1package v1alpha1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// ApplyConfiguration defines the desired configuration values of an object.
6#ApplyConfiguration: {
7 // expression will be evaluated by CEL to create an apply configuration. ref:
8 // https://github.com/google/cel-spec
9 //
10 // Apply configurations are declared in CEL using object initialization. For
11 // example, this CEL expression returns an apply configuration to set a single
12 // field:
13 //
14 // Object{
15 // spec: Object.spec{
16 // serviceAccountName: "example"
17 // }
18 // }
19 //
20 // Apply configurations may not modify atomic structs, maps or arrays due to the
21 // risk of accidental deletion of values not included in the apply
22 // configuration.
23 //
24 // CEL expressions have access to the object types needed to create apply configurations:
25 //
26 // - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
27 // type of object field (such as 'Object.spec') -
28 // 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
29 // (such as 'Object.spec.containers')
30 //
31 // CEL expressions have access to the contents of the API request, organized
32 // into CEL variables as well as some other useful variables:
33 //
34 // - 'object' - The object from the incoming request. The value is null for
35 // DELETE requests. - 'oldObject' - The existing object. The value is null for
36 // CREATE requests. - 'request' - Attributes of the API
37 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
38 // Parameter resource referred to by the policy binding being evaluated. Only
39 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
40 // object that the incoming object belongs to. The value is null for
41 // cluster-scoped resources. - 'variables' - Map of composited variables, from
42 // its name to its lazily evaluated value.
43 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
44 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
45 // checks for the principal (user or service account) of the request.
46 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
47 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
48 // 'authorizer' and configured with the
49 // request resource.
50 //
51 // The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
52 // always accessible from the root of the object. No other metadata properties
53 // are accessible.
54 //
55 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
56 "expression"?: string
57}
58
59// JSONPatch defines a JSON Patch.
60#JSONPatch: {
61 // expression will be evaluated by CEL to create a [JSON
62 // patch](https://jsonpatch.com/). ref: https://github.com/google/cel-spec
63 //
64 // expression must return an array of JSONPatch values.
65 //
66 // For example, this CEL expression returns a JSON patch to conditionally modify a value:
67 //
68 // [
69 // JSONPatch{op: "test", path: "/spec/example", value: "Red"},
70 // JSONPatch{op: "replace", path: "/spec/example", value: "Green"}
71 // ]
72 //
73 // To define an object for the patch value, use Object types. For example:
74 //
75 // [
76 // JSONPatch{
77 // op: "add",
78 // path: "/spec/selector",
79 // value: Object.spec.selector{matchLabels: {"environment": "test"}}
80 // }
81 // ]
82 //
83 // To use strings containing '/' and '~' as JSONPatch path keys, use
84 // "jsonpatch.escapeKey". For example:
85 //
86 // [
87 // JSONPatch{
88 // op: "add",
89 // path: "/metadata/labels/" + jsonpatch.escapeKey("example.com/environment"),
90 // value: "test"
91 // },
92 // ]
93 //
94 // CEL expressions have access to the types needed to create JSON patches and objects:
95 //
96 // - 'JSONPatch' - CEL type of JSON Patch operations. JSONPatch has the fields
97 // 'op', 'from', 'path' and 'value'.
98 // See [JSON patch](https://jsonpatch.com/) for more details. The 'value' field
99 // may be set to any of: string,
100 // integer, array, map or object. If set, the 'path' and 'from' fields must be set to a
101 // [JSON pointer](https://datatracker.ietf.org/doc/html/rfc6901/) string, where
102 // the 'jsonpatch.escapeKey()' CEL
103 // function may be used to escape path keys containing '/' and '~'.
104 // - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
105 // type of object field (such as 'Object.spec') -
106 // 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
107 // (such as 'Object.spec.containers')
108 //
109 // CEL expressions have access to the contents of the API request, organized
110 // into CEL variables as well as some other useful variables:
111 //
112 // - 'object' - The object from the incoming request. The value is null for
113 // DELETE requests. - 'oldObject' - The existing object. The value is null for
114 // CREATE requests. - 'request' - Attributes of the API
115 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
116 // Parameter resource referred to by the policy binding being evaluated. Only
117 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
118 // object that the incoming object belongs to. The value is null for
119 // cluster-scoped resources. - 'variables' - Map of composited variables, from
120 // its name to its lazily evaluated value.
