CEL type of JSON Patch operations. JSONPatch has the fields
146 // 'op', 'from', 'path' and 'value'.
147 // See [JSON patch](https://jsonpatch.com/) for more details. The 'value' field
148 // may be set to any of: string,
149 // integer, array, map or object. If set, the 'path' and 'from' fields must be set to a
150 // [JSON pointer](https://datatracker.ietf.org/doc/html/rfc6901/) string, where
151 // the 'jsonpatch.escapeKey()' CEL
152 // function may be used to escape path keys containing '/' and '~'.
153 // - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
154 // type of object field (such as 'Object.spec') -
155 // 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
156 // (such as 'Object.spec.containers')
157 //
158 // CEL expressions have access to the contents of the API request, organized
159 // into CEL variables as well as some other useful variables:
160 //
161 // - 'object' - The object from the incoming request. The value is null for
162 // DELETE requests. - 'oldObject' - The existing object. The value is null for
163 // CREATE requests. - 'request' - Attributes of the API
164 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
165 // Parameter resource referred to by the policy binding being evaluated. Only
166 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
167 // object that the incoming object belongs to. The value is null for
168 // cluster-scoped resources. - 'variables' - Map of composited variables, from
169 // its name to its lazily evaluated value.
170 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
171 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
172 // checks for the principal (user or service account) of the request.
173 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
174 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
175 // 'authorizer' and configured with the
176 // request resource.
177 //
178 // CEL expressions have access to [Kubernetes CEL function
179 // libraries](https://kubernetes.io/docs/reference/using-api/cel/#cel-options-language-features-and-libraries)
180 // as well as:
181 //
182 // - 'jsonpatch.escapeKey' - Performs JSONPatch key escaping. '~' and '/' are
183 // escaped as '~0' and `~1' respectively).
184 //
185 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
186 "expression"?: string
187}
188
189// MatchCondition represents a condition which must by fulfilled for a request
190// to be sent to a webhook.
191#MatchCondition: {
192 // expression represents the expression which will be evaluated by CEL. Must
193 // evaluate to bool. CEL expressions have access to the contents of the
194 // AdmissionRequest and Authorizer, organized into CEL variables:
195 //
196 // 'object' - The object from the incoming request. The value is null for DELETE
197 // requests. 'oldObject' - The existing object. The value is null for CREATE
198 // requests. 'request' - Attributes of the admission
199 // request(/pkg/apis/admission/types.go#AdmissionRequest). 'authorizer' - A CEL
200 // Authorizer. May be used to perform authorization checks for the principal
201 // (user or service account) of the request.
202 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
203 // 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
204 // 'authorizer' and configured with the
205 // request resource.
206 // Documentation on CEL: https://kubernetes.io/docs/reference/using-api/cel/
207 //
208 // Required.
209 "expression"!: string
210
211 // name is an identifier for this match condition, used for strategic merging of
212 // MatchConditions, as well as providing an identifier for logging purposes. A
213 // good name should be descriptive of the associated expression. Name must be a
214 // qualified name consisting of alphanumeric characters, '-', '_' or '.', and
215 // must start and end with an alphanumeric character (e.g. 'MyName', or
216 // 'my.name', or '123-abc', regex used for validation is
217 // '([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]') with an optional DNS subdomain
218 // prefix and '/' (e.g. 'example.com/MyName')
219 //
220 // Required.
221 "name"!: string
222}
223
224// MatchResources decides whether to run the admission control policy on an
225// object based on whether it meets the match criteria. The exclude rules take
226// precedence over include rules (if a resource matches both, it is excluded)
227#MatchResources: {
228 // excludeResourceRules describes what operations on what resources/subresources
229 // the ValidatingAdmissionPolicy should not care about. The exclude rules take
230 // precedence over include rules (if a resource matches both, it is excluded)
231 "excludeResourceRules"?: [...#NamedRuleWithOperations]
232
233 // matchPolicy defines how the "MatchResources" list is used to match incoming
234 // requests. Allowed values are "Exact" or "Equivalent".
235 //
236 // - Exact: match a request only if it exactly matches a specified rule. For
237 // example, if deployments can be modified via apps/v1, apps/v1beta1, and
238 // extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
239 // apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
240 // or extensions/v1beta1 would not be sent to the ValidatingAdmissionPolicy.
241 //
242 // - Equivalent: match a request if modifies a resource listed in rules, even
243 // via another API group or version. For example, if deployments can be
244 // modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
245 // included `apiGroups:["apps"], apiVersions:["v1"], resources:
246 // ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
247 // converted to apps/v1 and sent to the ValidatingAdmissionPolicy.
248 //
249 // Defaults to "Equivalent"
250 "matchPolicy"?: string
251
252 // namespaceSelector decides whether to run the admission control policy on an
253 // object based on whether the namespace for that object matches the selector.
254 // If the object itself is a namespace, the matching is performed on
255 // object.metadata.labels. If the object is another cluster scoped resource, it
256 // never skips the policy.
257 //
258 // For example, to run the webhook on any objects whose namespace is not
259 // associated with "runlevel" of "0" or "1"; you will set the selector as
260 // follows: "namespaceSelector": {
261 // "matchExpressions": [
262 // {
263 // "key": "runlevel",
264 // "operator": "NotIn",
265 // "values": [
266 // "0",
267 // "1"
268 // ]
269 // }
270 // ]
271 // }
272 //
273 // If instead you want to only run the policy on any objects whose namespace is
274 // associated with the "environment" of "prod" or "staging"; you will set the
275 // selector as follows: "namespaceSelector": {
276 // "matchExpressions": [
277 // {
278 // "key": "environment",
279 // "operator": "In",
280 // "values": [
281 // "prod",
282 // "staging"
283 // ]
284 // }
285 // ]
286 // }
287 //
288 // See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
289 // for more examples of label selectors.
290 //
291 // Default to the empty LabelSelector, which matches everything.
292 "namespaceSelector"?: v1.#LabelSelector
293
294 // objectSelector decides whether to run the validation based on if the object
295 // has matching labels. objectSelector is evaluated against both the oldObject
296 // and newObject that would be sent to the cel validation, and is considered to
297 // match if either object matches the selector. A null object (oldObject in the
298 // case of create, or newObject in the case of delete) or an object that cannot
299 // have labels (like a DeploymentRollback or a PodProxyOptions object) is not
300 // considered to match. Use the object selector only if the webhook is opt-in,
301 // because end users may skip the admission webhook by setting the labels.
302 // Default to the empty LabelSelector, which matches everything.
303 "objectSelector"?: v1.#LabelSelector
304
305 // resourceRules describes what operations on what resources/subresources the
306 // ValidatingAdmissionPolicy matches. The policy cares about an operation if it
307 // matches _any_ Rule.
308 "resourceRules"?: [...#NamedRuleWithOperations]
309}
310
311// MutatingAdmissionPolicy describes the definition of an admission mutation
312// policy that mutates the object coming into admission chain.
313#MutatingAdmissionPolicy: {
314 // APIVersion defines the versioned schema of this representation of an object.
315 // Servers should convert recognized schemas to the latest internal value, and
316 // may reject unrecognized values. More info:
317 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
318 "apiVersion": "admissionregistration.k8s.io/v1"
319
320 // Kind is a string value representing the REST resource this object represents.
321 // Servers may infer this from the endpoint the client submits requests to.
322 // Cannot be updated. In CamelCase. More info:
323 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
324 "kind": "MutatingAdmissionPolicy"
325
326 // metadata is the standard object metadata; More info:
327 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
328 "metadata"?: v1.#ObjectMeta
329
330 // spec defines the desired behavior of the MutatingAdmissionPolicy.
