1package v1beta1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// ApplyConfiguration defines the desired configuration values of an object.
6#ApplyConfiguration: {
7 // expression will be evaluated by CEL to create an apply configuration. ref:
8 // https://github.com/google/cel-spec
9 //
10 // Apply configurations are declared in CEL using object initialization. For
11 // example, this CEL expression returns an apply configuration to set a single
12 // field:
13 //
14 // Object{
15 // spec: Object.spec{
16 // serviceAccountName: "example"
17 // }
18 // }
19 //
20 // Apply configurations may not modify atomic structs, maps or arrays due to the
21 // risk of accidental deletion of values not included in the apply
22 // configuration.
23 //
24 // CEL expressions have access to the object types needed to create apply configurations:
25 //
26 // - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
27 // type of object field (such as 'Object.spec') -
28 // 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
29 // (such as 'Object.spec.containers')
30 //
31 // CEL expressions have access to the contents of the API request, organized
32 // into CEL variables as well as some other useful variables:
33 //
34 // - 'object' - The object from the incoming request. The value is null for
35 // DELETE requests. - 'oldObject' - The existing object. The value is null for
36 // CREATE requests. - 'request' - Attributes of the API
37 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
38 // Parameter resource referred to by the policy binding being evaluated. Only
39 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
40 // object that the incoming object belongs to. The value is null for
41 // cluster-scoped resources. - 'variables' - Map of composited variables, from
42 // its name to its lazily evaluated value.
43 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
44 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
45 // checks for the principal (user or service account) of the request.
46 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
47 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
48 // 'authorizer' and configured with the
49 // request resource.
50 //
51 // The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
52 // always accessible from the root of the object. No other metadata properties
53 // are accessible.
54 //
55 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
56 "expression"?: string
57}
58
59// JSONPatch defines a JSON Patch.
60#JSONPatch: {
61 // expression will be evaluated by CEL to create a [JSON
62 // patch](https://jsonpatch.com/). ref: https://github.com/google/cel-spec
63 //
64 // expression must return an array of JSONPatch values.
65 //
66 // For example, this CEL expression returns a JSON patch to conditionally modify a value:
67 //
68 // [
69 // JSONPatch{op: "test", path: "/spec/example", value: "Red"},
70 // JSONPatch{op: "replace", path: "/spec/example", value: "Green"}
71 // ]
72 //
73 // To define an object for the patch value, use Object types. For example:
74 //
75 // [
76 // JSONPatch{
77 // op: "add",
78 // path: "/spec/selector",
79 // value: Object.spec.selector{matchLabels: {"environment": "test"}}
80 // }
81 // ]
82 //
83 // To use strings containing '/' and '~' as JSONPatch path keys, use
84 // "jsonpatch.escapeKey". For example:
85 //
86 // [
87 // JSONPatch{
88 // op: "add",
89 // path: "/metadata/labels/" + jsonpatch.escapeKey("example.com/environment"),
90 // value: "test"
91 // },
92 // ]
93 //
94 // CEL expressions have access to the types needed to create JSON patches and objects:
95 //
96 // - 'JSONPatch' - CEL type of JSON Patch operations. JSONPatch has the fields
97 // 'op', 'from', 'path' and 'value'.
98 // See [JSON patch](https://jsonpatch.com/) for more details. The 'value' field
99 // may be set to any of: string,
100 // integer, array, map or object. If set, the 'path' and 'from' fields must be set to a
101 // [JSON pointer](https://datatracker.ietf.org/doc/html/rfc6901/) string, where
102 // the 'jsonpatch.escapeKey()' CEL
103 // function may be used to escape path keys containing '/' and '~'.
104 // - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
105 // type of object field (such as 'Object.spec') -
106 // 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
107 // (such as 'Object.spec.containers')
108 //
109 // CEL expressions have access to the contents of the API request, organized
110 // into CEL variables as well as some other useful variables:
111 //
112 // - 'object' - The object from the incoming request. The value is null for
113 // DELETE requests. - 'oldObject' - The existing object. The value is null for
114 // CREATE requests. - 'request' - Attributes of the API
115 // request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
116 // Parameter resource referred to by the policy binding being evaluated. Only
117 // populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
118 // object that the incoming object belongs to. The value is null for
119 // cluster-scoped resources. - 'variables' - Map of composited variables, from
120 // its name to its lazily evaluated value.
