1package v1beta1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// ClusterTrustBundle is a cluster-scoped container for X.509 trust anchors (root certificates).
6//
7// ClusterTrustBundle objects are considered to be readable by any authenticated
8// user in the cluster, because they can be mounted by pods using the
9// `clusterTrustBundle` projection. All service accounts have read access to
10// ClusterTrustBundles by default. Users who only have namespace-level access
11// to a cluster can read ClusterTrustBundles by impersonating a serviceaccount
12// that they have access to.
13//
14// It can be optionally associated with a particular assigner, in which case it
15// contains one valid set of trust anchors for that signer. Signers may have
16// multiple associated ClusterTrustBundles; each is an independent set of trust
17// anchors for that signer. Admission control is used to enforce that only
18// users with permissions on the signer can create or modify the corresponding
19// bundle.
20#ClusterTrustBundle: {
21 // APIVersion defines the versioned schema of this representation of an object.
22 // Servers should convert recognized schemas to the latest internal value, and
23 // may reject unrecognized values. More info:
24 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
25 "apiVersion": "certificates.k8s.io/v1beta1"
26
27 // Kind is a string value representing the REST resource this object represents.
28 // Servers may infer this from the endpoint the client submits requests to.
29 // Cannot be updated. In CamelCase. More info:
30 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
31 "kind": "ClusterTrustBundle"
32
33 // metadata contains the object metadata.
34 "metadata"?: v1.#ObjectMeta
35
36 // spec contains the signer (if any) and trust anchors.
37 "spec"!: #ClusterTrustBundleSpec
38}
39
40// ClusterTrustBundleList is a collection of ClusterTrustBundle objects
41#ClusterTrustBundleList: {
42 // APIVersion defines the versioned schema of this representation of an object.
43 // Servers should convert recognized schemas to the latest internal value, and
44 // may reject unrecognized values. More info:
45 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
46 "apiVersion": "certificates.k8s.io/v1beta1"
47
48 // items is a collection of ClusterTrustBundle objects
49 "items"!: [...#ClusterTrustBundle]
50
51 // Kind is a string value representing the REST resource this object represents.
52 // Servers may infer this from the endpoint the client submits requests to.
53 // Cannot be updated. In CamelCase. More info:
54 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
55 "kind": "ClusterTrustBundleList"
56
57 // metadata contains the list metadata.
58 "metadata"?: v1.#ListMeta
59}
60
61// ClusterTrustBundleSpec contains the signer and trust anchors.
62#ClusterTrustBundleSpec: {
63 // signerName indicates the associated signer, if any.
64 //
65 // In order to create or update a ClusterTrustBundle that sets signerName, you
66 // must have the following cluster-scoped permission: group=certificates.k8s.io
67 // resource=signers resourceName=<the signer name> verb=attest.
68 //
69 // If signerName is not empty, then the ClusterTrustBundle object must be named
70 // with the signer name as a prefix (translating slashes to colons). For
71 // example, for the signer name `example.com/foo`, valid ClusterTrustBundle
72 // object names include `example.com:foo:abc` and `example.com:foo:v1`.
73 //
74 // If signerName is empty, then the ClusterTrustBundle object's name must not have such a prefix.
75 //
76 // List/watch requests for ClusterTrustBundles can filter on this field using a
77 // `spec.signerName=NAME` field selector.
78 "signerName"?: string
79
80 // trustBundle contains the individual X.509 trust anchors for this bundle, as
81 // PEM bundle of PEM-wrapped, DER-formatted X.509 certificates.
82 //
83 // The data must consist only of PEM certificate blocks that parse as valid
84 // X.509 certificates. Each certificate must include a basic constraints
85 // extension with the CA bit set. The API server will reject objects that
86 // contain duplicate certificates, or that use PEM block headers.
87 //
88 // Users of ClusterTrustBundles, including Kubelet, are free to reorder and
89 // deduplicate certificate blocks in this file according to their own logic, as
90 // well as to drop PEM block headers and inter-block data.
91 "trustBundle"!: string
92}
93
94// PodCertificateRequest encodes a pod requesting a certificate from a given signer.
95//
96// Kubelets use this API to implement podCertificate projected volumes
97#PodCertificateRequest: {
98 // APIVersion defines the versioned schema of this representation of an object.
99 // Servers should convert recognized schemas to the latest internal value, and
100 // may reject unrecognized values. More info:
101 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
102 "apiVersion": "certificates.k8s.io/v1beta1"
103
104 // Kind is a string value representing the REST resource this object represents.