331 "spec"?: #MutatingAdmissionPolicySpec
332}
333
334// MutatingAdmissionPolicyBinding binds the MutatingAdmissionPolicy with
335// parametrized resources. MutatingAdmissionPolicyBinding and the optional
336// parameter resource together define how cluster administrators configure
337// policies for clusters.
338//
339// For a given admission request, each binding will cause its policy to be
340// evaluated N times, where N is 1 for policies/bindings that don't use params,
341// otherwise N is the number of parameters selected by the binding. Each
342// evaluation is constrained by a [runtime cost
343// budget](https://kubernetes.io/docs/reference/using-api/cel/#runtime-cost-budget).
344//
345// Adding/removing policies, bindings, or params can not affect whether a given
346// (policy, binding, param) combination is within its own CEL budget.
347#MutatingAdmissionPolicyBinding: {
348 // APIVersion defines the versioned schema of this representation of an object.
349 // Servers should convert recognized schemas to the latest internal value, and
350 // may reject unrecognized values. More info:
351 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
352 "apiVersion": "admissionregistration.k8s.io/v1"
353
354 // Kind is a string value representing the REST resource this object represents.
355 // Servers may infer this from the endpoint the client submits requests to.
356 // Cannot be updated. In CamelCase. More info:
357 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
358 "kind": "MutatingAdmissionPolicyBinding"
359
360 // metadata is the standard object metadata; More info:
361 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
362 "metadata"?: v1.#ObjectMeta
363
364 // spec defines the desired behavior of the MutatingAdmissionPolicyBinding.
365 "spec"?: #MutatingAdmissionPolicyBindingSpec
366}
367
368// MutatingAdmissionPolicyBindingList is a list of MutatingAdmissionPolicyBinding.
369#MutatingAdmissionPolicyBindingList: {
370 // APIVersion defines the versioned schema of this representation of an object.
371 // Servers should convert recognized schemas to the latest internal value, and
372 // may reject unrecognized values. More info:
373 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
374 "apiVersion": "admissionregistration.k8s.io/v1"
375
376 // List of PolicyBinding.
377 "items"!: [...#MutatingAdmissionPolicyBinding]
378
379 // Kind is a string value representing the REST resource this object represents.
380 // Servers may infer this from the endpoint the client submits requests to.
381 // Cannot be updated. In CamelCase. More info:
382 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
383 "kind": "MutatingAdmissionPolicyBindingList"
384
385 // metadata is the standard list metadata. More info:
386 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
387 "metadata"?: v1.#ListMeta
388}
389
390// MutatingAdmissionPolicyBindingSpec defines the specification of the
391// MutatingAdmissionPolicyBinding.
392#MutatingAdmissionPolicyBindingSpec: {
393 // matchResources limits what resources match this binding and may be mutated by
394 // it. Note that if matchResources matches a resource, the resource must also
395 // match a policy's matchConstraints and matchConditions before the resource
396 // may be mutated. When matchResources is unset, it does not constrain resource
397 // matching, and only the policy's matchConstraints and matchConditions must
398 // match for the resource to be mutated. Additionally,
399 // matchResources.resourceRules are optional and do not constraint matching
400 // when unset. Note that this is differs from MutatingAdmissionPolicy
401 // matchConstraints, where resourceRules are required. The CREATE, UPDATE and
402 // CONNECT operations are allowed. The DELETE operation may not be matched. '*'
403 // matches CREATE, UPDATE and CONNECT.
404 "matchResources"?: #MatchResources
405
406 // paramRef specifies the parameter resource used to configure the admission
407 // control policy. It should point to a resource of the type specified in
408 // spec.ParamKind of the bound MutatingAdmissionPolicy. If the policy specifies
409 // a ParamKind and the resource referred to by ParamRef does not exist, this
410 // binding is considered mis-configured and the FailurePolicy of the
411 // MutatingAdmissionPolicy applied. If the policy does not specify a ParamKind
412 // then this field is ignored, and the rules are evaluated without a param.
413 "paramRef"?: #ParamRef
414
415 // policyName references a MutatingAdmissionPolicy name which the
416 // MutatingAdmissionPolicyBinding binds to. If the referenced resource does not
417 // exist, this binding is considered invalid and will be ignored Required.
418 "policyName"?: string
419}
420
421// MutatingAdmissionPolicyList is a list of MutatingAdmissionPolicy.
422#MutatingAdmissionPolicyList: {
423 // APIVersion defines the versioned schema of this representation of an object.
424 // Servers should convert recognized schemas to the latest internal value, and
425 // may reject unrecognized values. More info:
426 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
427 "apiVersion": "admissionregistration.k8s.io/v1"
428
429 // List of ValidatingAdmissionPolicy.
430 "items"!: [...#MutatingAdmissionPolicy]
431
432 // Kind is a string value representing the REST resource this object represents.
433 // Servers may infer this from the endpoint the client submits requests to.
434 // Cannot be updated. In CamelCase. More info:
435 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
436 "kind": "MutatingAdmissionPolicyList"
437
438 // metadata is the standard list metadata. More info:
439 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
440 "metadata"?: v1.#ListMeta
441}
442
443// MutatingAdmissionPolicySpec defines the desired behavior of the admission policy.
444#MutatingAdmissionPolicySpec: {
445 // failurePolicy defines how to handle failures for the admission policy.
446 // Failures can occur from CEL expression parse errors, type check errors,
447 // runtime errors and invalid or mis-configured policy definitions or bindings.
448 //
449 // A policy is invalid if paramKind refers to a non-existent Kind. A binding is
450 // invalid if paramRef.name refers to a non-existent resource.
451 //
452 // failurePolicy does not define how validations that evaluate to false are handled.
453 //
454 // Allowed values are Ignore or Fail. Defaults to Fail.
455 "failurePolicy"?: string
456
457 // matchConditions is a list of conditions that must be met for a request to be
458 // validated. Match conditions filter requests that have already been matched
459 // by the matchConstraints. An empty list of matchConditions matches all
460 // requests. There are a maximum of 64 match conditions allowed.
461 //
462 // If a parameter object is provided, it can be accessed via the `params` handle
463 // in the same manner as validation expressions.
464 //
465 // The exact matching logic is (in order):
466 // 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
467 // 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
468 // 3. If any matchCondition evaluates to an error (but none are FALSE):
469 // - If failurePolicy=Fail, reject the request
470 // - If failurePolicy=Ignore, the policy is skipped
471 "matchConditions"?: [...#MatchCondition]
472
473 // matchConstraints specifies what resources this policy is designed to
474 // validate. The MutatingAdmissionPolicy cares about a request if it matches
475 // _all_ Constraints. However, in order to prevent clusters from being put into
476 // an unstable state that cannot be recovered from via the API
477 // MutatingAdmissionPolicy cannot match MutatingAdmissionPolicy and
478 // MutatingAdmissionPolicyBinding. The CREATE, UPDATE and CONNECT operations
479 // are allowed. The DELETE operation may not be matched. '*' matches CREATE,
480 // UPDATE and CONNECT. Required.
481 "matchConstraints"?: #MatchResources
482
483 // mutations contain operations to perform on matching objects. mutations may
484 // not be empty; a minimum of one mutation is required. mutations are evaluated
485 // in order, and are reinvoked according to the reinvocationPolicy. The
486 // mutations of a policy are invoked for each binding of this policy and
487 // reinvocation of mutations occurs on a per binding basis.