121 // For example, a variable named 'foo' can be accessed as 'variables.foo'.
122 // - 'authorizer' - A CEL Authorizer. May be used to perform authorization
123 // checks for the principal (user or service account) of the request.
124 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
125 // - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
126 // 'authorizer' and configured with the
127 // request resource.
128 //
129 // CEL expressions have access to [Kubernetes CEL function
130 // libraries](https://kubernetes.io/docs/reference/using-api/cel/#cel-options-language-features-and-libraries)
131 // as well as:
132 //
133 // - 'jsonpatch.escapeKey' - Performs JSONPatch key escaping. '~' and '/' are
134 // escaped as '~0' and `~1' respectively).
135 //
136 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
137 "expression"?: string
138}
139
140// MatchCondition represents a condition which must be fulfilled for a request
141// to be sent to a webhook.
142#MatchCondition: {
143 // expression represents the expression which will be evaluated by CEL. Must
144 // evaluate to bool. CEL expressions have access to the contents of the
145 // AdmissionRequest and Authorizer, organized into CEL variables:
146 //
147 // 'object' - The object from the incoming request. The value is null for DELETE
148 // requests. 'oldObject' - The existing object. The value is null for CREATE
149 // requests. 'request' - Attributes of the admission
150 // request(/pkg/apis/admission/types.go#AdmissionRequest). 'authorizer' - A CEL
151 // Authorizer. May be used to perform authorization checks for the principal
152 // (user or service account) of the request.
153 // See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
154 // 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
155 // 'authorizer' and configured with the
156 // request resource.
157 // Documentation on CEL: https://kubernetes.io/docs/reference/using-api/cel/
158 //
159 // Required.
160 "expression"!: string
161
162 // name is an identifier for this match condition, used for strategic merging of
163 // MatchConditions, as well as providing an identifier for logging purposes. A
164 // good name should be descriptive of the associated expression. Name must be a
165 // qualified name consisting of alphanumeric characters, '-', '_' or '.', and
166 // must start and end with an alphanumeric character (e.g. 'MyName', or
167 // 'my.name', or '123-abc', regex used for validation is
168 // '([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]') with an optional DNS subdomain
169 // prefix and '/' (e.g. 'example.com/MyName')
170 //
171 // Required.
172 "name"!: string
173}
174
175// MatchResources decides whether to run the admission control policy on an
176// object based on whether it meets the match criteria. The exclude rules take
177// precedence over include rules (if a resource matches both, it is excluded)
178#MatchResources: {
179 // excludeResourceRules describes what operations on what resources/subresources
180 // the ValidatingAdmissionPolicy should not care about. The exclude rules take
181 // precedence over include rules (if a resource matches both, it is excluded)
182 "excludeResourceRules"?: [...#NamedRuleWithOperations]
183
184 // matchPolicy defines how the "MatchResources" list is used to match incoming
185 // requests. Allowed values are "Exact" or "Equivalent".
186 //
187 // - Exact: match a request only if it exactly matches a specified rule. For
188 // example, if deployments can be modified via apps/v1, apps/v1beta1, and
189 // extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
190 // apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
191 // or extensions/v1beta1 would not be sent to the ValidatingAdmissionPolicy.
192 //
193 // - Equivalent: match a request if modifies a resource listed in rules, even
194 // via another API group or version. For example, if deployments can be
195 // modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
196 // included `apiGroups:["apps"], apiVersions:["v1"], resources:
197 // ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
198 // converted to apps/v1 and sent to the ValidatingAdmissionPolicy.
199 //
200 // Defaults to "Equivalent"
201 "matchPolicy"?: string
202
203 // namespaceSelector decides whether to run the admission control policy on an
204 // object based on whether the namespace for that object matches the selector.
205 // If the object itself is a namespace, the matching is performed on
206 // object.metadata.labels. If the object is another cluster scoped resource, it
207 // never skips the policy.
