cue.dev/x/k8s.io@v0.12.0

api/admissionregistration/v1alpha1/schema.cue raw

  1package v1alpha1
  2
  3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
  4
  5// ApplyConfiguration defines the desired configuration values of an object.
  6#ApplyConfiguration: {
  7	// expression will be evaluated by CEL to create an apply configuration. ref:
  8	// https://github.com/google/cel-spec
  9	//
 10	// Apply configurations are declared in CEL using object initialization. For
 11	// example, this CEL expression returns an apply configuration to set a single
 12	// field:
 13	//
 14	// Object{
 15	// spec: Object.spec{
 16	// serviceAccountName: "example"
 17	// }
 18	// }
 19	//
 20	// Apply configurations may not modify atomic structs, maps or arrays due to the
 21	// risk of accidental deletion of values not included in the apply
 22	// configuration.
 23	//
 24	// CEL expressions have access to the object types needed to create apply configurations:
 25	//
 26	// - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
 27	// type of object field (such as 'Object.spec') -
 28	// 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
 29	// (such as 'Object.spec.containers')
 30	//
 31	// CEL expressions have access to the contents of the API request, organized
 32	// into CEL variables as well as some other useful variables:
 33	//
 34	// - 'object' - The object from the incoming request. The value is null for
 35	// DELETE requests. - 'oldObject' - The existing object. The value is null for
 36	// CREATE requests. - 'request' - Attributes of the API
 37	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
 38	// Parameter resource referred to by the policy binding being evaluated. Only
 39	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
 40	// object that the incoming object belongs to. The value is null for
 41	// cluster-scoped resources. - 'variables' - Map of composited variables, from
 42	// its name to its lazily evaluated value.
 43	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
 44	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
 45	// checks for the principal (user or service account) of the request.
 46	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
 47	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
 48	// 'authorizer' and configured with the
 49	// request resource.
 50	//
 51	// The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
 52	// always accessible from the root of the object. No other metadata properties
 53	// are accessible.
 54	//
 55	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
 56	"expression"?: string
 57}
 58
 59// JSONPatch defines a JSON Patch.
 60#JSONPatch: {
 61	// expression will be evaluated by CEL to create a [JSON
 62	// patch](https://jsonpatch.com/). ref: https://github.com/google/cel-spec
 63	//
 64	// expression must return an array of JSONPatch values.
 65	//
 66	// For example, this CEL expression returns a JSON patch to conditionally modify a value:
 67	//
 68	// [
 69	// JSONPatch{op: "test", path: "/spec/example", value: "Red"},
 70	// JSONPatch{op: "replace", path: "/spec/example", value: "Green"}
 71	// ]
 72	//
 73	// To define an object for the patch value, use Object types. For example:
 74	//
 75	// [
 76	// JSONPatch{
 77	// op: "add",
 78	// path: "/spec/selector",
 79	// value: Object.spec.selector{matchLabels: {"environment": "test"}}
 80	// }
 81	// ]
 82	//
 83	// To use strings containing '/' and '~' as JSONPatch path keys, use
 84	// "jsonpatch.escapeKey". For example:
 85	//
 86	// [
 87	// JSONPatch{
 88	// op: "add",
 89	// path: "/metadata/labels/" + jsonpatch.escapeKey("example.com/environment"),
 90	// value: "test"
 91	// },
 92	// ]
 93	//
 94	// CEL expressions have access to the types needed to create JSON patches and objects:
 95	//
 96	// - 'JSONPatch' - CEL type of JSON Patch operations. JSONPatch has the fields
 97	// 'op', 'from', 'path' and 'value'.
 98	// See [JSON patch](https://jsonpatch.com/) for more details. The 'value' field
 99	// may be set to any of: string,
100	// integer, array, map or object. If set, the 'path' and 'from' fields must be set to a
101	// [JSON pointer](https://datatracker.ietf.org/doc/html/rfc6901/) string, where
102	// the 'jsonpatch.escapeKey()' CEL
103	// function may be used to escape path keys containing '/' and '~'.