488 "mutations"?: [...#Mutation]
489
490 // paramKind specifies the kind of resources used to parameterize this policy.
491 // If absent, there are no parameters for this policy and the param CEL
492 // variable will not be provided to validation expressions. If paramKind refers
493 // to a non-existent kind, this policy definition is mis-configured and the
494 // FailurePolicy is applied. If paramKind is specified but paramRef is unset in
495 // MutatingAdmissionPolicyBinding, the params variable will be null.
496 "paramKind"?: #ParamKind
497
498 // reinvocationPolicy indicates whether mutations may be called multiple times
499 // per MutatingAdmissionPolicyBinding as part of a single admission evaluation.
500 // Allowed values are "Never" and "IfNeeded".
501 //
502 // Never: These mutations will not be called more than once per binding in a
503 // single admission evaluation.
504 //
505 // IfNeeded: These mutations may be invoked more than once per binding for a
506 // single admission request and there is no guarantee of order with respect to
507 // other admission plugins, admission webhooks, bindings of this policy and
508 // admission policies. Mutations are only reinvoked when mutations change the
509 // object after this mutation is invoked. Required.
510 "reinvocationPolicy"?: string
511
512 // variables contain definitions of variables that can be used in composition of
513 // other expressions. Each variable is defined as a named CEL expression. The
514 // variables defined here will be available under `variables` in other
515 // expressions of the policy except matchConditions because matchConditions are
516 // evaluated before the rest of the policy.
517 //
518 // The expression of a variable can refer to other variables defined earlier in
519 // the list but not those after. Thus, variables must be sorted by the order of
520 // first appearance and acyclic.
521 "variables"?: [...#Variable]
522}
523
524// MutatingWebhook describes an admission webhook and the resources and operations it applies to.
525#MutatingWebhook: {
526 // admissionReviewVersions is an ordered list of preferred `AdmissionReview`
527 // versions the Webhook expects. API server will try to use first version in
528 // the list which it supports. If none of the versions specified in this list
529 // supported by API server, validation will fail for this object. If a
530 // persisted webhook configuration specifies allowed versions and does not
531 // include any versions known to the API Server, calls to the webhook will fail
532 // and be subject to the failure policy.
533 "admissionReviewVersions"!: [...string]
534
535 // clientConfig defines how to communicate with the hook. Required
536 "clientConfig"!: #WebhookClientConfig
537
538 // failurePolicy defines how unrecognized errors from the admission endpoint are
539 // handled - allowed values are Ignore or Fail. Defaults to Fail.
540 "failurePolicy"?: string
541
542 // matchConditions is a list of conditions that must be met for a request to be
543 // sent to this webhook. Match conditions filter requests that have already
544 // been matched by the rules, namespaceSelector, and objectSelector. An empty
545 // list of matchConditions matches all requests. There are a maximum of 64
546 // match conditions allowed.
547 //
548 // The exact matching logic is (in order):
549 // 1. If ANY matchCondition evaluates to FALSE, the webhook is skipped.
550 // 2. If ALL matchConditions evaluate to TRUE, the webhook is called.
551 // 3. If any matchCondition evaluates to an error (but none are FALSE):
552 // - If failurePolicy=Fail, reject the request
553 // - If failurePolicy=Ignore, the error is ignored and the webhook is skipped
554 "matchConditions"?: [...#MatchCondition]
555
556 // matchPolicy defines how the "rules" list is used to match incoming requests.
557 // Allowed values are "Exact" or "Equivalent".
558 //
559 // - Exact: match a request only if it exactly matches a specified rule. For
560 // example, if deployments can be modified via apps/v1, apps/v1beta1, and
561 // extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
562 // apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
563 // or extensions/v1beta1 would not be sent to the webhook.
564 //
565 // - Equivalent: match a request if modifies a resource listed in rules, even
566 // via another API group or version. For example, if deployments can be
567 // modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
568 // included `apiGroups:["apps"], apiVersions:["v1"], resources:
569 // ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
570 // converted to apps/v1 and sent to the webhook.
571 //
572 // Defaults to "Equivalent"
573 "matchPolicy"?: string
574
575 // name is the name of the admission webhook. Name should be fully qualified,
576 // e.g., imagepolicy.kubernetes.io, where "imagepolicy" is the name of the
577 // webhook, and kubernetes.io is the name of the organization. Required.
578 "name"!: string
579
580 // namespaceSelector decides whether to run the webhook on an object based on
581 // whether the namespace for that object matches the selector. If the object
582 // itself is a namespace, the matching is performed on object.metadata.labels.
583 // If the object is another cluster scoped resource, it never skips the
584 // webhook.
585 //
586 // For example, to run the webhook on any objects whose namespace is not
587 // associated with "runlevel" of "0" or "1"; you will set the selector as
588 // follows: "namespaceSelector": {
589 // "matchExpressions": [
590 // {
591 // "key": "runlevel",
592 // "operator": "NotIn",
593 // "values": [
594 // "0",
595 // "1"
596 // ]
597 // }
598 // ]
599 // }
600 //
601 // If instead you want to only run the webhook on any objects whose namespace is
602 // associated with the "environment" of "prod" or "staging"; you will set the
603 // selector as follows: "namespaceSelector": {
604 // "matchExpressions": [
605 // {
606 // "key": "environment",
607 // "operator": "In",
608 // "values": [
609 // "prod",
610 // "staging"
611 // ]
612 // }
613 // ]
614 // }
615 //
616 // See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
617 // for more examples of label selectors.
618 //
619 // Default to the empty LabelSelector, which matches everything.
620 "namespaceSelector"?: v1.#LabelSelector
621
622 // objectSelector decides whether to run the webhook based on if the object has
623 // matching labels. objectSelector is evaluated against both the oldObject and
624 // newObject that would be sent to the webhook, and is considered to match if
625 // either object matches the selector. A null object (oldObject in the case of
626 // create, or newObject in the case of delete) or an object that cannot have
627 // labels (like a DeploymentRollback or a PodProxyOptions object) is not
628 // considered to match. Use the object selector only if the webhook is opt-in,
629 // because end users may skip the admission webhook by setting the labels.
630 // Default to the empty LabelSelector, which matches everything.
631 "objectSelector"?: v1.#LabelSelector
632
633 // reinvocationPolicy indicates whether this webhook should be called multiple
634 // times as part of a single admission evaluation. Allowed values are "Never"
635 // and "IfNeeded".
636 //
637 // Never: the webhook will not be called more than once in a single admission evaluation.
638 //
639 // IfNeeded: the webhook will be called at least one additional time as part of
640 // the admission evaluation if the object being admitted is modified by other
641 // admission plugins after the initial webhook call. Webhooks that specify this
642 // option *must* be idempotent, able to process objects they previously
643 // admitted. Note: * the number of additional invocations is not guaranteed to
644 // be exactly one. * if additional invocations result in further modifications
645 // to the object, webhooks are not guaranteed to be invoked again. * webhooks
646 // that use this option may be reordered to minimize the number of additional
647 // invocations. * to validate an object after all mutations are guaranteed
648 // complete, use a validating admission webhook instead.
649 //
650 // Defaults to "Never".
651 "reinvocationPolicy"?: string
652
653 // rules describes what operations on what resources/subresources the webhook
654 // cares about. The webhook cares about an operation if it matches _any_ Rule.
655 // However, in order to prevent ValidatingAdmissionWebhooks and
656 // MutatingAdmissionWebhooks from putting the cluster in a state which cannot
657 // be recovered from without completely disabling the plugin,
658 // ValidatingAdmissionWebhooks and MutatingAdmissionWebhooks are never called
659 // on admission requests for ValidatingWebhookConfiguration and
660 // MutatingWebhookConfiguration objects.