208 //
209 // For example, to run the webhook on any objects whose namespace is not
210 // associated with "runlevel" of "0" or "1"; you will set the selector as
211 // follows: "namespaceSelector": {
212 // "matchExpressions": [
213 // {
214 // "key": "runlevel",
215 // "operator": "NotIn",
216 // "values": [
217 // "0",
218 // "1"
219 // ]
220 // }
221 // ]
222 // }
223 //
224 // If instead you want to only run the policy on any objects whose namespace is
225 // associated with the "environment" of "prod" or "staging"; you will set the
226 // selector as follows: "namespaceSelector": {
227 // "matchExpressions": [
228 // {
229 // "key": "environment",
230 // "operator": "In",
231 // "values": [
232 // "prod",
233 // "staging"
234 // ]
235 // }
236 // ]
237 // }
238 //
239 // See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
240 // for more examples of label selectors.
241 //
242 // Default to the empty LabelSelector, which matches everything.
243 "namespaceSelector"?: v1.#LabelSelector
244
245 // objectSelector decides whether to run the validation based on if the object
246 // has matching labels. objectSelector is evaluated against both the oldObject
247 // and newObject that would be sent to the cel validation, and is considered to
248 // match if either object matches the selector. A null object (oldObject in the
249 // case of create, or newObject in the case of delete) or an object that cannot
250 // have labels (like a DeploymentRollback or a PodProxyOptions object) is not
251 // considered to match. Use the object selector only if the webhook is opt-in,
252 // because end users may skip the admission webhook by setting the labels.
253 // Default to the empty LabelSelector, which matches everything.
254 "objectSelector"?: v1.#LabelSelector
255
256 // resourceRules describes what operations on what resources/subresources the
257 // ValidatingAdmissionPolicy matches. The policy cares about an operation if it
258 // matches _any_ Rule.
259 "resourceRules"?: [...#NamedRuleWithOperations]
260}
261
262// MutatingAdmissionPolicy describes the definition of an admission mutation
263// policy that mutates the object coming into admission chain.
264#MutatingAdmissionPolicy: {
265 // APIVersion defines the versioned schema of this representation of an object.
266 // Servers should convert recognized schemas to the latest internal value, and
267 // may reject unrecognized values. More info:
268 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
269 "apiVersion": "admissionregistration.k8s.io/v1beta1"
270
271 // Kind is a string value representing the REST resource this object represents.
272 // Servers may infer this from the endpoint the client submits requests to.
273 // Cannot be updated. In CamelCase. More info:
274 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
275 "kind": "MutatingAdmissionPolicy"
276
277 // metadata is the standard object metadata; More info:
278 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
279 "metadata"?: v1.#ObjectMeta
280
281 // spec defines the desired behavior of the MutatingAdmissionPolicy.
282 "spec"?: #MutatingAdmissionPolicySpec
283}
284
285// MutatingAdmissionPolicyBinding binds the MutatingAdmissionPolicy with
286// parametrized resources. MutatingAdmissionPolicyBinding and the optional
287// parameter resource together define how cluster administrators configure
288// policies for clusters.
289//
290// For a given admission request, each binding will cause its policy to be
291// evaluated N times, where N is 1 for policies/bindings that don't use params,
292// otherwise N is the number of parameters selected by the binding. Each
293// evaluation is constrained by a [runtime cost
294// budget](https://kubernetes.io/docs/reference/using-api/cel/#runtime-cost-budget).
295//
296// Adding/removing policies, bindings, or params can not affect whether a given
297// (policy, binding, param) combination is within its own CEL budget.
298#MutatingAdmissionPolicyBinding: {
299 // APIVersion defines the versioned schema of this representation of an object.
300 // Servers should convert recognized schemas to the latest internal value, and
301 // may reject unrecognized values. More info:
302 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
303 "apiVersion": "admissionregistration.k8s.io/v1beta1"
304
305 // Kind is a string value representing the REST resource this object represents.
306 // Servers may infer this from the endpoint the client submits requests to.
307 // Cannot be updated. In CamelCase. More info:
308 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
309 "kind": "MutatingAdmissionPolicyBinding"
310
311 // metadata is the standard object metadata; More info:
312 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
313 "metadata"?: v1.#ObjectMeta
314
315 // spec defines the desired behavior of the MutatingAdmissionPolicyBinding.
316 "spec"?: #MutatingAdmissionPolicyBindingSpec
317}
318
319// MutatingAdmissionPolicyBindingList is a list of MutatingAdmissionPolicyBinding.
320#MutatingAdmissionPolicyBindingList: {
321 // APIVersion defines the versioned schema of this representation of an object.