121 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
122 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
123 // checks for the principal (user or service account) of the request.
124 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
125 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
126 // 'authorizer' and configured with the
127 // request resource.
128 //
129 // CEL expressions have access to [Kubernetes CEL function
130 // libraries](https://kubernetes.io/docs/reference/using-api/cel/#cel-options-language-features-and-libraries)
131 // as well as:
132 //
133 // - 'jsonpatch.escapeKey' - Performs JSONPatch key escaping. '~' and '/' are
134 // escaped as '~0' and `~1' respectively).
135 //
136 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
137 "expression"?: string
138}
139#MatchCondition: {
140 // expression represents the expression which will be evaluated by CEL. Must
141 // evaluate to bool. CEL expressions have access to the contents of the
142 // AdmissionRequest and Authorizer, organized into CEL variables:
143 //
144 // 'object' - The object from the incoming request. The value is null for DELETE
145 // requests. 'oldObject' - The existing object. The value is null for CREATE
146 // requests. 'request' - Attributes of the admission
147 // request(/pkg/apis/admission/types.go#AdmissionRequest). 'authorizer' - A CEL
148 // Authorizer. May be used to perform authorization checks for the principal
149 // (user or service account) of the request.
150 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
151 // 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
152 // 'authorizer' and configured with the
153 // request resource.
154 // Documentation on CEL: https://kubernetes.io/docs/reference/using-api/cel/
155 //
156 // Required.
157 "expression"!: string
158
159 // name is an identifier for this match condition, used for strategic merging of
160 // MatchConditions, as well as providing an identifier for logging purposes. A
161 // good name should be descriptive of the associated expression. Name must be a
162 // qualified name consisting of alphanumeric characters, '-', '_' or '.', and
163 // must start and end with an alphanumeric character (e.g. 'MyName', or
164 // 'my.name', or '123-abc', regex used for validation is
165 // '([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]') with an optional DNS subdomain
166 // prefix and '/' (e.g. 'example.com/MyName')
167 //
168 // Required.
169 "name"!: string
170}
171
172// MatchResources decides whether to run the admission control policy on an
173// object based on whether it meets the match criteria. The exclude rules take
174// precedence over include rules (if a resource matches both, it is excluded)
175#MatchResources: {
176 // excludeResourceRules describes what operations on what resources/subresources
177 // the policy should not care about. The exclude rules take precedence over
178 // include rules (if a resource matches both, it is excluded)
179 "excludeResourceRules"?: [...#NamedRuleWithOperations]
180
181 // matchPolicy defines how the "MatchResources" list is used to match incoming
182 // requests. Allowed values are "Exact" or "Equivalent".
183 //
184 // - Exact: match a request only if it exactly matches a specified rule. For
185 // example, if deployments can be modified via apps/v1, apps/v1beta1, and
186 // extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
187 // apiVersions:["v1"], resources: ["deployments"]`, the admission policy does
188 // not consider requests to apps/v1beta1 or extensions/v1beta1 API groups.
189 //
190 // - Equivalent: match a request if modifies a resource listed in rules, even
191 // via another API group or version. For example, if deployments can be
192 // modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
193 // included `apiGroups:["apps"], apiVersions:["v1"], resources:
194 // ["deployments"]`, the admission policy **does** consider requests made to
195 // apps/v1beta1 or extensions/v1beta1 API groups. The API server translates the
196 // request to a matched resource API if necessary.
197 //
198 // Defaults to "Equivalent"
199 "matchPolicy"?: string
200
201 // namespaceSelector decides whether to run the admission control policy on an
202 // object based on whether the namespace for that object matches the selector.
203 // If the object itself is a namespace, the matching is performed on
204 // object.metadata.labels. If the object is another cluster scoped resource, it
205 // never skips the policy.