661 "rules"?: [...#RuleWithOperations]
662
663 // sideEffects states whether this webhook has side effects. Acceptable values
664 // are: None, NoneOnDryRun (webhooks created via v1beta1 may also specify Some
665 // or Unknown). Webhooks with side effects MUST implement a reconciliation
666 // system, since a request may be rejected by a future step in the admission
667 // chain and the side effects therefore need to be undone. Requests with the
668 // dryRun attribute will be auto-rejected if they match a webhook with
669 // sideEffects == Unknown or Some.
670 "sideEffects"!: string
671
672 // timeoutSeconds specifies the timeout for this webhook. After the timeout
673 // passes, the webhook call will be ignored or the API call will fail based on
674 // the failure policy. The timeout value must be between 1 and 30 seconds.
675 // Default to 10 seconds.
676 "timeoutSeconds"?: int32 & int
677}
678
679// MutatingWebhookConfiguration describes the configuration of and admission
680// webhook that accept or reject and may change the object.
681#MutatingWebhookConfiguration: {
682 // APIVersion defines the versioned schema of this representation of an object.
683 // Servers should convert recognized schemas to the latest internal value, and
684 // may reject unrecognized values. More info:
685 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
686 "apiVersion": "admissionregistration.k8s.io/v1"
687
688 // Kind is a string value representing the REST resource this object represents.
689 // Servers may infer this from the endpoint the client submits requests to.
690 // Cannot be updated. In CamelCase. More info:
691 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
692 "kind": "MutatingWebhookConfiguration"
693
694 // metadata is the standard object metadata; More info:
695 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
696 "metadata"?: v1.#ObjectMeta
697
698 // webhooks is a list of webhooks and the affected resources and operations.
699 "webhooks"?: [...#MutatingWebhook]
700}
701
702// MutatingWebhookConfigurationList is a list of MutatingWebhookConfiguration.
703#MutatingWebhookConfigurationList: {
704 // APIVersion defines the versioned schema of this representation of an object.
705 // Servers should convert recognized schemas to the latest internal value, and
706 // may reject unrecognized values. More info:
707 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
708 "apiVersion": "admissionregistration.k8s.io/v1"
709
710 // List of MutatingWebhookConfiguration.
711 "items"!: [...#MutatingWebhookConfiguration]
712
713 // Kind is a string value representing the REST resource this object represents.
714 // Servers may infer this from the endpoint the client submits requests to.
715 // Cannot be updated. In CamelCase. More info:
716 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
717 "kind": "MutatingWebhookConfigurationList"
718
719 // metadata is the standard list metadata. More info:
720 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
721 "metadata"?: v1.#ListMeta
722}
723
724// Mutation specifies the CEL expression which is used to apply the Mutation.
725#Mutation: {
726 // applyConfiguration defines the desired configuration values of an object. The
727 // configuration is applied to the admission object using [structured merge
728 // diff](https://github.com/kubernetes-sigs/structured-merge-diff). A CEL
729 // expression is used to create apply configuration.
730 "applyConfiguration"?: #ApplyConfiguration
731
732 // jsonPatch defines a [JSON patch](https://jsonpatch.com/) operation to perform
733 // a mutation to the object. A CEL expression is used to create the JSON patch.
734 "jsonPatch"?: #JSONPatch
735
736 // patchType indicates the patch strategy used. Allowed values are
737 // "ApplyConfiguration" and "JSONPatch". Required.
738 "patchType"!: string
739}
740
741// NamedRuleWithOperations is a tuple of Operations and Resources with ResourceNames.
742#NamedRuleWithOperations: {
743 // apiGroups is the API groups the resources belong to. '*' is all groups. If
744 // '*' is present, the length of the slice must be one. Required.
745 "apiGroups"?: [...string]
746
747 // apiVersions is the API versions the resources belong to. '*' is all versions.
748 // If '*' is present, the length of the slice must be one. Required.
749 "apiVersions"?: [...string]
750
751 // operations is the operations the admission hook cares about - CREATE, UPDATE,
752 // DELETE, CONNECT or * for all of those operations and any future admission
753 // operations that are added. If '*' is present, the length of the slice must
754 // be one. Required.
755 "operations"?: [...string]
756
757 // resourceNames is an optional white list of names that the rule applies to. An
758 // empty set means that everything is allowed.
759 "resourceNames"?: [...string]
760
761 // resources is a list of resources this rule applies to.
762 //
763 // For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
764 // '*' means all resources, but not subresources. 'pods/*' means all
765 // subresources of pods. '*/scale' means all scale subresources. '*/*' means
766 // all resources and their subresources.
767 //
768 // If wildcard is present, the validation rule will ensure resources do not overlap with each other.
769 //
770 // Depending on the enclosing object, subresources might not be allowed. Required.
771 "resources"?: [...string]
772
773 // scope specifies the scope of this rule. Valid values are "Cluster",
774 // "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
775 // will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
776 // means that only namespaced resources will match this rule. "*" means that
777 // there are no scope restrictions. Subresources match the scope of their
778 // parent resource. Default is "*".
779 "scope"?: string
780}
781
782// ParamKind is a tuple of Group Kind and Version.
783#ParamKind: {
784 // apiVersion is the API group version the resources belong to. In format of
785 // "group/version". Required.
786 "apiVersion"?: string
787
788 // kind is the API kind the resources belong to. Required.
789 "kind"?: string
790}
791
792// ParamRef describes how to locate the params to be used as input to
793// expressions of rules applied by a policy binding.
794#ParamRef: {
795 // name is the name of the resource being referenced.
796 //
797 // One of `name` or `selector` must be set, but `name` and `selector` are
798 // mutually exclusive properties. If one is set, the other must be unset.
799 //
800 // A single parameter used for all admission requests can be configured by
801 // setting the `name` field, leaving `selector` blank, and setting namespace if
802 // `paramKind` is namespace-scoped.
803 "name"?: string
804
805 // namespace is the namespace of the referenced resource. Allows limiting the
806 // search for params to a specific namespace. Applies to both `name` and
807 // `selector` fields.
808 //
809 // A per-namespace parameter may be used by specifying a namespace-scoped
810 // `paramKind` in the policy and leaving this field empty.
811 //
812 // - If `paramKind` is cluster-scoped, this field MUST be unset. Setting this
813 // field results in a configuration error.
814 //
815 // - If `paramKind` is namespace-scoped, the namespace of the object being
816 // evaluated for admission will be used when this field is left unset. Take
817 // care that if this is left empty the binding must not match any
818 // cluster-scoped resources, which will result in an error.
819 "namespace"?: string
820
821 // parameterNotFoundAction controls the behavior of the binding when the
822 // resource exists, and name or selector is valid, but there are no parameters
823 // matched by the binding. If the value is set to `Allow`, then no matched
824 // parameters will be treated as successful validation by the binding. If set
825 // to `Deny`, then no matched parameters will be subject to the `failurePolicy`
826 // of the policy.
827 //
828 // Allowed values are `Allow` or `Deny`
829 //
830 // Required
831 "parameterNotFoundAction"?: string
832
833 // selector can be used to match multiple param objects based on their labels.
834 // Supply selector: {} to match all resources of the ParamKind.
835 //
836 // If multiple params are found, they are all evaluated with the policy
837 // expressions and the results are ANDed together.
838 //
839 // One of `name` or `selector` must be set, but `name` and `selector` are
840 // mutually exclusive properties. If one is set, the other must be unset.
