cue.dev/x/k8s.io@v0.12.0

api/admissionregistration/v1beta1/schema.cue raw

  1package v1beta1
  2
  3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
  4
  5// ApplyConfiguration defines the desired configuration values of an object.
  6#ApplyConfiguration: {
  7	// expression will be evaluated by CEL to create an apply configuration. ref:
  8	// https://github.com/google/cel-spec
  9	//
 10	// Apply configurations are declared in CEL using object initialization. For
 11	// example, this CEL expression returns an apply configuration to set a single
 12	// field:
 13	//
 14	// Object{
 15	// spec: Object.spec{
 16	// serviceAccountName: "example"
 17	// }
 18	// }
 19	//
 20	// Apply configurations may not modify atomic structs, maps or arrays due to the
 21	// risk of accidental deletion of values not included in the apply
 22	// configuration.
 23	//
 24	// CEL expressions have access to the object types needed to create apply configurations:
 25	//
 26	// - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
 27	// type of object field (such as 'Object.spec') -
 28	// 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
 29	// (such as 'Object.spec.containers')
 30	//
 31	// CEL expressions have access to the contents of the API request, organized
 32	// into CEL variables as well as some other useful variables:
 33	//
 34	// - 'object' - The object from the incoming request. The value is null for
 35	// DELETE requests. - 'oldObject' - The existing object. The value is null for
 36	// CREATE requests. - 'request' - Attributes of the API
 37	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
 38	// Parameter resource referred to by the policy binding being evaluated. Only
 39	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
 40	// object that the incoming object belongs to. The value is null for
 41	// cluster-scoped resources. - 'variables' - Map of composited variables, from
 42	// its name to its lazily evaluated value.
 43	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
 44	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
 45	// checks for the principal (user or service account) of the request.
 46	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
 47	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
 48	// 'authorizer' and configured with the
 49	// request resource.
 50	//
 51	// The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
 52	// always accessible from the root of the object. No other metadata properties
 53	// are accessible.
 54	//
 55	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
 56	"expression"?: string
 57}
 58
 59// JSONPatch defines a JSON Patch.
 60#JSONPatch: {
 61	// expression will be evaluated by CEL to create a [JSON
 62	// patch](https://jsonpatch.com/). ref: https://github.com/google/cel-spec
 63	//
 64	// expression must return an array of JSONPatch values.
 65	//
 66	// For example, this CEL expression returns a JSON patch to conditionally modify a value:
 67	//
 68	// [
 69	// JSONPatch{op: "test", path: "/spec/example", value: "Red"},
 70	// JSONPatch{op: "replace", path: "/spec/example", value: "Green"}
 71	// ]
 72	//
 73	// To define an object for the patch value, use Object types. For example:
 74	//
 75	// [
 76	// JSONPatch{
 77	// op: "add",
 78	// path: "/spec/selector",
 79	// value: Object.spec.selector{matchLabels: {"environment": "test"}}
 80	// }
 81	// ]
 82	//
 83	// To use strings containing '/' and '~' as JSONPatch path keys, use
 84	// "jsonpatch.escapeKey". For example:
 85	//
 86	// [
 87	// JSONPatch{
 88	// op: "add",
 89	// path: "/metadata/labels/" + jsonpatch.escapeKey("example.com/environment"),
 90	// value: "test"
 91	// },
 92	// ]
 93	//
 94	// CEL expressions have access to the types needed to create JSON patches and objects:
 95	//
 96	// - 'JSONPatch' - CEL type of JSON Patch operations. JSONPatch has the fields
 97	// 'op', 'from', 'path' and 'value'.
 98	// See [JSON patch](https://jsonpatch.com/) for more details. The 'value' field
 99	// may be set to any of: string,
100	// integer, array, map or object. If set, the 'path' and 'from' fields must be set to a
101	// [JSON pointer](https://datatracker.ietf.org/doc/html/rfc6901/) string, where
102	// the 'jsonpatch.escapeKey()' CEL
103	// function may be used to escape path keys containing '/' and '~'.