206 //
207 // For example, to run the webhook on any objects whose namespace is not
208 // associated with "runlevel" of "0" or "1"; you will set the selector as
209 // follows: "namespaceSelector": {
210 // "matchExpressions": [
211 // {
212 // "key": "runlevel",
213 // "operator": "NotIn",
214 // "values": [
215 // "0",
216 // "1"
217 // ]
218 // }
219 // ]
220 // }
221 //
222 // If instead you want to only run the policy on any objects whose namespace is
223 // associated with the "environment" of "prod" or "staging"; you will set the
224 // selector as follows: "namespaceSelector": {
225 // "matchExpressions": [
226 // {
227 // "key": "environment",
228 // "operator": "In",
229 // "values": [
230 // "prod",
231 // "staging"
232 // ]
233 // }
234 // ]
235 // }
236 //
237 // See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
238 // for more examples of label selectors.
239 //
240 // Default to the empty LabelSelector, which matches everything.
241 "namespaceSelector"?: v1.#LabelSelector
242
243 // objectSelector decides whether to run the policy based on if the object has
244 // matching labels. objectSelector is evaluated against both the oldObject and
245 // newObject that would be sent to the policy's expression (CEL), and is
246 // considered to match if either object matches the selector. A null object
247 // (oldObject in the case of create, or newObject in the case of delete) or an
248 // object that cannot have labels (like a DeploymentRollback or a
249 // PodProxyOptions object) is not considered to match. Use the object selector
250 // only if the webhook is opt-in, because end users may skip the admission
251 // webhook by setting the labels. Default to the empty LabelSelector, which
252 // matches everything.
253 "objectSelector"?: v1.#LabelSelector
254
255 // resourceRules describes what operations on what resources/subresources the
256 // admission policy matches. The policy cares about an operation if it matches
257 // _any_ Rule.
258 "resourceRules"?: [...#NamedRuleWithOperations]
259}
260
261// MutatingAdmissionPolicy describes the definition of an admission mutation
262// policy that mutates the object coming into admission chain.
263#MutatingAdmissionPolicy: {
264 // APIVersion defines the versioned schema of this representation of an object.
265 // Servers should convert recognized schemas to the latest internal value, and
266 // may reject unrecognized values. More info:
267 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
268 "apiVersion": "admissionregistration.k8s.io/v1alpha1"
269
270 // Kind is a string value representing the REST resource this object represents.
271 // Servers may infer this from the endpoint the client submits requests to.
272 // Cannot be updated. In CamelCase. More info:
273 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
274 "kind": "MutatingAdmissionPolicy"
275
276 // metadata is the standard object metadata; More info:
277 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
278 "metadata"?: v1.#ObjectMeta
279
280 // spec defines the desired behavior of the MutatingAdmissionPolicy.
281 "spec"?: #MutatingAdmissionPolicySpec
282}
283
284// MutatingAdmissionPolicyBinding binds the MutatingAdmissionPolicy with
285// parametrized resources. MutatingAdmissionPolicyBinding and the optional
286// parameter resource together define how cluster administrators configure
287// policies for clusters.
288//
289// For a given admission request, each binding will cause its policy to be
290// evaluated N times, where N is 1 for policies/bindings that don't use params,
291// otherwise N is the number of parameters selected by the binding. Each
292// evaluation is constrained by a [runtime cost
293// budget](https://kubernetes.io/docs/reference/using-api/cel/#runtime-cost-budget).
294//
295// Adding/removing policies, bindings, or params can not affect whether a given
296// (policy, binding, param) combination is within its own CEL budget.
297#MutatingAdmissionPolicyBinding: {
298 // APIVersion defines the versioned schema of this representation of an object.
299 // Servers should convert recognized schemas to the latest internal value, and
300 // may reject unrecognized values. More info:
301 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
302 "apiVersion": "admissionregistration.k8s.io/v1alpha1"
303
304 // Kind is a string value representing the REST resource this object represents.
305 // Servers may infer this from the endpoint the client submits requests to.
306 // Cannot be updated. In CamelCase. More info:
307 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
308 "kind": "MutatingAdmissionPolicyBinding"
309
310 // metadata is the standard object metadata; More info:
311 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
312 "metadata"?: v1.#ObjectMeta
313
314 // spec defines the desired behavior of the MutatingAdmissionPolicyBinding.
315 "spec"?: #MutatingAdmissionPolicyBindingSpec
316}
317
318// MutatingAdmissionPolicyBindingList is a list of MutatingAdmissionPolicyBinding.