105 // Servers may infer this from the endpoint the client submits requests to.
106 // Cannot be updated. In CamelCase. More info:
107 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
108 "kind": "PodCertificateRequest"
109
110 // metadata contains the object metadata.
111 "metadata"?: v1.#ObjectMeta
112
113 // spec contains the details about the certificate being requested.
114 "spec"!: #PodCertificateRequestSpec
115
116 // status contains the issued certificate, and a standard set of conditions.
117 "status"?: #PodCertificateRequestStatus
118}
119
120// PodCertificateRequestList is a collection of PodCertificateRequest objects
121#PodCertificateRequestList: {
122 // APIVersion defines the versioned schema of this representation of an object.
123 // Servers should convert recognized schemas to the latest internal value, and
124 // may reject unrecognized values. More info:
125 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
126 "apiVersion": "certificates.k8s.io/v1beta1"
127
128 // items is a collection of PodCertificateRequest objects
129 "items"!: [...#PodCertificateRequest]
130
131 // Kind is a string value representing the REST resource this object represents.
132 // Servers may infer this from the endpoint the client submits requests to.
133 // Cannot be updated. In CamelCase. More info:
134 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
135 "kind": "PodCertificateRequestList"
136
137 // metadata contains the list metadata.
138 "metadata"?: v1.#ListMeta
139}
140
141// PodCertificateRequestSpec describes the certificate request. All fields are
142// immutable after creation.
143#PodCertificateRequestSpec: {
144 // maxExpirationSeconds is the maximum lifetime permitted for the certificate.
145 //
146 // If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver
147 // will reject values shorter than 3600 (1 hour). The maximum allowable value
148 // is 7862400 (91 days).
149 //
150 // The signer implementation is then free to issue a certificate with any
151 // lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600
152 // seconds (1 hour). This constraint is enforced by kube-apiserver.
153 // `kubernetes.io` signers will never issue certificates with a lifetime longer
154 // than 24 hours.
155 "maxExpirationSeconds"?: int32 & int
156
157 // nodeName is the name of the node the pod is assigned to.
158 "nodeName"!: string
159
160 // nodeUID is the UID of the node the pod is assigned to.
161 "nodeUID"!: string
162
163 // The PKIX-serialized public key the signer will issue the certificate to.
164 //
165 // The key must be one of RSA3072, RSA4096, ECDSAP256, ECDSAP384, ECDSAP521, or
166 // ED25519. Note that this list may be expanded in the future.
167 //
168 // Signer implementations do not need to support all key types supported by
169 // kube-apiserver and kubelet. If a signer does not support the key type used
170 // for a given PodCertificateRequest, it must deny the request by setting a
171 // status.conditions entry with a type of "Denied" and a reason of
172 // "UnsupportedKeyType". It may also suggest a key type that it does support in
173 // the message field.
174 //
175 // Deprecated: This field is replaced by StubPKCS10Request. If StubPKCS10Request
176 // is set, this field must be empty. Signer implementations should extract the
177 // public key from the StubPKCS10Request field.
178 "pkixPublicKey"?: string
179
180 // podName is the name of the pod into which the certificate will be mounted.
181 "podName"!: string
182
183 // podUID is the UID of the pod into which the certificate will be mounted.
184 "podUID"!: string
185
186 // A proof that the requesting kubelet holds the private key corresponding to pkixPublicKey.
187 //
188 // It is contructed by signing the ASCII bytes of the pod's UID using `pkixPublicKey`.
189 //
190 // kube-apiserver validates the proof of possession during creation of the PodCertificateRequest.
191 //
192 // If the key is an RSA key, then the signature is over the ASCII bytes of the
193 // pod UID, using RSASSA-PSS from RFC 8017 (as implemented by the golang
194 // function crypto/rsa.SignPSS with nil options).
195 //
196 // If the key is an ECDSA key, then the signature is as described by [SEC 1,
197 // Version 2.0](https://www.secg.org/sec1-v2.pdf) (as implemented by the golang
198 // library function crypto/ecdsa.SignASN1)
199 //
200 // If the key is an ED25519 key, the the signature is as described by the
201 // [ED25519 Specification](https://ed25519.cr.yp.to/) (as implemented by the
202 // golang library crypto/ed25519.Sign).
203 //
204 // Deprecated: This field is replaced by StubPKCS10Request. If StubPKCS10Request
205 // is set, this field must be empty.
206 "proofOfPossession"?: string
207
208 // serviceAccountName is the name of the service account the pod is running as.
209 "serviceAccountName"!: string
210
211 // serviceAccountUID is the UID of the service account the pod is running as.