104	// - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
105	// type of object field (such as 'Object.spec') -
106	// 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
107	// (such as 'Object.spec.containers')
108	//
109	// CEL expressions have access to the contents of the API request, organized
110	// into CEL variables as well as some other useful variables:
111	//
112	// - 'object' - The object from the incoming request. The value is null for
113	// DELETE requests. - 'oldObject' - The existing object. The value is null for
114	// CREATE requests. - 'request' - Attributes of the API
115	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
116	// Parameter resource referred to by the policy binding being evaluated. Only
117	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
118	// object that the incoming object belongs to. The value is null for
119	// cluster-scoped resources. - 'variables' - Map of composited variables, from
120	// its name to its lazily evaluated value.
121	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
122	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
123	// checks for the principal (user or service account) of the request.
124	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
125	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
126	// 'authorizer' and configured with the
127	// request resource.
128	//
129	// CEL expressions have access to [Kubernetes CEL function
130	// libraries](https://kubernetes.io/docs/reference/using-api/cel/#cel-options-language-features-and-libraries)
131	// as well as:
132	//
133	// - 'jsonpatch.escapeKey' - Performs JSONPatch key escaping. '~' and '/' are
134	// escaped as '~0' and `~1' respectively).
135	//
136	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
137	"expression"?: string
138}
139#MatchCondition: {
140	// expression represents the expression which will be evaluated by CEL. Must
141	// evaluate to bool. CEL expressions have access to the contents of the
142	// AdmissionRequest and Authorizer, organized into CEL variables:
143	//
144	// 'object' - The object from the incoming request. The value is null for DELETE
145	// requests. 'oldObject' - The existing object. The value is null for CREATE
146	// requests. 'request' - Attributes of the admission
147	// request(/pkg/apis/admission/types.go#AdmissionRequest). 'authorizer' - A CEL
148	// Authorizer. May be used to perform authorization checks for the principal
149	// (user or service account) of the request.
150	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
151	// 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
152	// 'authorizer' and configured with the
153	// request resource.
154	// Documentation on CEL: https://kubernetes.io/docs/reference/using-api/cel/
155	//
156	// Required.
157	"expression"!: string
158
159	// name is an identifier for this match condition, used for strategic merging of
160	// MatchConditions, as well as providing an identifier for logging purposes. A
161	// good name should be descriptive of the associated expression. Name must be a
162	// qualified name consisting of alphanumeric characters, '-', '_' or '.', and
163	// must start and end with an alphanumeric character (e.g. 'MyName', or
164	// 'my.name', or '123-abc', regex used for validation is
165	// '([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]') with an optional DNS subdomain
166	// prefix and '/' (e.g. 'example.com/MyName')
167	//
168	// Required.
169	"name"!: string
170}
171
172// MatchResources decides whether to run the admission control policy on an
173// object based on whether it meets the match criteria. The exclude rules take
174// precedence over include rules (if a resource matches both, it is excluded)
175#MatchResources: {
176	// excludeResourceRules describes what operations on what resources/subresources
177	// the policy should not care about. The exclude rules take precedence over
178	// include rules (if a resource matches both, it is excluded)
179	"excludeResourceRules"?: [...#NamedRuleWithOperations]
180
181	// matchPolicy defines how the "MatchResources" list is used to match incoming
182	// requests. Allowed values are "Exact" or "Equivalent".
183	//
184	// - Exact: match a request only if it exactly matches a specified rule. For
185	// example, if deployments can be modified via apps/v1, apps/v1beta1, and
186	// extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
187	// apiVersions:["v1"], resources: ["deployments"]`, the admission policy does
188	// not consider requests to apps/v1beta1 or extensions/v1beta1 API groups.
189	//
190	// - Equivalent: match a request if modifies a resource listed in rules, even
191	// via another API group or version. For example, if deployments can be
192	// modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
193	// included `apiGroups:["apps"], apiVersions:["v1"], resources:
194	// ["deployments"]`, the admission policy **does** consider requests made to
195	// apps/v1beta1 or extensions/v1beta1 API groups. The API server translates the
196	// request to a matched resource API if necessary.
197	//
198	// Defaults to "Equivalent"
199	"matchPolicy"?: string
200
201	// namespaceSelector decides whether to run the admission control policy on an
202	// object based on whether the namespace for that object matches the selector.
203	// If the object itself is a namespace, the matching is performed on
204	// object.metadata.labels. If the object is another cluster scoped resource, it
205	// never skips the policy.