319#MutatingAdmissionPolicyBindingList: {
320 // APIVersion defines the versioned schema of this representation of an object.
321 // Servers should convert recognized schemas to the latest internal value, and
322 // may reject unrecognized values. More info:
323 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
324 "apiVersion": "admissionregistration.k8s.io/v1alpha1"
325
326 // List of PolicyBinding.
327 "items"!: [...#MutatingAdmissionPolicyBinding]
328
329 // Kind is a string value representing the REST resource this object represents.
330 // Servers may infer this from the endpoint the client submits requests to.
331 // Cannot be updated. In CamelCase. More info:
332 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
333 "kind": "MutatingAdmissionPolicyBindingList"
334
335 // metadata is the standard list metadata. More info:
336 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
337 "metadata"?: v1.#ListMeta
338}
339
340// MutatingAdmissionPolicyBindingSpec is the specification of the MutatingAdmissionPolicyBinding.
341#MutatingAdmissionPolicyBindingSpec: {
342 // matchResources limits what resources match this binding and may be mutated by
343 // it. Note that if matchResources matches a resource, the resource must also
344 // match a policy's matchConstraints and matchConditions before the resource
345 // may be mutated. When matchResources is unset, it does not constrain resource
346 // matching, and only the policy's matchConstraints and matchConditions must
347 // match for the resource to be mutated. Additionally,
348 // matchResources.resourceRules are optional and do not constraint matching
349 // when unset. Note that this is differs from MutatingAdmissionPolicy
350 // matchConstraints, where resourceRules are required. The CREATE, UPDATE and
351 // CONNECT operations are allowed. The DELETE operation may not be matched. '*'
352 // matches CREATE, UPDATE and CONNECT.
353 "matchResources"?: #MatchResources
354
355 // paramRef specifies the parameter resource used to configure the admission
356 // control policy. It should point to a resource of the type specified in
357 // spec.ParamKind of the bound MutatingAdmissionPolicy. If the policy specifies
358 // a ParamKind and the resource referred to by ParamRef does not exist, this
359 // binding is considered mis-configured and the FailurePolicy of the
360 // MutatingAdmissionPolicy applied. If the policy does not specify a ParamKind
361 // then this field is ignored, and the rules are evaluated without a param.
362 "paramRef"?: #ParamRef
363
364 // policyName references a MutatingAdmissionPolicy name which the
365 // MutatingAdmissionPolicyBinding binds to. If the referenced resource does not
366 // exist, this binding is considered invalid and will be ignored Required.
367 "policyName"?: string
368}
369
370// MutatingAdmissionPolicyList is a list of MutatingAdmissionPolicy.
371#MutatingAdmissionPolicyList: {
372 // APIVersion defines the versioned schema of this representation of an object.
373 // Servers should convert recognized schemas to the latest internal value, and
374 // may reject unrecognized values. More info:
375 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
376 "apiVersion": "admissionregistration.k8s.io/v1alpha1"
377
378 // List of ValidatingAdmissionPolicy.
379 "items"!: [...#MutatingAdmissionPolicy]
380
381 // Kind is a string value representing the REST resource this object represents.
382 // Servers may infer this from the endpoint the client submits requests to.
383 // Cannot be updated. In CamelCase. More info:
384 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
385 "kind": "MutatingAdmissionPolicyList"
386
387 // metadata is the standard list metadata. More info:
388 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
389 "metadata"?: v1.#ListMeta
390}
391
392// MutatingAdmissionPolicySpec is the specification of the desired behavior of the admission policy.
393#MutatingAdmissionPolicySpec: {
394 // failurePolicy defines how to handle failures for the admission policy.
395 // Failures can occur from CEL expression parse errors, type check errors,
396 // runtime errors and invalid or mis-configured policy definitions or bindings.
397 //
398 // A policy is invalid if paramKind refers to a non-existent Kind. A binding is
399 // invalid if paramRef.name refers to a non-existent resource.
400 //
401 // failurePolicy does not define how validations that evaluate to false are handled.
402 //
403 // Allowed values are Ignore or Fail. Defaults to Fail.
