cue.dev/x/k8s.io@v0.12.0

api/certificates/v1beta1/schema.cue raw

  1package v1beta1
  2
  3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
  4
  5// ClusterTrustBundle is a cluster-scoped container for X.509 trust anchors (root certificates).
  6//
  7// ClusterTrustBundle objects are considered to be readable by any authenticated
  8// user in the cluster, because they can be mounted by pods using the
  9// `clusterTrustBundle` projection. All service accounts have read access to
 10// ClusterTrustBundles by default. Users who only have namespace-level access
 11// to a cluster can read ClusterTrustBundles by impersonating a serviceaccount
 12// that they have access to.
 13//
 14// It can be optionally associated with a particular assigner, in which case it
 15// contains one valid set of trust anchors for that signer. Signers may have
 16// multiple associated ClusterTrustBundles; each is an independent set of trust
 17// anchors for that signer. Admission control is used to enforce that only
 18// users with permissions on the signer can create or modify the corresponding
 19// bundle.
 20#ClusterTrustBundle: {
 21	// APIVersion defines the versioned schema of this representation of an object.
 22	// Servers should convert recognized schemas to the latest internal value, and
 23	// may reject unrecognized values. More info:
 24	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 25	"apiVersion": "certificates.k8s.io/v1beta1"
 26
 27	// Kind is a string value representing the REST resource this object represents.
 28	// Servers may infer this from the endpoint the client submits requests to.
 29	// Cannot be updated. In CamelCase. More info:
 30	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 31	"kind": "ClusterTrustBundle"
 32
 33	// metadata contains the object metadata.
 34	"metadata"?: v1.#ObjectMeta
 35
 36	// spec contains the signer (if any) and trust anchors.
 37	"spec"!: #ClusterTrustBundleSpec
 38}
 39
 40// ClusterTrustBundleList is a collection of ClusterTrustBundle objects
 41#ClusterTrustBundleList: {
 42	// APIVersion defines the versioned schema of this representation of an object.
 43	// Servers should convert recognized schemas to the latest internal value, and
 44	// may reject unrecognized values. More info:
 45	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 46	"apiVersion": "certificates.k8s.io/v1beta1"
 47
 48	// items is a collection of ClusterTrustBundle objects
 49	"items"!: [...#ClusterTrustBundle]
 50
 51	// Kind is a string value representing the REST resource this object represents.
 52	// Servers may infer this from the endpoint the client submits requests to.
 53	// Cannot be updated. In CamelCase. More info:
 54	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 55	"kind": "ClusterTrustBundleList"
 56
 57	// metadata contains the list metadata.
 58	"metadata"?: v1.#ListMeta
 59}
 60
 61// ClusterTrustBundleSpec contains the signer and trust anchors.
 62#ClusterTrustBundleSpec: {
 63	// signerName indicates the associated signer, if any.
 64	//
 65	// In order to create or update a ClusterTrustBundle that sets signerName, you
 66	// must have the following cluster-scoped permission: group=certificates.k8s.io
 67	// resource=signers resourceName=<the signer name> verb=attest.
 68	//
 69	// If signerName is not empty, then the ClusterTrustBundle object must be named
 70	// with the signer name as a prefix (translating slashes to colons). For
 71	// example, for the signer name `example.com/foo`, valid ClusterTrustBundle
 72	// object names include `example.com:foo:abc` and `example.com:foo:v1`.
 73	//
 74	// If signerName is empty, then the ClusterTrustBundle object's name must not have such a prefix.
 75	//
 76	// List/watch requests for ClusterTrustBundles can filter on this field using a
 77	// `spec.signerName=NAME` field selector.
 78	"signerName"?: string
 79
 80	// trustBundle contains the individual X.509 trust anchors for this bundle, as
 81	// PEM bundle of PEM-wrapped, DER-formatted X.509 certificates.
 82	//
 83	// The data must consist only of PEM certificate blocks that parse as valid
 84	// X.509 certificates. Each certificate must include a basic constraints
 85	// extension with the CA bit set. The API server will reject objects that
 86	// contain duplicate certificates, or that use PEM block headers.
 87	//
 88	// Users of ClusterTrustBundles, including Kubelet, are free to reorder and
 89	// deduplicate certificate blocks in this file according to their own logic, as
 90	// well as to drop PEM block headers and inter-block data.
 91	"trustBundle"!: string
 92}
 93
 94// PodCertificateRequest encodes a pod requesting a certificate from a given signer.
 95//
 96// Kubelets use this API to implement podCertificate projected volumes
 97#PodCertificateRequest: {
 98	// APIVersion defines the versioned schema of this representation of an object.