104	// - 'Object' - CEL type of the resource object. - 'Object.<fieldName>' - CEL
105	// type of object field (such as 'Object.spec') -
106	// 'Object.<fieldName1>.<fieldName2>...<fieldNameN>` - CEL type of nested field
107	// (such as 'Object.spec.containers')
108	//
109	// CEL expressions have access to the contents of the API request, organized
110	// into CEL variables as well as some other useful variables:
111	//
112	// - 'object' - The object from the incoming request. The value is null for
113	// DELETE requests. - 'oldObject' - The existing object. The value is null for
114	// CREATE requests. - 'request' - Attributes of the API
115	// request([ref](/pkg/apis/admission/types.go#AdmissionRequest)). - 'params' -
116	// Parameter resource referred to by the policy binding being evaluated. Only
117	// populated if the policy has a ParamKind. - 'namespaceObject' - The namespace
118	// object that the incoming object belongs to. The value is null for
119	// cluster-scoped resources. - 'variables' - Map of composited variables, from
120	// its name to its lazily evaluated value.
121	// For example, a variable named 'foo' can be accessed as 'variables.foo'.
122	// - 'authorizer' - A CEL Authorizer. May be used to perform authorization
123	// checks for the principal (user or service account) of the request.
124	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
125	// - 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
126	// 'authorizer' and configured with the
127	// request resource.
128	//
129	// CEL expressions have access to [Kubernetes CEL function
130	// libraries](https://kubernetes.io/docs/reference/using-api/cel/#cel-options-language-features-and-libraries)
131	// as well as:
132	//
133	// - 'jsonpatch.escapeKey' - Performs JSONPatch key escaping. '~' and '/' are
134	// escaped as '~0' and `~1' respectively).
135	//
136	// Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are accessible. Required.
137	"expression"?: string
138}
139
140// MatchCondition represents a condition which must be fulfilled for a request
141// to be sent to a webhook.
142#MatchCondition: {
143	// expression represents the expression which will be evaluated by CEL. Must
144	// evaluate to bool. CEL expressions have access to the contents of the
145	// AdmissionRequest and Authorizer, organized into CEL variables:
146	//
147	// 'object' - The object from the incoming request. The value is null for DELETE
148	// requests. 'oldObject' - The existing object. The value is null for CREATE
149	// requests. 'request' - Attributes of the admission
150	// request(/pkg/apis/admission/types.go#AdmissionRequest). 'authorizer' - A CEL
151	// Authorizer. May be used to perform authorization checks for the principal
152	// (user or service account) of the request.
153	// See https://pkg.go.dev/k8s.io/apiserver/pkg/cel/library#Authz
154	// 'authorizer.requestResource' - A CEL ResourceCheck constructed from the
155	// 'authorizer' and configured with the
156	// request resource.
157	// Documentation on CEL: https://kubernetes.io/docs/reference/using-api/cel/
158	//
159	// Required.
160	"expression"!: string
161
162	// name is an identifier for this match condition, used for strategic merging of
163	// MatchConditions, as well as providing an identifier for logging purposes. A
164	// good name should be descriptive of the associated expression. Name must be a
165	// qualified name consisting of alphanumeric characters, '-', '_' or '.', and
166	// must start and end with an alphanumeric character (e.g. 'MyName', or
167	// 'my.name', or '123-abc', regex used for validation is
168	// '([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]') with an optional DNS subdomain
169	// prefix and '/' (e.g. 'example.com/MyName')
170	//
171	// Required.
172	"name"!: string
173}
174
175// MatchResources decides whether to run the admission control policy on an
176// object based on whether it meets the match criteria. The exclude rules take
177// precedence over include rules (if a resource matches both, it is excluded)
178#MatchResources: {
179	// excludeResourceRules describes what operations on what resources/subresources
180	// the ValidatingAdmissionPolicy should not care about. The exclude rules take
181	// precedence over include rules (if a resource matches both, it is excluded)
182	"excludeResourceRules"?: [...#NamedRuleWithOperations]
183
184	// matchPolicy defines how the "MatchResources" list is used to match incoming
185	// requests. Allowed values are "Exact" or "Equivalent".
186	//
187	// - Exact: match a request only if it exactly matches a specified rule. For
188	// example, if deployments can be modified via apps/v1, apps/v1beta1, and
189	// extensions/v1beta1, but "rules" only included `apiGroups:["apps"],
190	// apiVersions:["v1"], resources: ["deployments"]`, a request to apps/v1beta1
191	// or extensions/v1beta1 would not be sent to the ValidatingAdmissionPolicy.
192	//
193	// - Equivalent: match a request if modifies a resource listed in rules, even
194	// via another API group or version. For example, if deployments can be
195	// modified via apps/v1, apps/v1beta1, and extensions/v1beta1, and "rules" only
196	// included `apiGroups:["apps"], apiVersions:["v1"], resources:
197	// ["deployments"]`, a request to apps/v1beta1 or extensions/v1beta1 would be
198	// converted to apps/v1 and sent to the ValidatingAdmissionPolicy.