404 "failurePolicy"?: string
405
406 // matchConditions is a list of conditions that must be met for a request to be
407 // validated. Match conditions filter requests that have already been matched
408 // by the matchConstraints. An empty list of matchConditions matches all
409 // requests. There are a maximum of 64 match conditions allowed.
410 //
411 // If a parameter object is provided, it can be accessed via the `params` handle
412 // in the same manner as validation expressions.
413 //
414 // The exact matching logic is (in order):
415 // 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
416 // 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
417 // 3. If any matchCondition evaluates to an error (but none are FALSE):
418 // - If failurePolicy=Fail, reject the request
419 // - If failurePolicy=Ignore, the policy is skipped
420 "matchConditions"?: [...#MatchCondition]
421
422 // matchConstraints specifies what resources this policy is designed to
423 // validate. The MutatingAdmissionPolicy cares about a request if it matches
424 // _all_ Constraints. However, in order to prevent clusters from being put into
425 // an unstable state that cannot be recovered from via the API
426 // MutatingAdmissionPolicy cannot match MutatingAdmissionPolicy and
427 // MutatingAdmissionPolicyBinding. The CREATE, UPDATE and CONNECT operations
428 // are allowed. The DELETE operation may not be matched. '*' matches CREATE,
429 // UPDATE and CONNECT. Required.
430 "matchConstraints"?: #MatchResources
431
432 // mutations contain operations to perform on matching objects. mutations may
433 // not be empty; a minimum of one mutation is required. mutations are evaluated
434 // in order, and are reinvoked according to the reinvocationPolicy. The
435 // mutations of a policy are invoked for each binding of this policy and
436 // reinvocation of mutations occurs on a per binding basis.
437 "mutations"?: [...#Mutation]
438
439 // paramKind specifies the kind of resources used to parameterize this policy.
440 // If absent, there are no parameters for this policy and the param CEL
441 // variable will not be provided to validation expressions. If paramKind refers
442 // to a non-existent kind, this policy definition is mis-configured and the
443 // FailurePolicy is applied. If paramKind is specified but paramRef is unset in
444 // MutatingAdmissionPolicyBinding, the params variable will be null.
445 "paramKind"?: #ParamKind
446
447 // reinvocationPolicy indicates whether mutations may be called multiple times
448 // per MutatingAdmissionPolicyBinding as part of a single admission evaluation.
449 // Allowed values are "Never" and "IfNeeded".
450 //
451 // Never: These mutations will not be called more than once per binding in a
452 // single admission evaluation.
453 //
454 // IfNeeded: These mutations may be invoked more than once per binding for a
455 // single admission request and there is no guarantee of order with respect to
456 // other admission plugins, admission webhooks, bindings of this policy and
457 // admission policies. Mutations are only reinvoked when mutations change the
458 // object after this mutation is invoked. Required.
459 "reinvocationPolicy"?: string
460
461 // variables contain definitions of variables that can be used in composition of
462 // other expressions. Each variable is defined as a named CEL expression. The
463 // variables defined here will be available under `variables` in other
464 // expressions of the policy except matchConditions because matchConditions are
465 // evaluated before the rest of the policy.
466 //
467 // The expression of a variable can refer to other variables defined earlier in
468 // the list but not those after. Thus, variables must be sorted by the order of
469 // first appearance and acyclic.
470 "variables"?: [...#Variable]
471}
472
473// Mutation specifies the CEL expression which is used to apply the Mutation.
474#Mutation: {
475 // applyConfiguration defines the desired configuration values of an object. The
476 // configuration is applied to the admission object using [structured merge
477 // diff](https://github.com/kubernetes-sigs/structured-merge-diff). A CEL
478 // expression is used to create apply configuration.
479 "applyConfiguration"?: #ApplyConfiguration
480
481 // jsonPatch defines a [JSON patch](https://jsonpatch.com/) operation to perform
482 // a mutation to the object. A CEL expression is used to create the JSON patch.
483 "jsonPatch"?: #JSONPatch
484
485 // patchType indicates the patch strategy used. Allowed values are
486 // "ApplyConfiguration" and "JSONPatch". Required.
487 "patchType"!: string
488}
489
490// NamedRuleWithOperations is a tuple of Operations and Resources with ResourceNames.
491#NamedRuleWithOperations: {
492 // apiGroups is the API groups the resources belong to. '*' is all groups. If
493 // '*' is present, the length of the slice must be one. Required.