841 "selector"?: v1.#LabelSelector
842}
843
844// RuleWithOperations is a tuple of Operations and Resources. It is recommended
845// to make sure that all the tuple expansions are valid.
846#RuleWithOperations: {
847 // apiGroups is the API groups the resources belong to. '*' is all groups. If
848 // '*' is present, the length of the slice must be one. Required.
849 "apiGroups"?: [...string]
850
851 // apiVersions is the API versions the resources belong to. '*' is all versions.
852 // If '*' is present, the length of the slice must be one. Required.
853 "apiVersions"?: [...string]
854
855 // operations is the operations the admission hook cares about - CREATE, UPDATE,
856 // DELETE, CONNECT or * for all of those operations and any future admission
857 // operations that are added. If '*' is present, the length of the slice must
858 // be one. Required.
859 "operations"?: [...string]
860
861 // resources is a list of resources this rule applies to.
862 //
863 // For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
864 // '*' means all resources, but not subresources. 'pods/*' means all
865 // subresources of pods. '*/scale' means all scale subresources. '*/*' means
866 // all resources and their subresources.
867 //
868 // If wildcard is present, the validation rule will ensure resources do not overlap with each other.
869 //
870 // Depending on the enclosing object, subresources might not be allowed. Required.
871 "resources"?: [...string]
872
873 // scope specifies the scope of this rule. Valid values are "Cluster",
874 // "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
875 // will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
876 // means that only namespaced resources will match this rule. "*" means that
877 // there are no scope restrictions. Subresources match the scope of their
878 // parent resource. Default is "*".
879 "scope"?: string
880}
881
882// ServiceReference holds a reference to Service.legacy.k8s.io
883#ServiceReference: {
884 // name is the name of the service. Required
885 "name"!: string
886
887 // namespace is the namespace of the service. Required
888 "namespace"!: string
889
890 // path is an optional URL path which will be sent in any request to this service.
891 "path"?: string
892
893 // port is the port on the service that hosts the webhook. Default to 443 for
894 // backward compatibility. `port` should be a valid port number (1-65535,
895 // inclusive).
896 "port"?: int32 & int
897}
898
899// TypeChecking contains results of type checking the expressions in the ValidatingAdmissionPolicy
900#TypeChecking: {
901 // expressionWarnings contains the type checking warnings for each expression.
902 "expressionWarnings"?: [...#ExpressionWarning]
903}
904
905// ValidatingAdmissionPolicy describes the definition of an admission validation
906// policy that accepts or rejects an object without changing it.
907#ValidatingAdmissionPolicy: {
908 // APIVersion defines the versioned schema of this representation of an object.
909 // Servers should convert recognized schemas to the latest internal value, and
910 // may reject unrecognized values. More info:
911 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
912 "apiVersion": "admissionregistration.k8s.io/v1"
913
914 // Kind is a string value representing the REST resource this object represents.
915 // Servers may infer this from the endpoint the client submits requests to.
916 // Cannot be updated. In CamelCase. More info:
917 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
918 "kind": "ValidatingAdmissionPolicy"
919
920 // metadata is the standard object metadata; More info:
921 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
922 "metadata"?: v1.#ObjectMeta
923
924 // spec defines the desired behavior of the ValidatingAdmissionPolicy.
925 "spec"?: #ValidatingAdmissionPolicySpec
926
927 // status represents the current status of the ValidatingAdmissionPolicy,
928 // including warnings that are useful to determine if the policy behaves in the
929 // expected way. Populated by the system. Read-only.
930 "status"?: #ValidatingAdmissionPolicyStatus
931}
932
933// ValidatingAdmissionPolicyBinding binds the ValidatingAdmissionPolicy with
934// paramerized resources. ValidatingAdmissionPolicyBinding and parameter CRDs
935// together define how cluster administrators configure policies for clusters.
936//
937// For a given admission request, each binding will cause its policy to be
938// evaluated N times, where N is 1 for policies/bindings that don't use params,
939// otherwise N is the number of parameters selected by the binding.
940//
941// The CEL expressions of a policy must have a computed CEL cost below the
942// maximum CEL budget. Each evaluation of the policy is given an independent
943// CEL cost budget. Adding/removing policies, bindings, or params can not
944// affect whether a given (policy, binding, param) combination is within its
945// own CEL budget.
946#ValidatingAdmissionPolicyBinding: {
947 // APIVersion defines the versioned schema of this representation of an object.
948 // Servers should convert recognized schemas to the latest internal value, and
949 // may reject unrecognized values. More info:
950 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
951 "apiVersion": "admissionregistration.k8s.io/v1"
952
953 // Kind is a string value representing the REST resource this object represents.
954 // Servers may infer this from the endpoint the client submits requests to.
955 // Cannot be updated. In CamelCase. More info:
956 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
957 "kind": "ValidatingAdmissionPolicyBinding"
958
959 // metadata is the standard object metadata; More info:
960 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
961 "metadata"?: v1.#ObjectMeta
962
963 // spec defines the desired behavior of the ValidatingAdmissionPolicyBinding.
964 "spec"!: #ValidatingAdmissionPolicyBindingSpec
965}
966
967// ValidatingAdmissionPolicyBindingList is a list of ValidatingAdmissionPolicyBinding.
968#ValidatingAdmissionPolicyBindingList: {
969 // APIVersion defines the versioned schema of this representation of an object.
970 // Servers should convert recognized schemas to the latest internal value, and
971 // may reject unrecognized values. More info:
972 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
973 "apiVersion": "admissionregistration.k8s.io/v1"
974
975 // List of PolicyBinding.
976 "items"!: [...#ValidatingAdmissionPolicyBinding]
977
978 // Kind is a string value representing the REST resource this object represents.
979 // Servers may infer this from the endpoint the client submits requests to.
980 // Cannot be updated. In CamelCase. More info:
981 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
982 "kind": "ValidatingAdmissionPolicyBindingList"
983
984 // metadata is the standard list metadata. More info:
985 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
986 "metadata"?: v1.#ListMeta
987}
988
989// ValidatingAdmissionPolicyBindingSpec is the specification of the
990// ValidatingAdmissionPolicyBinding.
991#ValidatingAdmissionPolicyBindingSpec: {
992 // matchResources declares what resources match this binding and will be
993 // validated by it. Note that this is intersected with the policy's
994 // matchConstraints, so only requests that are matched by the policy can be
995 // selected by this. If this is unset, all resources matched by the policy are
996 // validated by this binding When resourceRules is unset, it does not constrain
997 // resource matching. If a resource is matched by the other fields of this
998 // object, it will be validated. Note that this is differs from
999 // ValidatingAdmissionPolicy matchConstraints, where resourceRules are
1000 // required.
1001 "matchResources"?: #MatchResources
1002
1003 // paramRef specifies the parameter resource used to configure the admission
1004 // control policy. It should point to a resource of the type specified in
1005 // ParamKind of the bound ValidatingAdmissionPolicy. If the policy specifies a
1006 // ParamKind and the resource referred to by ParamRef does not exist, this
1007 // binding is considered mis-configured and the FailurePolicy of the
1008 // ValidatingAdmissionPolicy applied. If the policy does not specify a
1009 // ParamKind then this field is ignored, and the rules are evaluated without a
1010 // param.
1011 "paramRef"?: #ParamRef
1012
1013 // policyName references a ValidatingAdmissionPolicy name which the
1014 // ValidatingAdmissionPolicyBinding binds to. If the referenced resource does
1015 // not exist, this binding is considered invalid and will be ignored Required.
