1package v1alpha1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// ClusterTrustBundle is a cluster-scoped container for X.509 trust anchors (root certificates).
6//
7// ClusterTrustBundle objects are considered to be readable by any authenticated
8// user in the cluster, because they can be mounted by pods using the
9// `clusterTrustBundle` projection. All service accounts have read access to
10// ClusterTrustBundles by default. Users who only have namespace-level access
11// to a cluster can read ClusterTrustBundles by impersonating a serviceaccount
12// that they have access to.
13//
14// It can be optionally associated with a particular assigner, in which case it
15// contains one valid set of trust anchors for that signer. Signers may have
16// multiple associated ClusterTrustBundles; each is an independent set of trust
17// anchors for that signer. Admission control is used to enforce that only
18// users with permissions on the signer can create or modify the corresponding
19// bundle.
20#ClusterTrustBundle: {
21 // APIVersion defines the versioned schema of this representation of an object.
22 // Servers should convert recognized schemas to the latest internal value, and
23 // may reject unrecognized values. More info:
24 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
25 "apiVersion": "certificates.k8s.io/v1alpha1"
26
27 // Kind is a string value representing the REST resource this object represents.
28 // Servers may infer this from the endpoint the client submits requests to.
29 // Cannot be updated. In CamelCase. More info:
30 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
31 "kind": "ClusterTrustBundle"
32
33 // metadata contains the object metadata.
34 "metadata"?: v1.#ObjectMeta
35
36 // spec contains the signer (if any) and trust anchors.
37 "spec"!: #ClusterTrustBundleSpec
38}
39
40// ClusterTrustBundleList is a collection of ClusterTrustBundle objects
41#ClusterTrustBundleList: {
42 // APIVersion defines the versioned schema of this representation of an object.
43 // Servers should convert recognized schemas to the latest internal value, and
44 // may reject unrecognized values. More info:
45 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
46 "apiVersion": "certificates.k8s.io/v1alpha1"
47
48 // items is a collection of ClusterTrustBundle objects
49 "items"!: [...#ClusterTrustBundle]
50
51 // Kind is a string value representing the REST resource this object represents.
52 // Servers may infer this from the endpoint the client submits requests to.
53 // Cannot be updated. In CamelCase. More info:
54 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
55 "kind": "ClusterTrustBundleList"
56
57 // metadata contains the list metadata.
58 "metadata"?: v1.#ListMeta
59}
60
61// ClusterTrustBundleSpec contains the signer and trust anchors.
62#ClusterTrustBundleSpec: {
63 // signerName indicates the associated signer, if any.
64 //
65 // In order to create or update a ClusterTrustBundle that sets signerName, you
66 // must have the following cluster-scoped permission: group=certificates.k8s.io
67 // resource=signers resourceName=<the signer name> verb=attest.
68 //
69 // If signerName is not empty, then the ClusterTrustBundle object must be named
70 // with the signer name as a prefix (translating slashes to colons). For
71 // example, for the signer name `example.com/foo`, valid ClusterTrustBundle
72 // object names include `example.com:foo:abc` and `example.com:foo:v1`.
73 //
74 // If signerName is empty, then the ClusterTrustBundle object's name must not have such a prefix.
75 //
76 // List/watch requests for ClusterTrustBundles can filter on this field using a
77 // `spec.signerName=NAME` field selector.
78 "signerName"?: string
79
80 // trustBundle contains the individual X.509 trust anchors for this bundle, as
81 // PEM bundle of PEM-wrapped, DER-formatted X.509 certificates.
82 //
83 // The data must consist only of PEM certificate blocks that parse as valid
84 // X.509 certificates. Each certificate must include a basic constraints
85 // extension with the CA bit set. The API server will reject objects that
86 // contain duplicate certificates, or that use PEM block headers.
87 //
88 // Users of ClusterTrustBundles, including Kubelet, are free to reorder and
89 // deduplicate certificate blocks in this file according to their own logic, as
90 // well as to drop PEM block headers and inter-block data.
91 "trustBundle"!: string
92}