 99	// Servers should convert recognized schemas to the latest internal value, and
100	// may reject unrecognized values. More info:
101	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
102	"apiVersion": "certificates.k8s.io/v1beta1"
103
104	// Kind is a string value representing the REST resource this object represents.
105	// Servers may infer this from the endpoint the client submits requests to.
106	// Cannot be updated. In CamelCase. More info:
107	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
108	"kind": "PodCertificateRequest"
109
110	// metadata contains the object metadata.
111	"metadata"?: v1.#ObjectMeta
112
113	// spec contains the details about the certificate being requested.
114	"spec"!: #PodCertificateRequestSpec
115
116	// status contains the issued certificate, and a standard set of conditions.
117	"status"?: #PodCertificateRequestStatus
118}
119
120// PodCertificateRequestList is a collection of PodCertificateRequest objects
121#PodCertificateRequestList: {
122	// APIVersion defines the versioned schema of this representation of an object.
123	// Servers should convert recognized schemas to the latest internal value, and
124	// may reject unrecognized values. More info:
125	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
126	"apiVersion": "certificates.k8s.io/v1beta1"
127
128	// items is a collection of PodCertificateRequest objects
129	"items"!: [...#PodCertificateRequest]
130
131	// Kind is a string value representing the REST resource this object represents.
132	// Servers may infer this from the endpoint the client submits requests to.
133	// Cannot be updated. In CamelCase. More info:
134	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
135	"kind": "PodCertificateRequestList"
136
137	// metadata contains the list metadata.
138	"metadata"?: v1.#ListMeta
139}
140
141// PodCertificateRequestSpec describes the certificate request. All fields are
142// immutable after creation.
143#PodCertificateRequestSpec: {
144	// maxExpirationSeconds is the maximum lifetime permitted for the certificate.
145	//
146	// If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver
147	// will reject values shorter than 3600 (1 hour). The maximum allowable value
148	// is 7862400 (91 days).
149	//
150	// The signer implementation is then free to issue a certificate with any
151	// lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600
152	// seconds (1 hour). This constraint is enforced by kube-apiserver.
153	// `kubernetes.io` signers will never issue certificates with a lifetime longer
154	// than 24 hours.
155	"maxExpirationSeconds"?: int32 & int
156
157	// nodeName is the name of the node the pod is assigned to.
158	"nodeName"!: string
159
160	// nodeUID is the UID of the node the pod is assigned to.
161	"nodeUID"!: string
162
163	// The PKIX-serialized public key the signer will issue the certificate to.
164	//
165	// The key must be one of RSA3072, RSA4096, ECDSAP256, ECDSAP384, ECDSAP521, or
166	// ED25519. Note that this list may be expanded in the future.
167	//
168	// Signer implementations do not need to support all key types supported by
169	// kube-apiserver and kubelet. If a signer does not support the key type used
170	// for a given PodCertificateRequest, it must deny the request by setting a
171	// status.conditions entry with a type of "Denied" and a reason of
172	// "UnsupportedKeyType". It may also suggest a key type that it does support in
173	// the message field.
174	//
175	// Deprecated: This field is replaced by StubPKCS10Request. If StubPKCS10Request
176	// is set, this field must be empty. Signer implementations should extract the
177	// public key from the StubPKCS10Request field.
178	"pkixPublicKey"?: string
179
180	// podName is the name of the pod into which the certificate will be mounted.
181	"podName"!: string
182
183	// podUID is the UID of the pod into which the certificate will be mounted.
184	"podUID"!: string
185
186	// A proof that the requesting kubelet holds the private key corresponding to pkixPublicKey.
187	//
188	// It is contructed by signing the ASCII bytes of the pod's UID using `pkixPublicKey`.
189	//
190	// kube-apiserver validates the proof of possession during creation of the PodCertificateRequest.
191	//
192	// If the key is an RSA key, then the signature is over the ASCII bytes of the
193	// pod UID, using RSASSA-PSS from RFC 8017 (as implemented by the golang
194	// function crypto/rsa.SignPSS with nil options).
195	//
196	// If the key is an ECDSA key, then the signature is as described by [SEC 1,
197	// Version 2.0](https://www.secg.org/sec1-v2.pdf) (as implemented by the golang
198	// library function crypto/ecdsa.SignASN1)
199	//
200	// If the key is an ED25519 key, the the signature is as described by the
201	// [ED25519 Specification](https://ed25519.cr.yp.to/) (as implemented by the
202	// golang library crypto/ed25519.Sign).
203	//
204	// Deprecated: This field is replaced by StubPKCS10Request. If StubPKCS10Request
205	// is set, this field must be empty.
206	"proofOfPossession"?: string
207
208	// serviceAccountName is the name of the service account the pod is running as.