1016 "policyName"!: string
1017
1018 // validationActions declares how Validations of the referenced
1019 // ValidatingAdmissionPolicy are enforced. If a validation evaluates to false
1020 // it is always enforced according to these actions.
1021 //
1022 // Failures defined by the ValidatingAdmissionPolicy's FailurePolicy are
1023 // enforced according to these actions only if the FailurePolicy is set to
1024 // Fail, otherwise the failures are ignored. This includes compilation errors,
1025 // runtime errors and misconfigurations of the policy.
1026 //
1027 // validationActions is declared as a set of action values. Order does not
1028 // matter. validationActions may not contain duplicates of the same action.
1029 //
1030 // The supported actions values are:
1031 //
1032 // "Deny" specifies that a validation failure results in a denied request.
1033 //
1034 // "Warn" specifies that a validation failure is reported to the request client
1035 // in HTTP Warning headers, with a warning code of 299. Warnings can be sent
1036 // both for allowed or denied admission responses.
1037 //
1038 // "Audit" specifies that a validation failure is included in the published
1039 // audit event for the request. The audit event will contain a
1040 // `validation.policy.admission.k8s.io/validation_failure` audit annotation
1041 // with a value containing the details of the validation failures, formatted as
1042 // a JSON list of objects, each with the following fields: - message: The
1043 // validation failure message string - policy: The resource name of the
1044 // ValidatingAdmissionPolicy - binding: The resource name of the
1045 // ValidatingAdmissionPolicyBinding - expressionIndex: The index of the failed
1046 // validations in the ValidatingAdmissionPolicy - validationActions: The
1047 // enforcement actions enacted for the validation failure Example audit
1048 // annotation: `"validation.policy.admission.k8s.io/validation_failure":
1049 // "[{\"message\": \"Invalid value\", {\"policy\": \"policy.example.com\",
1050 // {\"binding\": \"policybinding.example.com\", {\"expressionIndex\": \"1\",
1051 // {\"validationActions\": [\"Audit\"]}]"`
1052 //
1053 // Clients should expect to handle additional values by ignoring any values not recognized.
1054 //
1055 // "Deny" and "Warn" may not be used together since this combination needlessly
1056 // duplicates the validation failure both in the API response body and the HTTP
1057 // warning headers.
1058 //
1059 // Required.
1060 "validationActions"!: [...string]
1061}
1062
1063// ValidatingAdmissionPolicyList is a list of ValidatingAdmissionPolicy.
1064#ValidatingAdmissionPolicyList: {
1065 // APIVersion defines the versioned schema of this representation of an object.
1066 // Servers should convert recognized schemas to the latest internal value, and
1067 // may reject unrecognized values. More info:
1068 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1069 "apiVersion": "admissionregistration.k8s.io/v1"
1070
1071 // List of ValidatingAdmissionPolicy.
1072 "items"!: [...#ValidatingAdmissionPolicy]
1073
1074 // Kind is a string value representing the REST resource this object represents.
1075 // Servers may infer this from the endpoint the client submits requests to.
1076 // Cannot be updated. In CamelCase. More info:
1077 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1078 "kind": "ValidatingAdmissionPolicyList"
1079
1080 // metadata is the standard list metadata. More info:
1081 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1082 "metadata"?: v1.#ListMeta
1083}
1084
1085// ValidatingAdmissionPolicySpec is the specification of the desired behavior of
1086// the AdmissionPolicy.
1087#ValidatingAdmissionPolicySpec: {
1088 // auditAnnotations contains CEL expressions which are used to produce audit
1089 // annotations for the audit event of the API request. validations and
1090 // auditAnnotations may not both be empty; a least one of validations or
1091 // auditAnnotations is required.
1092 "auditAnnotations"?: [...#AuditAnnotation]
1093
1094 // failurePolicy defines how to handle failures for the admission policy.
1095 // Failures can occur from CEL expression parse errors, type check errors,
1096 // runtime errors and invalid or mis-configured policy definitions or bindings.
1097 //
1098 // A policy is invalid if spec.paramKind refers to a non-existent Kind. A
1099 // binding is invalid if spec.paramRef.name refers to a non-existent resource.
1100 //
1101 // failurePolicy does not define how validations that evaluate to false are handled.
1102 //
1103 // When failurePolicy is set to Fail, ValidatingAdmissionPolicyBinding
1104 // validationActions define how failures are enforced.
1105 //
1106 // Allowed values are Ignore or Fail. Defaults to Fail.
1107 "failurePolicy"?: string
1108
1109 // matchConditions is a list of conditions that must be met for a request to be
1110 // validated. Match conditions filter requests that have already been matched
1111 // by the rules, namespaceSelector, and objectSelector. An empty list of
1112 // matchConditions matches all requests. There are a maximum of 64 match
1113 // conditions allowed.
1114 //
1115 // If a parameter object is provided, it can be accessed via the `params` handle
1116 // in the same manner as validation expressions.
1117 //
1118 // The exact matching logic is (in order):
1119 // 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
1120 // 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
1121 // 3. If any matchCondition evaluates to an error (but none are FALSE):
1122 // - If failurePolicy=Fail, reject the request
1123 // - If failurePolicy=Ignore, the policy is skipped
1124 "matchConditions"?: [...#MatchCondition]
1125
1126 // matchConstraints specifies what resources this policy is designed to
1127 // validate. The AdmissionPolicy cares about a request if it matches _all_
1128 // Constraints. However, in order to prevent clusters from being put into an
1129 // unstable state that cannot be recovered from via the API
1130 // ValidatingAdmissionPolicy cannot match ValidatingAdmissionPolicy and
1131 // ValidatingAdmissionPolicyBinding. Required.
1132 "matchConstraints"?: #MatchResources
1133
1134 // paramKind specifies the kind of resources used to parameterize this policy.
1135 // If absent, there are no parameters for this policy and the param CEL
1136 // variable will not be provided to validation expressions. If ParamKind refers
1137 // to a non-existent kind, this policy definition is mis-configured and the
1138 // FailurePolicy is applied. If paramKind is specified but paramRef is unset in
1139 // ValidatingAdmissionPolicyBinding, the params variable will be null.
1140 "paramKind"?: #ParamKind
1141
1142 // validations contain CEL expressions which is used to apply the validation.
1143 // Validations and AuditAnnotations may not both be empty; a minimum of one
1144 // Validations or AuditAnnotations is required.
1145 "validations"?: [...#Validation]
1146
1147 // variables contain definitions of variables that can be used in composition of
1148 // other expressions. Each variable is defined as a named CEL expression. The
1149 // variables defined here will be available under `variables` in other
1150 // expressions of the policy except MatchConditions because MatchConditions are
1151 // evaluated before the rest of the policy.
1152 //
1153 // The expression of a variable can refer to other variables defined earlier in
1154 // the list but not those after. Thus, Variables must be sorted by the order of
1155 // first appearance and acyclic.
1156 "variables"?: [...#Variable]
1157}
1158
1159// ValidatingAdmissionPolicyStatus represents the status of an admission validation policy.
1160#ValidatingAdmissionPolicyStatus: {
1161 // conditions represent the latest available observations of a policy's current state.
1162 "conditions"?: [...v1.#Condition]
1163
1164 // observedGeneration is the generation observed by the controller.
1165 "observedGeneration"?: int64 & int
1166
1167 // typeChecking contains the results of type checking for each expression.
1168 // Presence of this field indicates the completion of the type checking.
1169 "typeChecking"?: #TypeChecking
1170}
1171
1172// ValidatingWebhook describes an admission webhook and the resources and operations it applies to.