206	//
207	// For example, to run the webhook on any objects whose namespace is not
208	// associated with "runlevel" of "0" or "1"; you will set the selector as
209	// follows: "namespaceSelector": {
210	// "matchExpressions": [
211	// {
212	// "key": "runlevel",
213	// "operator": "NotIn",
214	// "values": [
215	// "0",
216	// "1"
217	// ]
218	// }
219	// ]
220	// }
221	//
222	// If instead you want to only run the policy on any objects whose namespace is
223	// associated with the "environment" of "prod" or "staging"; you will set the
224	// selector as follows: "namespaceSelector": {
225	// "matchExpressions": [
226	// {
227	// "key": "environment",
228	// "operator": "In",
229	// "values": [
230	// "prod",
231	// "staging"
232	// ]
233	// }
234	// ]
235	// }
236	//
237	// See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
238	// for more examples of label selectors.
239	//
240	// Default to the empty LabelSelector, which matches everything.
241	"namespaceSelector"?: v1.#LabelSelector
242
243	// objectSelector decides whether to run the policy based on if the object has
244	// matching labels. objectSelector is evaluated against both the oldObject and
245	// newObject that would be sent to the policy's expression (CEL), and is
246	// considered to match if either object matches the selector. A null object
247	// (oldObject in the case of create, or newObject in the case of delete) or an
248	// object that cannot have labels (like a DeploymentRollback or a
249	// PodProxyOptions object) is not considered to match. Use the object selector
250	// only if the webhook is opt-in, because end users may skip the admission
251	// webhook by setting the labels. Default to the empty LabelSelector, which
252	// matches everything.
253	"objectSelector"?: v1.#LabelSelector
254
255	// resourceRules describes what operations on what resources/subresources the
256	// admission policy matches. The policy cares about an operation if it matches
257	// _any_ Rule.
258	"resourceRules"?: [...#NamedRuleWithOperations]
259}
260
261// MutatingAdmissionPolicy describes the definition of an admission mutation
262// policy that mutates the object coming into admission chain.
263#MutatingAdmissionPolicy: {
264	// APIVersion defines the versioned schema of this representation of an object.
265	// Servers should convert recognized schemas to the latest internal value, and
266	// may reject unrecognized values. More info:
267	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
268	"apiVersion": "admissionregistration.k8s.io/v1alpha1"
269
270	// Kind is a string value representing the REST resource this object represents.
271	// Servers may infer this from the endpoint the client submits requests to.
272	// Cannot be updated. In CamelCase. More info:
273	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
274	"kind": "MutatingAdmissionPolicy"
275
276	// metadata is the standard object metadata; More info:
277	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
278	"metadata"?: v1.#ObjectMeta
279
280	// spec defines the desired behavior of the MutatingAdmissionPolicy.
281	"spec"?: #MutatingAdmissionPolicySpec
282}
283
284// MutatingAdmissionPolicyBinding binds the MutatingAdmissionPolicy with
285// parametrized resources. MutatingAdmissionPolicyBinding and the optional
286// parameter resource together define how cluster administrators configure
287// policies for clusters.
288//
289// For a given admission request, each binding will cause its policy to be
290// evaluated N times, where N is 1 for policies/bindings that don't use params,
291// otherwise N is the number of parameters selected by the binding. Each
292// evaluation is constrained by a [runtime cost
293// budget](https://kubernetes.io/docs/reference/using-api/cel/#runtime-cost-budget).
294//
295// Adding/removing policies, bindings, or params can not affect whether a given
296// (policy, binding, param) combination is within its own CEL budget.
297#MutatingAdmissionPolicyBinding: {
298	// APIVersion defines the versioned schema of this representation of an object.
299	// Servers should convert recognized schemas to the latest internal value, and
300	// may reject unrecognized values. More info:
301	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
302	"apiVersion": "admissionregistration.k8s.io/v1alpha1"
303
304	// Kind is a string value representing the REST resource this object represents.
305	// Servers may infer this from the endpoint the client submits requests to.
306	// Cannot be updated. In CamelCase. More info:
307	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
308	"kind": "MutatingAdmissionPolicyBinding"
309
310	// metadata is the standard object metadata; More info:
311	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
312	"metadata"?: v1.#ObjectMeta
313
314	// spec defines the desired behavior of the MutatingAdmissionPolicyBinding.
