cue.dev/x/k8s.io@v0.12.0

api/certificates/v1alpha1/schema.cue raw

 1package v1alpha1
 2
 3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
 4
 5// ClusterTrustBundle is a cluster-scoped container for X.509 trust anchors (root certificates).
 6//
 7// ClusterTrustBundle objects are considered to be readable by any authenticated
 8// user in the cluster, because they can be mounted by pods using the
 9// `clusterTrustBundle` projection. All service accounts have read access to
10// ClusterTrustBundles by default. Users who only have namespace-level access
11// to a cluster can read ClusterTrustBundles by impersonating a serviceaccount
12// that they have access to.
13//
14// It can be optionally associated with a particular assigner, in which case it
15// contains one valid set of trust anchors for that signer. Signers may have
16// multiple associated ClusterTrustBundles; each is an independent set of trust
17// anchors for that signer. Admission control is used to enforce that only
18// users with permissions on the signer can create or modify the corresponding
19// bundle.
20#ClusterTrustBundle: {
21	// APIVersion defines the versioned schema of this representation of an object.
22	// Servers should convert recognized schemas to the latest internal value, and
23	// may reject unrecognized values. More info:
24	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
25	"apiVersion": "certificates.k8s.io/v1alpha1"
26
27	// Kind is a string value representing the REST resource this object represents.
28	// Servers may infer this from the endpoint the client submits requests to.
29	// Cannot be updated. In CamelCase. More info:
30	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
31	"kind": "ClusterTrustBundle"
32
33	// metadata contains the object metadata.
34	"metadata"?: v1.#ObjectMeta
35
36	// spec contains the signer (if any) and trust anchors.
37	"spec"!: #ClusterTrustBundleSpec
38}
39
40// ClusterTrustBundleList is a collection of ClusterTrustBundle objects
41#ClusterTrustBundleList: {
42	// APIVersion defines the versioned schema of this representation of an object.
43	// Servers should convert recognized schemas to the latest internal value, and
44	// may reject unrecognized values. More info:
45	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
46	"apiVersion": "certificates.k8s.io/v1alpha1"
47
48	// items is a collection of ClusterTrustBundle objects
49	"items"!: [...#ClusterTrustBundle]
50
51	// Kind is a string value representing the REST resource this object represents.
52	// Servers may infer this from the endpoint the client submits requests to.
53	// Cannot be updated. In CamelCase. More info:
54	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
55	"kind": "ClusterTrustBundleList"
56
57	// metadata contains the list metadata.
58	"metadata"?: v1.#ListMeta
59}
60
61// ClusterTrustBundleSpec contains the signer and trust anchors.
62#ClusterTrustBundleSpec: {
63	// signerName indicates the associated signer, if any.
64	//
65	// In order to create or update a ClusterTrustBundle that sets signerName, you
66	// must have the following cluster-scoped permission: group=certificates.k8s.io
67	// resource=signers resourceName=<the signer name> verb=attest.
68	//
69	// If signerName is not empty, then the ClusterTrustBundle object must be named
70	// with the signer name as a prefix (translating slashes to colons). For
71	// example, for the signer name `example.com/foo`, valid ClusterTrustBundle
72	// object names include `example.com:foo:abc` and `example.com:foo:v1`.
73	//
74	// If signerName is empty, then the ClusterTrustBundle object's name must not have such a prefix.
75	//
76	// List/watch requests for ClusterTrustBundles can filter on this field using a
77	// `spec.signerName=NAME` field selector.
78	"signerName"?: string
79
80	// trustBundle contains the individual X.509 trust anchors for this bundle, as
81	// PEM bundle of PEM-wrapped, DER-formatted X.509 certificates.
82	//
83	// The data must consist only of PEM certificate blocks that parse as valid
84	// X.509 certificates. Each certificate must include a basic constraints
85	// extension with the CA bit set. The API server will reject objects that
86	// contain duplicate certificates, or that use PEM block headers.
87	//
88	// Users of ClusterTrustBundles, including Kubelet, are free to reorder and
89	// deduplicate certificate blocks in this file according to their own logic, as
90	// well as to drop PEM block headers and inter-block data.
91	"trustBundle"!: string
92}