1173#ValidatingWebhook: {
1174 // admissionReviewVersions is an ordered list of preferred `AdmissionReview`
1175 // versions the Webhook expects. API server will try to use first version in
1176 // the list which it supports. If none of the versions specified in this list
1177 // supported by API server, validation will fail for this object. If a
1178 // persisted webhook configuration specifies allowed versions and does not
1179 // include any versions known to the API Server, calls to the webhook will fail
1180 // and be subject to the failure policy.
1181 "admissionReviewVersions"!: [...string]
1182
1183 // clientConfig defines how to communicate with the hook. Required
1184 "clientConfig"!: #WebhookClientConfig
1185
1186 // failurePolicy defines how unrecognized errors from the admission endpoint are
1187 // handled - allowed values are Ignore or Fail. Defaults to Fail.
1188 "failurePolicy"?: string
1189
1190 // matchConditions is a list of conditions that must be met for a request to be
1191 // sent to this webhook. Match conditions filter requests that have already
1192 // been matched by the rules, namespaceSelector, and objectSelector. An empty
1193 // list of matchConditions matches all requests. There are a maximum of 64
1194 // match conditions allowed.
1195 //
1196 // The exact matching logic is (in order):
1197 // 1. If ANY matchCondition evaluates to FALSE, the webhook is skipped.
1198 // 2. If ALL matchConditions evaluate to TRUE, the webhook is called.
1199 // 3. If any matchCondition evaluates to an error (but none are FALSE):
1200 // - If failurePolicy=Fail, reject the request
1201 // - If failurePolicy=Ignore, the error is ignored and the webhook is skipped
1202 "matchConditions"?: [...#MatchCondition]
1203
1204 // matchPolicy defines how the "rules" list is used to match incoming requests.
1205 // Allowed values are "Exact" or "Equivalent".
1206 //
1207 // - Exact: match a request only if it exactly matches a specified rule. For
1208 // example, if deployments can be modified via apps/v1, apps/v1beta1, and
1209 // extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
1210 // apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
1211 // or extensions/v1beta1 would not be sent to the webhook.
1212 //
1213 // - Equivalent: match a request if modifies a resource listed in rules, even
1214 // via another API group or version. For example, if deployments can be
1215 // modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
1216 // included `apiGroups:["apps"], apiVersions:["v1"], resources:
1217 // ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
1218 // converted to apps/v1 and sent to the webhook.
1219 //
1220 // Defaults to "Equivalent"
1221 "matchPolicy"?: string
1222
1223 // name is the name of the admission webhook. Name should be fully qualified,
1224 // e.g., imagepolicy.kubernetes.io, where "imagepolicy" is the name of the
1225 // webhook, and kubernetes.io is the name of the organization. Required.
1226 "name"!: string
1227
1228 // namespaceSelector decides whether to run the webhook on an object based on
1229 // whether the namespace for that object matches the selector. If the object
1230 // itself is a namespace, the matching is performed on object.metadata.labels.
1231 // If the object is another cluster scoped resource, it never skips the
1232 // webhook.
1233 //
1234 // For example, to run the webhook on any objects whose namespace is not
1235 // associated with "runlevel" of "0" or "1"; you will set the selector as
1236 // follows: "namespaceSelector": {
1237 // "matchExpressions": [
1238 // {
1239 // "key": "runlevel",
1240 // "operator": "NotIn",
1241 // "values": [
1242 // "0",
1243 // "1"
1244 // ]
1245 // }
1246 // ]
1247 // }
1248 //
1249 // If instead you want to only run the webhook on any objects whose namespace is
1250 // associated with the "environment" of "prod" or "staging"; you will set the
1251 // selector as follows: "namespaceSelector": {
1252 // "matchExpressions": [
1253 // {
1254 // "key": "environment",
1255 // "operator": "In",
1256 // "values": [
1257 // "prod",
1258 // "staging"
1259 // ]
1260 // }
1261 // ]
1262 // }
1263 //
1264 // See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels
1265 // for more examples of label selectors.
1266 //
1267 // Default to the empty LabelSelector, which matches everything.
1268 "namespaceSelector"?: v1.#LabelSelector
1269
1270 // objectSelector decides whether to run the webhook based on if the object has
1271 // matching labels. objectSelector is evaluated against both the oldObject and
1272 // newObject that would be sent to the webhook, and is considered to match if
1273 // either object matches the selector. A null object (oldObject in the case of
1274 // create, or newObject in the case of delete) or an object that cannot have
1275 // labels (like a DeploymentRollback or a PodProxyOptions object) is not
1276 // considered to match. Use the object selector only if the webhook is opt-in,
1277 // because end users may skip the admission webhook by setting the labels.
1278 // Default to the empty LabelSelector, which matches everything.
1279 "objectSelector"?: v1.#LabelSelector
1280
1281 // rules describes what operations on what resources/subresources the webhook
1282 // cares about. The webhook cares about an operation if it matches _any_ Rule.
1283 // However, in order to prevent ValidatingAdmissionWebhooks and
1284 // MutatingAdmissionWebhooks from putting the cluster in a state which cannot
1285 // be recovered from without completely disabling the plugin,
1286 // ValidatingAdmissionWebhooks and MutatingAdmissionWebhooks are never called
1287 // on admission requests for ValidatingWebhookConfiguration and
1288 // MutatingWebhookConfiguration objects.
1289 "rules"?: [...#RuleWithOperations]
1290
1291 // sideEffects states whether this webhook has side effects. Acceptable values
1292 // are: None, NoneOnDryRun (webhooks created via v1beta1 may also specify Some
1293 // or Unknown). Webhooks with side effects MUST implement a reconciliation
1294 // system, since a request may be rejected by a future step in the admission
1295 // chain and the side effects therefore need to be undone. Requests with the
1296 // dryRun attribute will be auto-rejected if they match a webhook with
1297 // sideEffects == Unknown or Some.
1298 "sideEffects"!: string
1299
1300 // timeoutSeconds specifies the timeout for this webhook. After the timeout
1301 // passes, the webhook call will be ignored or the API call will fail based on
1302 // the failure policy. The timeout value must be between 1 and 30 seconds.
1303 // Default to 10 seconds.
1304 "timeoutSeconds"?: int32 & int
1305}
1306
1307// ValidatingWebhookConfiguration describes the configuration of and admission
1308// webhook that accept or reject and object without changing it.
1309#ValidatingWebhookConfiguration: {
1310 // APIVersion defines the versioned schema of this representation of an object.
1311 // Servers should convert recognized schemas to the latest internal value, and
1312 // may reject unrecognized values. More info:
1313 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1314 "apiVersion": "admissionregistration.k8s.io/v1"
1315
1316 // Kind is a string value representing the REST resource this object represents.
1317 // Servers may infer this from the endpoint the client submits requests to.
1318 // Cannot be updated. In CamelCase. More info:
1319 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1320 "kind": "ValidatingWebhookConfiguration"
1321
1322 // metadata is the standard object metadata; More info:
1323 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
1324 "metadata"?: v1.#ObjectMeta
1325
1326 // webhooks is a list of webhooks and the affected resources and operations.
1327 "webhooks"?: [...#ValidatingWebhook]
1328}
1329
1330// ValidatingWebhookConfigurationList is a list of ValidatingWebhookConfiguration.
1331#ValidatingWebhookConfigurationList: {
1332 // APIVersion defines the versioned schema of this representation of an object.
1333 // Servers should convert recognized schemas to the latest internal value, and
1334 // may reject unrecognized values. More info:
1335 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1336 "apiVersion": "admissionregistration.k8s.io/v1"
1337
1338 // List of ValidatingWebhookConfiguration.