212 "serviceAccountUID"!: string
213
214 // signerName indicates the requested signer.
215 //
216 // All signer names beginning with `kubernetes.io` are reserved for use by the
217 // Kubernetes project. There is currently one well-known signer documented by
218 // the Kubernetes project, `kubernetes.io/kube-apiserver-client-pod`, which
219 // will issue client certificates understood by kube-apiserver. It is currently
220 // unimplemented.
221 "signerName"!: string
222
223 // A PKCS#10 certificate signing request (DER-serialized) generated by Kubelet
224 // using the subject private key.
225 //
226 // Most signer implementations will ignore the contents of the CSR except to
227 // extract the subject public key. The API server automatically verifies the
228 // CSR signature during admission, so the signer does not need to repeat the
229 // verification. CSRs generated by kubelet are completely empty.
230 //
231 // The subject public key must be one of RSA3072, RSA4096, ECDSAP256, ECDSAP384,
232 // ECDSAP521, or ED25519. Note that this list may be expanded in the future.
233 //
234 // Signer implementations do not need to support all key types supported by
235 // kube-apiserver and kubelet. If a signer does not support the key type used
236 // for a given PodCertificateRequest, it must deny the request by setting a
237 // status.conditions entry with a type of "Denied" and a reason of
238 // "UnsupportedKeyType". It may also suggest a key type that it does support in
239 // the message field.
240 "stubPKCS10Request"!: string
241
242 // unverifiedUserAnnotations allow pod authors to pass additional information to
243 // the signer implementation. Kubernetes does not restrict or validate this
244 // metadata in any way.
245 //
246 // Entries are subject to the same validation as object metadata annotations,
247 // with the addition that all keys must be domain-prefixed. No restrictions are
248 // placed on values, except an overall size limitation on the entire field.
249 //
250 // Signers should document the keys and values they support. Signers should deny
251 // requests that contain keys they do not recognize.
252 "unverifiedUserAnnotations"?: [string]: string
253}
254
255// PodCertificateRequestStatus describes the status of the request, and holds
256// the certificate data if the request is issued.
257#PodCertificateRequestStatus: {
258 // beginRefreshAt is the time at which the kubelet should begin trying to
259 // refresh the certificate. This field is set via the /status subresource, and
260 // must be set at the same time as certificateChain. Once populated, this field
261 // is immutable.
262 //
263 // This field is only a hint. Kubelet may start refreshing before or after this time if necessary.
264 "beginRefreshAt"?: v1.#Time
265
266 // certificateChain is populated with an issued certificate by the signer. This
267 // field is set via the /status subresource. Once populated, this field is
268 // immutable.
269 //
270 // If the certificate signing request is denied, a condition of type "Denied" is
271 // added and this field remains empty. If the signer cannot issue the
272 // certificate, a condition of type "Failed" is added and this field remains
273 // empty.
274 //
275 // Validation requirements:
276 // 1. certificateChain must consist of one or more PEM-formatted certificates.
277 // 2. Each entry must be a valid PEM-wrapped, DER-encoded ASN.1 Certificate as
278 // described in section 4 of RFC5280.
279 //
280 // If more than one block is present, and the definition of the requested
281 // spec.signerName does not indicate otherwise, the first block is the issued
282 // certificate, and subsequent blocks should be treated as intermediate
283 // certificates and presented in TLS handshakes. When projecting the chain into
284 // a pod volume, kubelet will drop any data in-between the PEM blocks, as well
285 // as any PEM block headers.
286 "certificateChain"?: string
287
288 // conditions applied to the request.
289 //
290 // The types "Issued", "Denied", and "Failed" have special handling. At most one
291 // of these conditions may be present, and they must have status "True".
292 //
293 // If the request is denied with `Reason=UnsupportedKeyType`, the signer may
294 // suggest a key type that will work in the message field.
295 "conditions"?: [...v1.#Condition]
296
297 // notAfter is the time at which the certificate expires. The value must be the
298 // same as the notAfter value in the leaf certificate in certificateChain. This
299 // field is set via the /status subresource. Once populated, it is immutable.
300 // The signer must set this field at the same time it sets certificateChain.
301 "notAfter"?: v1.#Time
302
303 // notBefore is the time at which the certificate becomes valid. The value must
304 // be the same as the notBefore value in the leaf certificate in
305 // certificateChain. This field is set via the /status subresource. Once
306 // populated, it is immutable. The signer must set this field at the same time
307 // it sets certificateChain.
308 "notBefore"?: v1.#Time
309}