322 // Servers should convert recognized schemas to the latest internal value, and
323 // may reject unrecognized values. More info:
324 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
325 "apiVersion": "admissionregistration.k8s.io/v1beta1"
326
327 // List of PolicyBinding.
328 "items"!: [...#MutatingAdmissionPolicyBinding]
329
330 // Kind is a string value representing the REST resource this object represents.
331 // Servers may infer this from the endpoint the client submits requests to.
332 // Cannot be updated. In CamelCase. More info:
333 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
334 "kind": "MutatingAdmissionPolicyBindingList"
335
336 // metadata is the standard list metadata. More info:
337 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
338 "metadata"?: v1.#ListMeta
339}
340
341// MutatingAdmissionPolicyBindingSpec is the specification of the MutatingAdmissionPolicyBinding.
342#MutatingAdmissionPolicyBindingSpec: {
343 // matchResources limits what resources match this binding and may be mutated by
344 // it. Note that if matchResources matches a resource, the resource must also
345 // match a policy's matchConstraints and matchConditions before the resource
346 // may be mutated. When matchResources is unset, it does not constrain resource
347 // matching, and only the policy's matchConstraints and matchConditions must
348 // match for the resource to be mutated. Additionally,
349 // matchResources.resourceRules are optional and do not constraint matching
350 // when unset. Note that this is differs from MutatingAdmissionPolicy
351 // matchConstraints, where resourceRules are required. The CREATE, UPDATE and
352 // CONNECT operations are allowed. The DELETE operation may not be matched. '*'
353 // matches CREATE, UPDATE and CONNECT.
354 "matchResources"?: #MatchResources
355
356 // paramRef specifies the parameter resource used to configure the admission
357 // control policy. It should point to a resource of the type specified in
358 // spec.ParamKind of the bound MutatingAdmissionPolicy. If the policy specifies
359 // a ParamKind and the resource referred to by ParamRef does not exist, this
360 // binding is considered mis-configured and the FailurePolicy of the
361 // MutatingAdmissionPolicy applied. If the policy does not specify a ParamKind
362 // then this field is ignored, and the rules are evaluated without a param.
363 "paramRef"?: #ParamRef
364
365 // policyName references a MutatingAdmissionPolicy name which the
366 // MutatingAdmissionPolicyBinding binds to. If the referenced resource does not
367 // exist, this binding is considered invalid and will be ignored Required.
368 "policyName"?: string
369}
370
371// MutatingAdmissionPolicyList is a list of MutatingAdmissionPolicy.
372#MutatingAdmissionPolicyList: {
373 // APIVersion defines the versioned schema of this representation of an object.
374 // Servers should convert recognized schemas to the latest internal value, and
375 // may reject unrecognized values. More info:
376 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
377 "apiVersion": "admissionregistration.k8s.io/v1beta1"
378
379 // List of ValidatingAdmissionPolicy.
380 "items"!: [...#MutatingAdmissionPolicy]
381
382 // Kind is a string value representing the REST resource this object represents.
383 // Servers may infer this from the endpoint the client submits requests to.
384 // Cannot be updated. In CamelCase. More info:
385 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
386 "kind": "MutatingAdmissionPolicyList"
387
388 // metadata is the standard list metadata. More info:
389 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
390 "metadata"?: v1.#ListMeta
391}
392
393// MutatingAdmissionPolicySpec is the specification of the desired behavior of the admission policy.
394#MutatingAdmissionPolicySpec: {
395 // failurePolicy defines how to handle failures for the admission policy.
396 // Failures can occur from CEL expression parse errors, type check errors,
397 // runtime errors and invalid or mis-configured policy definitions or bindings.
398 //
399 // A policy is invalid if paramKind refers to a non-existent Kind. A binding is
400 // invalid if paramRef.name refers to a non-existent resource.
401 //
402 // failurePolicy does not define how validations that evaluate to false are handled.
403 //
404 // Allowed values are Ignore or Fail. Defaults to Fail.
405 "failurePolicy"?: string
406
407 // matchConditions is a list of conditions that must be met for a request to be
408 // validated. Match conditions filter requests that have already been matched
409 // by the matchConstraints. An empty list of matchConditions matches all
410 // requests. There are a maximum of 64 match conditions allowed.