209	"serviceAccountName"!: string
210
211	// serviceAccountUID is the UID of the service account the pod is running as.
212	"serviceAccountUID"!: string
213
214	// signerName indicates the requested signer.
215	//
216	// All signer names beginning with `kubernetes.io` are reserved for use by the
217	// Kubernetes project. There is currently one well-known signer documented by
218	// the Kubernetes project, `kubernetes.io/kube-apiserver-client-pod`, which
219	// will issue client certificates understood by kube-apiserver. It is currently
220	// unimplemented.
221	"signerName"!: string
222
223	// A PKCS#10 certificate signing request (DER-serialized) generated by Kubelet
224	// using the subject private key.
225	//
226	// Most signer implementations will ignore the contents of the CSR except to
227	// extract the subject public key. The API server automatically verifies the
228	// CSR signature during admission, so the signer does not need to repeat the
229	// verification. CSRs generated by kubelet are completely empty.
230	//
231	// The subject public key must be one of RSA3072, RSA4096, ECDSAP256, ECDSAP384,
232	// ECDSAP521, or ED25519. Note that this list may be expanded in the future.
233	//
234	// Signer implementations do not need to support all key types supported by
235	// kube-apiserver and kubelet. If a signer does not support the key type used
236	// for a given PodCertificateRequest, it must deny the request by setting a
237	// status.conditions entry with a type of "Denied" and a reason of
238	// "UnsupportedKeyType". It may also suggest a key type that it does support in
239	// the message field.
240	"stubPKCS10Request"!: string
241
242	// unverifiedUserAnnotations allow pod authors to pass additional information to
243	// the signer implementation. Kubernetes does not restrict or validate this
244	// metadata in any way.
245	//
246	// Entries are subject to the same validation as object metadata annotations,
247	// with the addition that all keys must be domain-prefixed. No restrictions are
248	// placed on values, except an overall size limitation on the entire field.
249	//
250	// Signers should document the keys and values they support. Signers should deny
251	// requests that contain keys they do not recognize.
252	"unverifiedUserAnnotations"?: [string]: string
253}
254
255// PodCertificateRequestStatus describes the status of the request, and holds
256// the certificate data if the request is issued.
257#PodCertificateRequestStatus: {
258	// beginRefreshAt is the time at which the kubelet should begin trying to
259	// refresh the certificate. This field is set via the /status subresource, and
260	// must be set at the same time as certificateChain. Once populated, this field
261	// is immutable.
262	//
263	// This field is only a hint. Kubelet may start refreshing before or after this time if necessary.
264	"beginRefreshAt"?: v1.#Time
265
266	// certificateChain is populated with an issued certificate by the signer. This
267	// field is set via the /status subresource. Once populated, this field is
268	// immutable.
269	//
270	// If the certificate signing request is denied, a condition of type "Denied" is
271	// added and this field remains empty. If the signer cannot issue the
272	// certificate, a condition of type "Failed" is added and this field remains
273	// empty.
274	//
275	// Validation requirements:
276	// 1. certificateChain must consist of one or more PEM-formatted certificates.
277	// 2. Each entry must be a valid PEM-wrapped, DER-encoded ASN.1 Certificate as
278	// described in section 4 of RFC5280.
279	//
280	// If more than one block is present, and the definition of the requested
281	// spec.signerName does not indicate otherwise, the first block is the issued
282	// certificate, and subsequent blocks should be treated as intermediate
283	// certificates and presented in TLS handshakes. When projecting the chain into
284	// a pod volume, kubelet will drop any data in-between the PEM blocks, as well
285	// as any PEM block headers.
286	"certificateChain"?: string
287
288	// conditions applied to the request.
289	//
290	// The types "Issued", "Denied", and "Failed" have special handling. At most one
291	// of these conditions may be present, and they must have status "True".
292	//
293	// If the request is denied with `Reason=UnsupportedKeyType`, the signer may
294	// suggest a key type that will work in the message field.
295	"conditions"?: [...v1.#Condition]
296
297	// notAfter is the time at which the certificate expires. The value must be the
298	// same as the notAfter value in the leaf certificate in certificateChain. This
299	// field is set via the /status subresource. Once populated, it is immutable.
300	// The signer must set this field at the same time it sets certificateChain.
301	"notAfter"?: v1.#Time
302
303	// notBefore is the time at which the certificate becomes valid. The value must
304	// be the same as the notBefore value in the leaf certificate in
305	// certificateChain. This field is set via the /status subresource. Once
306	// populated, it is immutable. The signer must set this field at the same time
307	// it sets certificateChain.
308	"notBefore"?: v1.#Time
309}