315	"spec"?: #MutatingAdmissionPolicyBindingSpec
316}
317
318// MutatingAdmissionPolicyBindingList is a list of MutatingAdmissionPolicyBinding.
319#MutatingAdmissionPolicyBindingList: {
320	// APIVersion defines the versioned schema of this representation of an object.
321	// Servers should convert recognized schemas to the latest internal value, and
322	// may reject unrecognized values. More info:
323	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
324	"apiVersion": "admissionregistration.k8s.io/v1alpha1"
325
326	// List of PolicyBinding.
327	"items"!: [...#MutatingAdmissionPolicyBinding]
328
329	// Kind is a string value representing the REST resource this object represents.
330	// Servers may infer this from the endpoint the client submits requests to.
331	// Cannot be updated. In CamelCase. More info:
332	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
333	"kind": "MutatingAdmissionPolicyBindingList"
334
335	// metadata is the standard list metadata. More info:
336	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
337	"metadata"?: v1.#ListMeta
338}
339
340// MutatingAdmissionPolicyBindingSpec is the specification of the MutatingAdmissionPolicyBinding.
341#MutatingAdmissionPolicyBindingSpec: {
342	// matchResources limits what resources match this binding and may be mutated by
343	// it. Note that if matchResources matches a resource, the resource must also
344	// match a policy's matchConstraints and matchConditions before the resource
345	// may be mutated. When matchResources is unset, it does not constrain resource
346	// matching, and only the policy's matchConstraints and matchConditions must
347	// match for the resource to be mutated. Additionally,
348	// matchResources.resourceRules are optional and do not constraint matching
349	// when unset. Note that this is differs from MutatingAdmissionPolicy
350	// matchConstraints, where resourceRules are required. The CREATE, UPDATE and
351	// CONNECT operations are allowed. The DELETE operation may not be matched. '*'
352	// matches CREATE, UPDATE and CONNECT.
353	"matchResources"?: #MatchResources
354
355	// paramRef specifies the parameter resource used to configure the admission
356	// control policy. It should point to a resource of the type specified in
357	// spec.ParamKind of the bound MutatingAdmissionPolicy. If the policy specifies
358	// a ParamKind and the resource referred to by ParamRef does not exist, this
359	// binding is considered mis-configured and the FailurePolicy of the
360	// MutatingAdmissionPolicy applied. If the policy does not specify a ParamKind
361	// then this field is ignored, and the rules are evaluated without a param.
362	"paramRef"?: #ParamRef
363
364	// policyName references a MutatingAdmissionPolicy name which the
365	// MutatingAdmissionPolicyBinding binds to. If the referenced resource does not
366	// exist, this binding is considered invalid and will be ignored Required.
367	"policyName"?: string
368}
369
370// MutatingAdmissionPolicyList is a list of MutatingAdmissionPolicy.
371#MutatingAdmissionPolicyList: {
372	// APIVersion defines the versioned schema of this representation of an object.
373	// Servers should convert recognized schemas to the latest internal value, and
374	// may reject unrecognized values. More info:
375	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
376	"apiVersion": "admissionregistration.k8s.io/v1alpha1"
377
378	// List of ValidatingAdmissionPolicy.
379	"items"!: [...#MutatingAdmissionPolicy]
380
381	// Kind is a string value representing the REST resource this object represents.
382	// Servers may infer this from the endpoint the client submits requests to.
383	// Cannot be updated. In CamelCase. More info:
384	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
385	"kind": "MutatingAdmissionPolicyList"
386
387	// metadata is the standard list metadata. More info:
388	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
389	"metadata"?: v1.#ListMeta
390}
391
392// MutatingAdmissionPolicySpec is the specification of the desired behavior of the admission policy.
393#MutatingAdmissionPolicySpec: {
394	// failurePolicy defines how to handle failures for the admission policy.
395	// Failures can occur from CEL expression parse errors, type check errors,
396	// runtime errors and invalid or mis-configured policy definitions or bindings.
397	//
398	// A policy is invalid if paramKind refers to a non-existent Kind. A binding is
399	// invalid if paramRef.name refers to a non-existent resource.
400	//
401	// failurePolicy does not define how validations that evaluate to false are handled.
402	//
403	// Allowed values are Ignore or Fail. Defaults to Fail.