199	//
200	// Defaults to "Equivalent"
201	"matchPolicy"?: string
202
203	// namespaceSelector decides whether to run the admission control policy on an
204	// object based on whether the namespace for that object matches the selector.
205	// If the object itself is a namespace, the matching is performed on
206	// object.metadata.labels. If the object is another cluster scoped resource, it
207	// never skips the policy.
208	//
209	// For example, to run the webhook on any objects whose namespace is not
210	// associated with "runlevel" of "0" or "1"; you will set the selector as
211	// follows: "namespaceSelector": {
212	// "matchExpressions": [
213	// {
214	// "key": "runlevel",
215	// "operator": "NotIn",
216	// "values": [
217	// "0",
218	// "1"
219	// ]
220	// }
221	// ]
222	// }
223	//
224	// If instead you want to only run the policy on any objects whose namespace is
225	// associated with the "environment" of "prod" or "staging"; you will set the
226	// selector as follows: "namespaceSelector": {
227	// "matchExpressions": [
228	// {
229	// "key": "environment",
230	// "operator": "In",
231	// "values": [
232	// "prod",
233	// "staging"
234	// ]
235	// }
236	// ]
237	// }
238	//
239	// See https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
240	// for more examples of label selectors.
241	//
242	// Default to the empty LabelSelector, which matches everything.
243	"namespaceSelector"?: v1.#LabelSelector
244
245	// objectSelector decides whether to run the validation based on if the object
246	// has matching labels. objectSelector is evaluated against both the oldObject
247	// and newObject that would be sent to the cel validation, and is considered to
248	// match if either object matches the selector. A null object (oldObject in the
249	// case of create, or newObject in the case of delete) or an object that cannot
250	// have labels (like a DeploymentRollback or a PodProxyOptions object) is not
251	// considered to match. Use the object selector only if the webhook is opt-in,
252	// because end users may skip the admission webhook by setting the labels.
253	// Default to the empty LabelSelector, which matches everything.
254	"objectSelector"?: v1.#LabelSelector
255
256	// resourceRules describes what operations on what resources/subresources the
257	// ValidatingAdmissionPolicy matches. The policy cares about an operation if it
258	// matches _any_ Rule.
259	"resourceRules"?: [...#NamedRuleWithOperations]
260}
261
262// MutatingAdmissionPolicy describes the definition of an admission mutation
263// policy that mutates the object coming into admission chain.
264#MutatingAdmissionPolicy: {
265	// APIVersion defines the versioned schema of this representation of an object.
266	// Servers should convert recognized schemas to the latest internal value, and
267	// may reject unrecognized values. More info:
268	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
269	"apiVersion": "admissionregistration.k8s.io/v1beta1"
270
271	// Kind is a string value representing the REST resource this object represents.
272	// Servers may infer this from the endpoint the client submits requests to.
273	// Cannot be updated. In CamelCase. More info:
274	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
275	"kind": "MutatingAdmissionPolicy"
276
277	// metadata is the standard object metadata; More info:
278	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
279	"metadata"?: v1.#ObjectMeta
280
281	// spec defines the desired behavior of the MutatingAdmissionPolicy.
282	"spec"?: #MutatingAdmissionPolicySpec
283}
284
285// MutatingAdmissionPolicyBinding binds the MutatingAdmissionPolicy with
286// parametrized resources. MutatingAdmissionPolicyBinding and the optional
287// parameter resource together define how cluster administrators configure
288// policies for clusters.
289//
290// For a given admission request, each binding will cause its policy to be
291// evaluated N times, where N is 1 for policies/bindings that don't use params,
292// otherwise N is the number of parameters selected by the binding. Each
293// evaluation is constrained by a [runtime cost
294// budget](https://kubernetes.io/docs/reference/using-api/cel/#runtime-cost-budget).
295//
296// Adding/removing policies, bindings, or params can not affect whether a given
297// (policy, binding, param) combination is within its own CEL budget.
298#MutatingAdmissionPolicyBinding: {
299	// APIVersion defines the versioned schema of this representation of an object.
300	// Servers should convert recognized schemas to the latest internal value, and
301	// may reject unrecognized values. More info:
302	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
303	"apiVersion": "admissionregistration.k8s.io/v1beta1"
304
305	// Kind is a string value representing the REST resource this object represents.
306	// Servers may infer this from the endpoint the client submits requests to.
307	// Cannot be updated. In CamelCase. More info:
308	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
309	"kind": "MutatingAdmissionPolicyBinding"
310
311	// metadata is the standard object metadata; More info:
312	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata.