1339 "items"!: [...#ValidatingWebhookConfiguration]
1340
1341 // Kind is a string value representing the REST resource this object represents.
1342 // Servers may infer this from the endpoint the client submits requests to.
1343 // Cannot be updated. In CamelCase. More info:
1344 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1345 "kind": "ValidatingWebhookConfigurationList"
1346
1347 // metadata is the standard list metadata. More info:
1348 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1349 "metadata"?: v1.#ListMeta
1350}
1351
1352// Validation specifies the CEL expression which is used to apply the validation.
1353#Validation: {
1354 // expression represents the expression which will be evaluated by CEL. ref:
1355 // https://github.com/google/cel-spec CEL expressions have access to the
1356 // contents of the API request/response, organized into CEL variables as well
1357 // as some other useful variables:
1358 //
1359 // - 'object' - The object from the incoming request. The value is null for
1360 // DELETE requests. - 'oldObject' - The existing object. The value is null for
1361 // CREATE requests. - 'request' - Attributes of the API
1362 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
1363 // Parameter resource referred to by the policy binding being evaluated. Only
1364 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
1365 // object that the incoming object belongs to. The value is null for
1366 // cluster-scoped resources. - 'variables' - Map of composited variables, from
1367 // its name to its lazily evaluated value.
1368 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
1369 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
1370 // checks for the principal (user or service account) of the request.
1371 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
1372 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
1373 // 'authorizer' and configured with the
1374 // request resource.
1375 //
1376 // The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
1377 // always accessible from the root of the object. No other metadata properties
1378 // are accessible.
1379 //
1380 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are
1381 // accessible. Accessible property names are escaped according to the following
1382 // rules when accessed in the expression: - '__' escapes to '__underscores__' -
1383 // '.' escapes to '__dot__' - '-' escapes to '__dash__' - '/' escapes to
1384 // '__slash__' - Property names that exactly match a CEL RESERVED keyword
1385 // escape to '__{keyword}__'. The keywords are:
1386 // "true", "false", "null", "in", "as", "break", "const", "continue", "else",
1387 // "for", "function", "if",
1388 // "import", "let", "loop", "package", "namespace", "return".
1389 // Examples:
1390 // - Expression accessing a property named "namespace": {"Expression": "object.__namespace__ > 0"}
1391 // - Expression accessing a property named "x-prop": {"Expression": "object.x__dash__prop > 0"}
1392 // - Expression accessing a property named "redact__d": {"Expression":
1393 // "object.redact__underscores__d > 0"}
1394 //
1395 // Equality on arrays with list type of 'set' or 'map' ignores element order,
1396 // i.e. [1, 2] == [2, 1]. Concatenation on arrays with x-kubernetes-list-type
1397 // use the semantics of the list type:
1398 // - 'set': `X + Y` performs a union where the array positions of all elements
1399 // in `X` are preserved and
1400 // non-intersecting elements in `Y` are appended, retaining their partial order.
1401 // - 'map': `X + Y` performs a merge where the array positions of all keys in
1402 // `X` are preserved but the values
1403 // are overwritten by values in `Y` when the key sets of `X` and `Y` intersect. Elements in `Y` with
1404 // non-intersecting keys are appended, retaining their partial order.
1405 // Required.
1406 "expression"!: string
1407
1408 // message represents the message displayed when validation fails. The message
1409 // is required if the Expression contains line breaks. The message must not
1410 // contain line breaks. If unset, the message is "failed rule: {Rule}". e.g.
1411 // "must be a URL with the host matching spec.host" If the Expression contains
1412 // line breaks. Message is required. The message must not contain line breaks.
1413 // If unset, the message is "failed Expression: {Expression}".
1414 "message"?: string
1415
1416 // messageExpression declares a CEL expression that evaluates to the validation
1417 // failure message that is returned when this rule fails. Since
1418 // messageExpression is used as a failure message, it must evaluate to a
1419 // string. If both message and messageExpression are present on a validation,
1420 // then messageExpression will be used if validation fails. If
1421 // messageExpression results in a runtime error, the runtime error is logged,
1422 // and the validation failure message is produced as if the messageExpression
1423 // field were unset. If messageExpression evaluates to an empty string, a
1424 // string with only spaces, or a string that contains line breaks, then the
1425 // validation failure message will also be produced as if the messageExpression
1426 // field were unset, and the fact that messageExpression produced an empty
1427 // string/string with only spaces/string with line breaks will be logged.
1428 // messageExpression has access to all the same variables as the `expression`
1429 // except for 'authorizer' and 'authorizer.requestResource'. Example: "object.x
1430 // must be less than max ("+string(params.max)+")"
1431 "messageExpression"?: string
1432
1433 // reason represents a machine-readable description of why this validation
1434 // failed. If this is the first validation in the list to fail, this reason, as
1435 // well as the corresponding HTTP response code, are used in the HTTP response
1436 // to the client. The currently supported reasons are: "Unauthorized",
1437 // "Forbidden", "Invalid", "RequestEntityTooLarge". If not set,
1438 // StatusReasonInvalid is used in the response to the client.
1439 "reason"?: string
1440}
1441
1442// Variable is the definition of a variable that is used for composition. A
1443// variable is defined as a named expression.
1444#Variable: {
1445 // expression is the expression that will be evaluated as the value of the
1446 // variable. The CEL expression has access to the same identifiers as the CEL
1447 // expressions in Validation.
1448 "expression"!: string
1449
1450 // name is the name of the variable. The name must be a valid CEL identifier and
1451 // unique among all variables. The variable can be accessed in other
1452 // expressions through `variables` For example, if name is "foo", the variable
1453 // will be available as `variables.foo`
1454 "name"!: string
1455}
1456
1457// WebhookClientConfig contains the information to make a TLS connection with the webhook
1458#WebhookClientConfig: {
1459 // caBundle is a PEM encoded CA bundle which will be used to validate the
1460 // webhook's server certificate. If unspecified, system trust roots on the
1461 // apiserver are used.
1462 "caBundle"?: string
1463
1464 // service is a reference to the service for this webhook. Either `service` or
1465 // `url` must be specified.
1466 //
1467 // If the webhook is running within the cluster, then you should use `service`.
1468 "service"?: #ServiceReference
1469
1470 // url gives the location of the webhook, in standard URL form
1471 // (`scheme://host:port/path`). Exactly one of `url` or `service` must be
1472 // specified.
1473 //
1474 // The `host` should not refer to a service running in the cluster; use the
1475 // `service` field instead. The host might be resolved via external DNS in some
1476 // apiservers (e.g., `kube-apiserver` cannot resolve in-cluster DNS as that
1477 // would be a layering violation). `host` may also be an IP address.
1478 //
1479 // Please note that using `localhost` or `127.0.0.1` as a `host` is risky unless
1480 // you take great care to run this webhook on all hosts which run an apiserver
1481 // which might need to make calls to this webhook. Such installs are likely to
1482 // be non-portable, i.e., not easy to turn up in a new cluster.
1483 //
1484 // The scheme must be "https"; the URL must begin with "https://".
1485 //
1486 // A path is optional, and if present may be any string permissible in a URL.
1487 // You may use the path to pass an arbitrary string to the webhook, for
1488 // example, a cluster identifier.
1489 //
1490 // Attempting to use a user or basic auth e.g. "user:password@" is not allowed.
1491 // Fragments ("#...") and query parameters ("?...") are not allowed, either.
1492 "url"?: string
1493}