404	"failurePolicy"?: string
405
406	// matchConditions is a list of conditions that must be met for a request to be
407	// validated. Match conditions filter requests that have already been matched
408	// by the matchConstraints. An empty list of matchConditions matches all
409	// requests. There are a maximum of 64 match conditions allowed.
410	//
411	// If a parameter object is provided, it can be accessed via the `params` handle
412	// in the same manner as validation expressions.
413	//
414	// The exact matching logic is (in order):
415	// 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
416	// 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
417	// 3. If any matchCondition evaluates to an error (but none are FALSE):
418	// - If failurePolicy=Fail, reject the request
419	// - If failurePolicy=Ignore, the policy is skipped
420	"matchConditions"?: [...#MatchCondition]
421
422	// matchConstraints specifies what resources this policy is designed to
423	// validate. The MutatingAdmissionPolicy cares about a request if it matches
424	// _all_ Constraints. However, in order to prevent clusters from being put into
425	// an unstable state that cannot be recovered from via the API
426	// MutatingAdmissionPolicy cannot match MutatingAdmissionPolicy and
427	// MutatingAdmissionPolicyBinding. The CREATE, UPDATE and CONNECT operations
428	// are allowed. The DELETE operation may not be matched. '*' matches CREATE,
429	// UPDATE and CONNECT. Required.
430	"matchConstraints"?: #MatchResources
431
432	// mutations contain operations to perform on matching objects. mutations may
433	// not be empty; a minimum of one mutation is required. mutations are evaluated
434	// in order, and are reinvoked according to the reinvocationPolicy. The
435	// mutations of a policy are invoked for each binding of this policy and
436	// reinvocation of mutations occurs on a per binding basis.
437	"mutations"?: [...#Mutation]
438
439	// paramKind specifies the kind of resources used to parameterize this policy.
440	// If absent, there are no parameters for this policy and the param CEL
441	// variable will not be provided to validation expressions. If paramKind refers
442	// to a non-existent kind, this policy definition is mis-configured and the
443	// FailurePolicy is applied. If paramKind is specified but paramRef is unset in
444	// MutatingAdmissionPolicyBinding, the params variable will be null.
445	"paramKind"?: #ParamKind
446
447	// reinvocationPolicy indicates whether mutations may be called multiple times
448	// per MutatingAdmissionPolicyBinding as part of a single admission evaluation.
449	// Allowed values are "Never" and "IfNeeded".
450	//
451	// Never: These mutations will not be called more than once per binding in a
452	// single admission evaluation.
453	//
454	// IfNeeded: These mutations may be invoked more than once per binding for a
455	// single admission request and there is no guarantee of order with respect to
456	// other admission plugins, admission webhooks, bindings of this policy and
457	// admission policies. Mutations are only reinvoked when mutations change the
458	// object after this mutation is invoked. Required.
459	"reinvocationPolicy"?: string
460
461	// variables contain definitions of variables that can be used in composition of
462	// other expressions. Each variable is defined as a named CEL expression. The
463	// variables defined here will be available under `variables` in other
464	// expressions of the policy except matchConditions because matchConditions are
465	// evaluated before the rest of the policy.
466	//
467	// The expression of a variable can refer to other variables defined earlier in
468	// the list but not those after. Thus, variables must be sorted by the order of
469	// first appearance and acyclic.
470	"variables"?: [...#Variable]
471}
472
473// Mutation specifies the CEL expression which is used to apply the Mutation.
474#Mutation: {
475	// applyConfiguration defines the desired configuration values of an object. The
476	// configuration is applied to the admission object using [structured merge
477	// diff](https://github.com/kubernetes-sigs/structured-merge-diff). A CEL
478	// expression is used to create apply configuration.
479	"applyConfiguration"?: #ApplyConfiguration
480
481	// jsonPatch defines a [JSON patch](https://jsonpatch.com/) operation to perform
482	// a mutation to the object. A CEL expression is used to create the JSON patch.
483	"jsonPatch"?: #JSONPatch
484
485	// patchType indicates the patch strategy used. Allowed values are
486	// "ApplyConfiguration" and "JSONPatch". Required.
487	"patchType"!: string
488}
489
490// NamedRuleWithOperations is a tuple of Operations and Resources with ResourceNames.
