cue.dev/x/k8s.io@v0.12.0

api/authentication/v1/schema.cue raw

  1package v1
  2
  3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
  4
  5// BoundObjectReference is a reference to an object that a token is bound to.
  6#BoundObjectReference: {
  7	// apiVersion is API version of the referent.
  8	"apiVersion"?: string
  9
 10	// kind of the referent. Valid kinds are 'Pod' and 'Secret'.
 11	"kind"?: string
 12
 13	// name of the referent.
 14	"name"?: string
 15
 16	// uid of the referent.
 17	"uid"?: string
 18}
 19
 20// SelfSubjectReview contains the user information that the kube-apiserver has
 21// about the user making this request. When using impersonation, users will
 22// receive the user info of the user being impersonated. If impersonation or
 23// request header authentication is used, any extra keys will have their case
 24// ignored and returned as lowercase.
 25#SelfSubjectReview: {
 26	// APIVersion defines the versioned schema of this representation of an object.
 27	// Servers should convert recognized schemas to the latest internal value, and
 28	// may reject unrecognized values. More info:
 29	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 30	"apiVersion": "authentication.k8s.io/v1"
 31
 32	// Kind is a string value representing the REST resource this object represents.
 33	// Servers may infer this from the endpoint the client submits requests to.
 34	// Cannot be updated. In CamelCase. More info:
 35	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 36	"kind": "SelfSubjectReview"
 37
 38	// metadata is standard object's metadata. More info:
 39	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 40	"metadata"?: v1.#ObjectMeta
 41
 42	// status is filled in by the server with the user attributes.
 43	"status"?: #SelfSubjectReviewStatus
 44}
 45
 46// SelfSubjectReviewStatus is filled by the kube-apiserver and sent back to a user.
 47#SelfSubjectReviewStatus: {
 48	// userInfo is a set of attributes belonging to the user making this request.
 49	"userInfo"?: #UserInfo
 50}
 51
 52// TokenRequest requests a token for a given service account.
 53#TokenRequest: {
 54	// APIVersion defines the versioned schema of this representation of an object.
 55	// Servers should convert recognized schemas to the latest internal value, and
 56	// may reject unrecognized values. More info:
 57	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 58	"apiVersion": "authentication.k8s.io/v1"
 59
 60	// Kind is a string value representing the REST resource this object represents.
 61	// Servers may infer this from the endpoint the client submits requests to.
 62	// Cannot be updated. In CamelCase. More info:
 63	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 64	"kind": "TokenRequest"
 65
 66	// metadata is the standard object's metadata. More info:
 67	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 68	"metadata"?: v1.#ObjectMeta
 69
 70	// spec holds information about the request being evaluated
 71	"spec"?: #TokenRequestSpec
 72
 73	// status is filled in by the server and indicates whether the token can be authenticated.
 74	"status"?: #TokenRequestStatus
 75}
 76
 77// TokenRequestSpec contains client provided parameters of a token request.
 78#TokenRequestSpec: {
 79	// audiences are the intendend audiences of the token. A recipient of a token
 80	// must identify themself with an identifier in the list of audiences of the
 81	// token, and otherwise should reject the token. A token issued for multiple
 82	// audiences may be used to authenticate against any of the audiences listed
 83	// but implies a high degree of trust between the target audiences.
 84	"audiences"?: [...string]
 85
 86	// boundObjectRef is a reference to an object that the token will be bound to.
 87	// The token will only be valid for as long as the bound object exists. NOTE:
 88	// The API server's TokenReview endpoint will validate the BoundObjectRef, but
 89	// other audiences may not. Keep ExpirationSeconds small if you want prompt
 90	// revocation.
 91	"boundObjectRef"?: #BoundObjectReference
 92
 93	// expirationSeconds is the requested duration of validity of the request. The
 94	// token issuer may return a token with a different validity duration so a
 95	// client needs to check the 'expiration' field in a response.
 96	"expirationSeconds"?: int64 & int
 97}
 98
 99// TokenRequestStatus is the result of a token request.
100#TokenRequestStatus: {
101	// expirationTimestamp is the time of expiration of the returned token.
102	"expirationTimestamp"?: v1.#Time
103
104	// token is the opaque bearer token.
105	"token"?: string
106}
107
108// TokenReview attempts to authenticate a token to a known user. Note:
109// TokenReview requests may be cached by the webhook token authenticator plugin
110// in the kube-apiserver.
111#TokenReview: {
112	// APIVersion defines the versioned schema of this representation of an object.
113	// Servers should convert recognized schemas to the latest internal value, and
114	// may reject unrecognized values. More info:
115	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
116	"apiVersion": "authentication.k8s.io/v1"
117
118	// Kind is a string value representing the REST resource this object represents.
119	// Servers may infer this from the endpoint the client submits requests to.
120	// Cannot be updated. In CamelCase. More info:
121	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
122	"kind": "TokenReview"
123
124	// metadata is the standard object's metadata. More info:
125	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
126	"metadata"?: v1.#ObjectMeta
127
128	// spec holds information about the request being evaluated
129	"spec"!: #TokenReviewSpec
130
131	// status is filled in by the server and indicates whether the request can be authenticated.
132	"status"?: #TokenReviewStatus
133}
134
135// TokenReviewSpec is a description of the token authentication request.
136#TokenReviewSpec: {
137	// audiences is a list of the identifiers that the resource server presented
138	// with the token identifies as. Audience-aware token authenticators will
139	// verify that the token was intended for at least one of the audiences in this
140	// list. If no audiences are provided, the audience will default to the
141	// audience of the Kubernetes apiserver.
142	"audiences"?: [...string]
143
144	// token is the opaque bearer token.
145	"token"!: string
146}
147
148// TokenReviewStatus is the result of the token authentication request.
149#TokenReviewStatus: {
150	// audiences are audience identifiers chosen by the authenticator that are
151	// compatible with both the TokenReview and token. An identifier is any
152	// identifier in the intersection of the TokenReviewSpec audiences and the
153	// token's audiences. A client of the TokenReview API that sets the
154	// spec.audiences field should validate that a compatible audience identifier
155	// is returned in the status.audiences field to ensure that the TokenReview
156	// server is audience aware. If a TokenReview returns an empty status.audience
157	// field where status.authenticated is "true", the token is valid against the
158	// audience of the Kubernetes API server.
159	"audiences"?: [...string]
160
161	// authenticated indicates that the token was associated with a known user.
162	"authenticated"?: bool
163
164	// error indicates that the token couldn't be checked
165	"error"?: string
166
167	// user is the UserInfo associated with the provided token.
168	"user"?: #UserInfo
169}
170
171// UserInfo holds the information about the user needed to implement the user.Info interface.
172#UserInfo: {
173	// extra is any additional information provided by the authenticator.
174	"extra"?: [string]: [...string]
175
176	// groups is the names of groups this user is a part of.
177	"groups"?: [...string]
178
179	// uid is a unique value that identifies this user across time. If this user is
180	// deleted and another user by the same name is added, they will have different
181	// UIDs.
182	"uid"?: string
183
184	// username is the name that uniquely identifies this user among all active users.
185	"username"?: string
186}