313	"metadata"?: v1.#ObjectMeta
314
315	// spec defines the desired behavior of the MutatingAdmissionPolicyBinding.
316	"spec"?: #MutatingAdmissionPolicyBindingSpec
317}
318
319// MutatingAdmissionPolicyBindingList is a list of MutatingAdmissionPolicyBinding.
320#MutatingAdmissionPolicyBindingList: {
321	// APIVersion defines the versioned schema of this representation of an object.
322	// Servers should convert recognized schemas to the latest internal value, and
323	// may reject unrecognized values. More info:
324	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
325	"apiVersion": "admissionregistration.k8s.io/v1beta1"
326
327	// List of PolicyBinding.
328	"items"!: [...#MutatingAdmissionPolicyBinding]
329
330	// Kind is a string value representing the REST resource this object represents.
331	// Servers may infer this from the endpoint the client submits requests to.
332	// Cannot be updated. In CamelCase. More info:
333	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
334	"kind": "MutatingAdmissionPolicyBindingList"
335
336	// metadata is the standard list metadata. More info:
337	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
338	"metadata"?: v1.#ListMeta
339}
340
341// MutatingAdmissionPolicyBindingSpec is the specification of the MutatingAdmissionPolicyBinding.
342#MutatingAdmissionPolicyBindingSpec: {
343	// matchResources limits what resources match this binding and may be mutated by
344	// it. Note that if matchResources matches a resource, the resource must also
345	// match a policy's matchConstraints and matchConditions before the resource
346	// may be mutated. When matchResources is unset, it does not constrain resource
347	// matching, and only the policy's matchConstraints and matchConditions must
348	// match for the resource to be mutated. Additionally,
349	// matchResources.resourceRules are optional and do not constraint matching
350	// when unset. Note that this is differs from MutatingAdmissionPolicy
351	// matchConstraints, where resourceRules are required. The CREATE, UPDATE and
352	// CONNECT operations are allowed. The DELETE operation may not be matched. '*'
353	// matches CREATE, UPDATE and CONNECT.
354	"matchResources"?: #MatchResources
355
356	// paramRef specifies the parameter resource used to configure the admission
357	// control policy. It should point to a resource of the type specified in
358	// spec.ParamKind of the bound MutatingAdmissionPolicy. If the policy specifies
359	// a ParamKind and the resource referred to by ParamRef does not exist, this
360	// binding is considered mis-configured and the FailurePolicy of the
361	// MutatingAdmissionPolicy applied. If the policy does not specify a ParamKind
362	// then this field is ignored, and the rules are evaluated without a param.
363	"paramRef"?: #ParamRef
364
365	// policyName references a MutatingAdmissionPolicy name which the
366	// MutatingAdmissionPolicyBinding binds to. If the referenced resource does not
367	// exist, this binding is considered invalid and will be ignored Required.
368	"policyName"?: string
369}
370
371// MutatingAdmissionPolicyList is a list of MutatingAdmissionPolicy.
372#MutatingAdmissionPolicyList: {
373	// APIVersion defines the versioned schema of this representation of an object.
374	// Servers should convert recognized schemas to the latest internal value, and
375	// may reject unrecognized values. More info:
376	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
377	"apiVersion": "admissionregistration.k8s.io/v1beta1"
378
379	// List of ValidatingAdmissionPolicy.
380	"items"!: [...#MutatingAdmissionPolicy]
381
382	// Kind is a string value representing the REST resource this object represents.
383	// Servers may infer this from the endpoint the client submits requests to.
384	// Cannot be updated. In CamelCase. More info:
385	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
386	"kind": "MutatingAdmissionPolicyList"
387
388	// metadata is the standard list metadata. More info:
389	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
390	"metadata"?: v1.#ListMeta
391}
392
393// MutatingAdmissionPolicySpec is the specification of the desired behavior of the admission policy.
394#MutatingAdmissionPolicySpec: {
395	// failurePolicy defines how to handle failures for the admission policy.
396	// Failures can occur from CEL expression parse errors, type check errors,
397	// runtime errors and invalid or mis-configured policy definitions or bindings.
398	//
399	// A policy is invalid if paramKind refers to a non-existent Kind. A binding is
400	// invalid if paramRef.name refers to a non-existent resource.
401	//
402	// failurePolicy does not define how validations that evaluate to false are handled.
403	//
404	// Allowed values are Ignore or Fail. Defaults to Fail.