491#NamedRuleWithOperations: {
492	// apiGroups is the API groups the resources belong to. '*' is all groups. If
493	// '*' is present, the length of the slice must be one. Required.
494	"apiGroups"?: [...string]
495
496	// apiVersions is the API versions the resources belong to. '*' is all versions.
497	// If '*' is present, the length of the slice must be one. Required.
498	"apiVersions"?: [...string]
499
500	// operations is the operations the admission hook cares about - CREATE, UPDATE,
501	// DELETE, CONNECT or * for all of those operations and any future admission
502	// operations that are added. If '*' is present, the length of the slice must
503	// be one. Required.
504	"operations"?: [...string]
505
506	// resourceNames is an optional white list of names that the rule applies to. An
507	// empty set means that everything is allowed.
508	"resourceNames"?: [...string]
509
510	// resources is a list of resources this rule applies to.
511	//
512	// For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
513	// '*' means all resources, but not subresources. 'pods/*' means all
514	// subresources of pods. '*/scale' means all scale subresources. '*/*' means
515	// all resources and their subresources.
516	//
517	// If wildcard is present, the validation rule will ensure resources do not overlap with each other.
518	//
519	// Depending on the enclosing object, subresources might not be allowed. Required.
520	"resources"?: [...string]
521
522	// scope specifies the scope of this rule. Valid values are "Cluster",
523	// "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
524	// will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
525	// means that only namespaced resources will match this rule. "*" means that
526	// there are no scope restrictions. Subresources match the scope of their
527	// parent resource. Default is "*".
528	"scope"?: string
529}
530
531// ParamKind is a tuple of Group Kind and Version.
532#ParamKind: {
533	// apiVersion is the API group version the resources belong to. In format of
534	// "group/version". Required.
535	"apiVersion"?: string
536
537	// kind is the API kind the resources belong to. Required.
538	"kind"?: string
539}
540
541// ParamRef describes how to locate the params to be used as input to
542// expressions of rules applied by a policy binding.
543#ParamRef: {
544	// name is the name of the resource being referenced.
545	//
546	// `name` and `selector` are mutually exclusive properties. If one is set, the other must be unset.
547	"name"?: string
548
549	// namespace is the namespace of the referenced resource. Allows limiting the
550	// search for params to a specific namespace. Applies to both `name` and
551	// `selector` fields.
552	//
553	// A per-namespace parameter may be used by specifying a namespace-scoped
554	// `paramKind` in the policy and leaving this field empty.
555	//
556	// - If `paramKind` is cluster-scoped, this field MUST be unset. Setting this
557	// field results in a configuration error.
558	//
559	// - If `paramKind` is namespace-scoped, the namespace of the object being
560	// evaluated for admission will be used when this field is left unset. Take
561	// care that if this is left empty the binding must not match any
562	// cluster-scoped resources, which will result in an error.
563	"namespace"?: string
564
565	// parameterNotFoundAction controls the behavior of the binding when the
566	// resource exists, and name or selector is valid, but there are no parameters
567	// matched by the binding. If the value is set to `Allow`, then no matched
568	// parameters will be treated as successful validation by the binding. If set
569	// to `Deny`, then no matched parameters will be subject to the `failurePolicy`
570	// of the policy.
571	//
572	// Allowed values are `Allow` or `Deny` Default to `Deny`
573	"parameterNotFoundAction"?: string
574
575	// selector can be used to match multiple param objects based on their labels.
576	// Supply selector: {} to match all resources of the ParamKind.
577	//
578	// If multiple params are found, they are all evaluated with the policy
579	// expressions and the results are ANDed together.
580	//
581	// One of `name` or `selector` must be set, but `name` and `selector` are
582	// mutually exclusive properties. If one is set, the other must be unset.
583	"selector"?: v1.#LabelSelector
584}
585
586// Variable is the definition of a variable that is used for composition.
587#Variable: {
588	// expression is the expression that will be evaluated as the value of the
589	// variable. The CEL expression has access to the same identifiers as the CEL
590	// expressions in Validation.
591	"expression"!: string
592
593	// name is the name of the variable. The name must be a valid CEL identifier and
594	// unique among all variables. The variable can be accessed in other
595	// expressions through `variables` For example, if name is "foo", the variable
596	// will be available as `variables.foo`
597	"name"!: string
598}