494 "apiGroups"?: [...string]
495
496 // apiVersions is the API versions the resources belong to. '*' is all versions.
497 // If '*' is present, the length of the slice must be one. Required.
498 "apiVersions"?: [...string]
499
500 // operations is the operations the admission hook cares about - CREATE, UPDATE,
501 // DELETE, CONNECT or * for all of those operations and any future admission
502 // operations that are added. If '*' is present, the length of the slice must
503 // be one. Required.
504 "operations"?: [...string]
505
506 // resourceNames is an optional white list of names that the rule applies to. An
507 // empty set means that everything is allowed.
508 "resourceNames"?: [...string]
509
510 // resources is a list of resources this rule applies to.
511 //
512 // For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
513 // '*' means all resources, but not subresources. 'pods/*' means all
514 // subresources of pods. '*/scale' means all scale subresources. '*/*' means
515 // all resources and their subresources.
516 //
517 // If wildcard is present, the validation rule will ensure resources do not overlap with each other.
518 //
519 // Depending on the enclosing object, subresources might not be allowed. Required.
520 "resources"?: [...string]
521
522 // scope specifies the scope of this rule. Valid values are "Cluster",
523 // "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
524 // will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
525 // means that only namespaced resources will match this rule. "*" means that
526 // there are no scope restrictions. Subresources match the scope of their
527 // parent resource. Default is "*".
528 "scope"?: string
529}
530
531// ParamKind is a tuple of Group Kind and Version.
532#ParamKind: {
533 // apiVersion is the API group version the resources belong to. In format of
534 // "group/version". Required.
535 "apiVersion"?: string
536
537 // kind is the API kind the resources belong to. Required.
538 "kind"?: string
539}
540
541// ParamRef describes how to locate the params to be used as input to
542// expressions of rules applied by a policy binding.
543#ParamRef: {
544 // name is the name of the resource being referenced.
545 //
546 // `name` and `selector` are mutually exclusive properties. If one is set, the other must be unset.
547 "name"?: string
548
549 // namespace is the namespace of the referenced resource. Allows limiting the
550 // search for params to a specific namespace. Applies to both `name` and
551 // `selector` fields.
552 //
553 // A per-namespace parameter may be used by specifying a namespace-scoped
554 // `paramKind` in the policy and leaving this field empty.
555 //
556 // - If `paramKind` is cluster-scoped, this field MUST be unset. Setting this
557 // field results in a configuration error.
558 //
559 // - If `paramKind` is namespace-scoped, the namespace of the object being
560 // evaluated for admission will be used when this field is left unset. Take
561 // care that if this is left empty the binding must not match any
562 // cluster-scoped resources, which will result in an error.
563 "namespace"?: string
564
565 // parameterNotFoundAction controls the behavior of the binding when the
566 // resource exists, and name or selector is valid, but there are no parameters
567 // matched by the binding. If the value is set to `Allow`, then no matched
568 // parameters will be treated as successful validation by the binding. If set
569 // to `Deny`, then no matched parameters will be subject to the `failurePolicy`
570 // of the policy.
571 //
572 // Allowed values are `Allow` or `Deny` Default to `Deny`
573 "parameterNotFoundAction"?: string
574
575 // selector can be used to match multiple param objects based on their labels.
576 // Supply selector: {} to match all resources of the ParamKind.
577 //
578 // If multiple params are found, they are all evaluated with the policy
579 // expressions and the results are ANDed together.
580 //
581 // One of `name` or `selector` must be set, but `name` and `selector` are
582 // mutually exclusive properties. If one is set, the other must be unset.
583 "selector"?: v1.#LabelSelector
584}
585
586// Variable is the definition of a variable that is used for composition.
587#Variable: {
588 // expression is the expression that will be evaluated as the value of the
589 // variable. The CEL expression has access to the same identifiers as the CEL
590 // expressions in Validation.
591 "expression"!: string
592
593 // name is the name of the variable. The name must be a valid CEL identifier and
594 // unique among all variables. The variable can be accessed in other
595 // expressions through `variables` For example, if name is "foo", the variable
596 // will be available as `variables.foo`
597 "name"!: string
598}