405	"failurePolicy"?: string
406
407	// matchConditions is a list of conditions that must be met for a request to be
408	// validated. Match conditions filter requests that have already been matched
409	// by the matchConstraints. An empty list of matchConditions matches all
410	// requests. There are a maximum of 64 match conditions allowed.
411	//
412	// If a parameter object is provided, it can be accessed via the `params` handle
413	// in the same manner as validation expressions.
414	//
415	// The exact matching logic is (in order):
416	// 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
417	// 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
418	// 3. If any matchCondition evaluates to an error (but none are FALSE):
419	// - If failurePolicy=Fail, reject the request
420	// - If failurePolicy=Ignore, the policy is skipped
421	"matchConditions"?: [...#MatchCondition]
422
423	// matchConstraints specifies what resources this policy is designed to
424	// validate. The MutatingAdmissionPolicy cares about a request if it matches
425	// _all_ Constraints. However, in order to prevent clusters from being put into
426	// an unstable state that cannot be recovered from via the API
427	// MutatingAdmissionPolicy cannot match MutatingAdmissionPolicy and
428	// MutatingAdmissionPolicyBinding. The CREATE, UPDATE and CONNECT operations
429	// are allowed. The DELETE operation may not be matched. '*' matches CREATE,
430	// UPDATE and CONNECT. Required.
431	"matchConstraints"?: #MatchResources
432
433	// mutations contain operations to perform on matching objects. mutations may
434	// not be empty; a minimum of one mutation is required. mutations are evaluated
435	// in order, and are reinvoked according to the reinvocationPolicy. The
436	// mutations of a policy are invoked for each binding of this policy and
437	// reinvocation of mutations occurs on a per binding basis.
438	"mutations"?: [...#Mutation]
439
440	// paramKind specifies the kind of resources used to parameterize this policy.
441	// If absent, there are no parameters for this policy and the param CEL
442	// variable will not be provided to validation expressions. If paramKind refers
443	// to a non-existent kind, this policy definition is mis-configured and the
444	// FailurePolicy is applied. If paramKind is specified but paramRef is unset in
445	// MutatingAdmissionPolicyBinding, the params variable will be null.
446	"paramKind"?: #ParamKind
447
448	// reinvocationPolicy indicates whether mutations may be called multiple times
449	// per MutatingAdmissionPolicyBinding as part of a single admission evaluation.
450	// Allowed values are "Never" and "IfNeeded".
451	//
452	// Never: These mutations will not be called more than once per binding in a
453	// single admission evaluation.
454	//
455	// IfNeeded: These mutations may be invoked more than once per binding for a
456	// single admission request and there is no guarantee of order with respect to
457	// other admission plugins, admission webhooks, bindings of this policy and
458	// admission policies. Mutations are only reinvoked when mutations change the
459	// object after this mutation is invoked. Required.
460	"reinvocationPolicy"?: string
461
462	// variables contain definitions of variables that can be used in composition of
463	// other expressions. Each variable is defined as a named CEL expression. The
464	// variables defined here will be available under `variables` in other
465	// expressions of the policy except matchConditions because matchConditions are
466	// evaluated before the rest of the policy.
467	//
468	// The expression of a variable can refer to other variables defined earlier in
469	// the list but not those after. Thus, variables must be sorted by the order of
470	// first appearance and acyclic.
471	"variables"?: [...#Variable]
472}
473
474// Mutation specifies the CEL expression which is used to apply the Mutation.
475#Mutation: {
476	// applyConfiguration defines the desired configuration values of an object. The
477	// configuration is applied to the admission object using [structured merge
478	// diff](https://github.com/kubernetes-sigs/structured-merge-diff). A CEL
479	// expression is used to create apply configuration.
480	"applyConfiguration"?: #ApplyConfiguration
481
482	// jsonPatch defines a [JSON patch](https://jsonpatch.com/) operation to perform
483	// a mutation to the object. A CEL expression is used to create the JSON patch.
484	"jsonPatch"?: #JSONPatch
485
486	// patchType indicates the patch strategy used. Allowed values are
487	// "ApplyConfiguration" and "JSONPatch". Required.
488	"patchType"!: string
489}
490
491// NamedRuleWithOperations is a tuple of Operations and Resources with ResourceNames.
492#NamedRuleWithOperations: {
493	// apiGroups is the API groups the resources belong to. '*' is all groups. If
494	// '*' is present, the length of the slice must be one. Required.
495	"apiGroups"?: [...string]
496
497	// apiVersions is the API versions the resources belong to. '*' is all versions.