411 //
412 // If a parameter object is provided, it can be accessed via the `params` handle
413 // in the same manner as validation expressions.
414 //
415 // The exact matching logic is (in order):
416 // 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
417 // 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
418 // 3. If any matchCondition evaluates to an error (but none are FALSE):
419 // - If failurePolicy=Fail, reject the request
420 // - If failurePolicy=Ignore, the policy is skipped
421 "matchConditions"?: [...#MatchCondition]
422
423 // matchConstraints specifies what resources this policy is designed to
424 // validate. The MutatingAdmissionPolicy cares about a request if it matches
425 // _all_ Constraints. However, in order to prevent clusters from being put into
426 // an unstable state that cannot be recovered from via the API
427 // MutatingAdmissionPolicy cannot match MutatingAdmissionPolicy and
428 // MutatingAdmissionPolicyBinding. The CREATE, UPDATE and CONNECT operations
429 // are allowed. The DELETE operation may not be matched. '*' matches CREATE,
430 // UPDATE and CONNECT. Required.
431 "matchConstraints"?: #MatchResources
432
433 // mutations contain operations to perform on matching objects. mutations may
434 // not be empty; a minimum of one mutation is required. mutations are evaluated
435 // in order, and are reinvoked according to the reinvocationPolicy. The
436 // mutations of a policy are invoked for each binding of this policy and
437 // reinvocation of mutations occurs on a per binding basis.
438 "mutations"?: [...#Mutation]
439
440 // paramKind specifies the kind of resources used to parameterize this policy.
441 // If absent, there are no parameters for this policy and the param CEL
442 // variable will not be provided to validation expressions. If paramKind refers
443 // to a non-existent kind, this policy definition is mis-configured and the
444 // FailurePolicy is applied. If paramKind is specified but paramRef is unset in
445 // MutatingAdmissionPolicyBinding, the params variable will be null.
446 "paramKind"?: #ParamKind
447
448 // reinvocationPolicy indicates whether mutations may be called multiple times
449 // per MutatingAdmissionPolicyBinding as part of a single admission evaluation.
450 // Allowed values are "Never" and "IfNeeded".
451 //
452 // Never: These mutations will not be called more than once per binding in a
453 // single admission evaluation.
454 //
455 // IfNeeded: These mutations may be invoked more than once per binding for a
456 // single admission request and there is no guarantee of order with respect to
457 // other admission plugins, admission webhooks, bindings of this policy and
458 // admission policies. Mutations are only reinvoked when mutations change the
459 // object after this mutation is invoked. Required.
460 "reinvocationPolicy"?: string
461
462 // variables contain definitions of variables that can be used in composition of
463 // other expressions. Each variable is defined as a named CEL expression. The
464 // variables defined here will be available under `variables` in other
465 // expressions of the policy except matchConditions because matchConditions are
466 // evaluated before the rest of the policy.
467 //
468 // The expression of a variable can refer to other variables defined earlier in
469 // the list but not those after. Thus, variables must be sorted by the order of
470 // first appearance and acyclic.
471 "variables"?: [...#Variable]
472}
473
474// Mutation specifies the CEL expression which is used to apply the Mutation.
475#Mutation: {
476 // applyConfiguration defines the desired configuration values of an object. The
477 // configuration is applied to the admission object using [structured merge
478 // diff](https://github.com/kubernetes-sigs/structured-merge-diff). A CEL
479 // expression is used to create apply configuration.
480 "applyConfiguration"?: #ApplyConfiguration
481
482 // jsonPatch defines a [JSON patch](https://jsonpatch.com/) operation to perform
483 // a mutation to the object. A CEL expression is used to create the JSON patch.
484 "jsonPatch"?: #JSONPatch
485
486 // patchType indicates the patch strategy used. Allowed values are
487 // "ApplyConfiguration" and "JSONPatch". Required.
488 "patchType"!: string
489}
490
491// NamedRuleWithOperations is a tuple of Operations and Resources with ResourceNames.
492#NamedRuleWithOperations: {
493 // apiGroups is the API groups the resources belong to. '*' is all groups. If
494 // '*' is present, the length of the slice must be one. Required.
495 "apiGroups"?: [...string]
496
497 // apiVersions is the API versions the resources belong to. '*' is all versions.