498	// If '*' is present, the length of the slice must be one. Required.
499	"apiVersions"?: [...string]
500
501	// operations is the operations the admission hook cares about - CREATE, UPDATE,
502	// DELETE, CONNECT or * for all of those operations and any future admission
503	// operations that are added. If '*' is present, the length of the slice must
504	// be one. Required.
505	"operations"?: [...string]
506
507	// resourceNames is an optional white list of names that the rule applies to. An
508	// empty set means that everything is allowed.
509	"resourceNames"?: [...string]
510
511	// resources is a list of resources this rule applies to.
512	//
513	// For example: 'pods' means pods. 'pods/log' means the log subresource of pods.
514	// '*' means all resources, but not subresources. 'pods/*' means all
515	// subresources of pods. '*/scale' means all scale subresources. '*/*' means
516	// all resources and their subresources.
517	//
518	// If wildcard is present, the validation rule will ensure resources do not overlap with each other.
519	//
520	// Depending on the enclosing object, subresources might not be allowed. Required.
521	"resources"?: [...string]
522
523	// scope specifies the scope of this rule. Valid values are "Cluster",
524	// "Namespaced", and "*" "Cluster" means that only cluster-scoped resources
525	// will match this rule. Namespace API objects are cluster-scoped. "Namespaced"
526	// means that only namespaced resources will match this rule. "*" means that
527	// there are no scope restrictions. Subresources match the scope of their
528	// parent resource. Default is "*".
529	"scope"?: string
530}
531
532// ParamKind is a tuple of Group Kind and Version.
533#ParamKind: {
534	// apiVersion is the API group version the resources belong to. In format of
535	// "group/version". Required.
536	"apiVersion"?: string
537
538	// kind is the API kind the resources belong to. Required.
539	"kind"?: string
540}
541
542// ParamRef describes how to locate the params to be used as input to
543// expressions of rules applied by a policy binding.
544#ParamRef: {
545	// name is the name of the resource being referenced.
546	//
547	// One of `name` or `selector` must be set, but `name` and `selector` are
548	// mutually exclusive properties. If one is set, the other must be unset.
549	//
550	// A single parameter used for all admission requests can be configured by
551	// setting the `name` field, leaving `selector` blank, and setting namespace if
552	// `paramKind` is namespace-scoped.
553	"name"?: string
554
555	// namespace is the namespace of the referenced resource. Allows limiting the
556	// search for params to a specific namespace. Applies to both `name` and
557	// `selector` fields.
558	//
559	// A per-namespace parameter may be used by specifying a namespace-scoped
560	// `paramKind` in the policy and leaving this field empty.
561	//
562	// - If `paramKind` is cluster-scoped, this field MUST be unset. Setting this
563	// field results in a configuration error.
564	//
565	// - If `paramKind` is namespace-scoped, the namespace of the object being
566	// evaluated for admission will be used when this field is left unset. Take
567	// care that if this is left empty the binding must not match any
568	// cluster-scoped resources, which will result in an error.
569	"namespace"?: string
570
571	// parameterNotFoundAction controls the behavior of the binding when the
572	// resource exists, and name or selector is valid, but there are no parameters
573	// matched by the binding. If the value is set to `Allow`, then no matched
574	// parameters will be treated as successful validation by the binding. If set
575	// to `Deny`, then no matched parameters will be subject to the `failurePolicy`
576	// of the policy.
577	//
578	// Allowed values are `Allow` or `Deny`
579	//
580	// Required
581	"parameterNotFoundAction"?: string
582
583	// selector can be used to match multiple param objects based on their labels.
584	// Supply selector: {} to match all resources of the ParamKind.
585	//
586	// If multiple params are found, they are all evaluated with the policy
587	// expressions and the results are ANDed together.
588	//
589	// One of `name` or `selector` must be set, but `name` and `selector` are
590	// mutually exclusive properties. If one is set, the other must be unset.
591	"selector"?: v1.#LabelSelector
592}
593
594// Variable is the definition of a variable that is used for composition. A
595// variable is defined as a named expression.
596#Variable: {
597	// expression is the expression that will be evaluated as the value of the
598	// variable. The CEL expression has access to the same identifiers as the CEL
599	// expressions in Validation.
600	"expression"!: string
601
602	// name is the name of the variable. The name must be a valid CEL identifier and
603	// unique among all variables. The variable can be accessed in other
604	// expressions through `variables` For example, if name is "foo", the variable
605	// will be available as `variables.foo`
606	"name"!: string
607}