498 // If '*' is present, the length of the slice must be one. Required.
499 "apiVersions"?: [...string]
500
501 // operations is the operations the admission hook cares about - CREATE, UPDATE,
502 // DELETE, CONNECT or * for all of those operations and any future admission
503 // operations that are added. If '*' is present, the length of the slice must
504 // be one. Required.
505 "operations"?: [...string]
506
507 // resourceNames is an optional white list of names that the rule applies to. An
508 // empty set means that everything is allowed.
509 "resourceNames"?: [...string]
510
511 // resources is a list of resources this rule applies to.
512 //
513 // For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
514 // '*' means all resources, but not subresources. 'pods/*' means all
515 // subresources of pods. '*/scale' means all scale subresources. '*/*' means
516 // all resources and their subresources.
517 //
518 // If wildcard is present, the validation rule will ensure resources do not overlap with each other.
519 //
520 // Depending on the enclosing object, subresources might not be allowed. Required.
521 "resources"?: [...string]
522
523 // scope specifies the scope of this rule. Valid values are "Cluster",
524 // "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
525 // will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
526 // means that only namespaced resources will match this rule. "*" means that
527 // there are no scope restrictions. Subresources match the scope of their
528 // parent resource. Default is "*".
529 "scope"?: string
530}
531
532// ParamKind is a tuple of Group Kind and Version.
533#ParamKind: {
534 // apiVersion is the API group version the resources belong to. In format of
535 // "group/version". Required.
536 "apiVersion"?: string
537
538 // kind is the API kind the resources belong to. Required.
539 "kind"?: string
540}
541
542// ParamRef describes how to locate the params to be used as input to
543// expressions of rules applied by a policy binding.
544#ParamRef: {
545 // name is the name of the resource being referenced.
546 //
547 // One of `name` or `selector` must be set, but `name` and `selector` are
548 // mutually exclusive properties. If one is set, the other must be unset.
549 //
550 // A single parameter used for all admission requests can be configured by
551 // setting the `name` field, leaving `selector` blank, and setting namespace if
552 // `paramKind` is namespace-scoped.
553 "name"?: string
554
555 // namespace is the namespace of the referenced resource. Allows limiting the
556 // search for params to a specific namespace. Applies to both `name` and
557 // `selector` fields.
558 //
559 // A per-namespace parameter may be used by specifying a namespace-scoped
560 // `paramKind` in the policy and leaving this field empty.
561 //
562 // - If `paramKind` is cluster-scoped, this field MUST be unset. Setting this
563 // field results in a configuration error.
564 //
565 // - If `paramKind` is namespace-scoped, the namespace of the object being
566 // evaluated for admission will be used when this field is left unset. Take
567 // care that if this is left empty the binding must not match any
568 // cluster-scoped resources, which will result in an error.
569 "namespace"?: string
570
571 // parameterNotFoundAction controls the behavior of the binding when the
572 // resource exists, and name or selector is valid, but there are no parameters
573 // matched by the binding. If the value is set to `Allow`, then no matched
574 // parameters will be treated as successful validation by the binding. If set
575 // to `Deny`, then no matched parameters will be subject to the `failurePolicy`
576 // of the policy.
577 //
578 // Allowed values are `Allow` or `Deny`
579 //
580 // Required
581 "parameterNotFoundAction"?: string
582
583 // selector can be used to match multiple param objects based on their labels.
584 // Supply selector: {} to match all resources of the ParamKind.
585 //
586 // If multiple params are found, they are all evaluated with the policy
587 // expressions and the results are ANDed together.
588 //
589 // One of `name` or `selector` must be set, but `name` and `selector` are
590 // mutually exclusive properties. If one is set, the other must be unset.
591 "selector"?: v1.#LabelSelector
592}
593
594// Variable is the definition of a variable that is used for composition. A
595// variable is defined as a named expression.
596#Variable: {
597 // expression is the expression that will be evaluated as the value of the
598 // variable. The CEL expression has access to the same identifiers as the CEL
599 // expressions in Validation.
600 "expression"!: string
601
602 // name is the name of the variable. The name must be a valid CEL identifier and
603 // unique among all variables. The variable can be accessed in other
604 // expressions through `variables` For example, if name is "foo", the variable
605 // will be available as `variables.foo`
606 "name"!: string
607}