1package v1
2
3import (
4 "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
5 "cue.dev/x/k8s.io/apimachinery/pkg/api/resource"
6 "cue.dev/x/k8s.io/apimachinery/pkg/util/intstr"
7)
8
9// Represents a Persistent Disk resource in AWS.
10//
11// An AWS EBS disk must exist before mounting to a container. The disk must also
12// be in the same AWS zone as the kubelet. An AWS EBS disk can only be mounted
13// as read/write once. AWS EBS volumes support ownership management and SELinux
14// relabeling.
15#AWSElasticBlockStoreVolumeSource: {
16 // fsType is the filesystem type of the volume that you want to mount. Tip:
17 // Ensure that the filesystem type is supported by the host operating system.
18 // Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
19 // unspecified. More info:
20 // https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
21 "fsType"?: string
22
23 // partition is the partition in the volume that you want to mount. If omitted,
24 // the default is to mount by volume name. Examples: For volume /dev/sda1, you
25 // specify the partition as "1". Similarly, the volume partition for /dev/sda
26 // is "0" (or you can leave the property empty).
27 "partition"?: int32 & int
28
29 // readOnly value true will force the readOnly setting in VolumeMounts. More
30 // info:
31 // https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
32 "readOnly"?: bool
33
34 // volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS
35 // volume). More info:
36 // https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
37 "volumeID"!: string
38}
39
40// Affinity is a group of affinity scheduling rules.
41#Affinity: {
42 // Describes node affinity scheduling rules for the pod.
43 "nodeAffinity"?: #NodeAffinity
44
45 // Describes pod affinity scheduling rules (e.g. co-locate this pod in the same
46 // node, zone, etc. as some other pod(s)).
47 "podAffinity"?: #PodAffinity
48
49 // Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in
50 // the same node, zone, etc. as some other pod(s)).
51 "podAntiAffinity"?: #PodAntiAffinity
52}
53
54// AppArmorProfile defines a pod or container's AppArmor settings.
55#AppArmorProfile: {
56 // localhostProfile indicates a profile loaded on the node that should be used.
57 // The profile must be preconfigured on the node to work. Must match the loaded
58 // name of the profile. Must be set if and only if type is "Localhost".
59 "localhostProfile"?: string
60
61 // type indicates which kind of AppArmor profile will be applied. Valid options are:
62 // Localhost - a profile pre-loaded on the node.
63 // RuntimeDefault - the container runtime's default profile.
64 // Unconfined - no AppArmor enforcement.
65 "type"!: string
66}
67
68// AttachedVolume describes a volume attached to a node
69#AttachedVolume: {
70 // DevicePath represents the device path where the volume should be available
71 "devicePath"!: string
72
73 // Name of the attached volume
74 "name"!: string
75}
76
77// AzureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.
78#AzureDiskVolumeSource: {
79 // cachingMode is the Host Caching mode: None, Read Only, Read Write.
80 "cachingMode"?: string
81
82 // diskName is the Name of the data disk in the blob storage
83 "diskName"!: string
84
85 // diskURI is the URI of data disk in the blob storage
86 "diskURI"!: string
87
88 // fsType is Filesystem type to mount. Must be a filesystem type supported by
89 // the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to
90 // be "ext4" if unspecified.
91 "fsType"?: string
92
93 // kind expected values are Shared: multiple blob disks per storage account
94 // Dedicated: single blob disk per storage account Managed: azure managed data
95 // disk (only in managed availability set). defaults to shared
96 "kind"?: string
97
98 // readOnly Defaults to false (read/write). ReadOnly here will force the
99 // ReadOnly setting in VolumeMounts.
100 "readOnly"?: bool
101}
102
103// AzureFile represents an Azure File Service mount on the host and bind mount to the pod.
104#AzureFilePersistentVolumeSource: {
105 // readOnly defaults to false (read/write). ReadOnly here will force the
106 // ReadOnly setting in VolumeMounts.
107 "readOnly"?: bool
108
109 // secretName is the name of secret that contains Azure Storage Account Name and Key
110 "secretName"!: string
111
112 // secretNamespace is the namespace of the secret that contains Azure Storage
113 // Account Name and Key default is the same as the Pod
114 "secretNamespace"?: string
115
116 // shareName is the azure Share Name
117 "shareName"!: string
118}
119
120// AzureFile represents an Azure File Service mount on the host and bind mount to the pod.
121#AzureFileVolumeSource: {
122 // readOnly defaults to false (read/write). ReadOnly here will force the
123 // ReadOnly setting in VolumeMounts.
124 "readOnly"?: bool
125
126 // secretName is the name of secret that contains Azure Storage Account Name and Key
127 "secretName"!: string
128
129 // shareName is the azure share Name
130 "shareName"!: string
131}
132
133// Binding ties one object to another; for example, a pod is bound to a node by a scheduler.
134#Binding: {
135 // APIVersion defines the versioned schema of this representation of an object.
136 // Servers should convert recognized schemas to the latest internal value, and
137 // may reject unrecognized values. More info:
138 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
139 "apiVersion": "v1"
140
141 // Kind is a string value representing the REST resource this object represents.
142 // Servers may infer this from the endpoint the client submits requests to.
143 // Cannot be updated. In CamelCase. More info:
144 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
145 "kind": "Binding"
146
147 // Standard object's metadata. More info:
148 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
149 "metadata"?: v1.#ObjectMeta
150
151 // The target object that you want to bind to the standard object.
152 "target"!: #ObjectReference
153}
154
155// Represents storage that is managed by an external CSI volume driver
156#CSIPersistentVolumeSource: {
157 // controllerExpandSecretRef is a reference to the secret object containing
158 // sensitive information to pass to the CSI driver to complete the CSI
159 // ControllerExpandVolume call. This field is optional, and may be empty if no
160 // secret is required. If the secret object contains more than one secret, all
161 // secrets are passed.
162 "controllerExpandSecretRef"?: #SecretReference
163
164 // controllerPublishSecretRef is a reference to the secret object containing
165 // sensitive information to pass to the CSI driver to complete the CSI
166 // ControllerPublishVolume and ControllerUnpublishVolume calls. This field is
167 // optional, and may be empty if no secret is required. If the secret object
168 // contains more than one secret, all secrets are passed.
169 "controllerPublishSecretRef"?: #SecretReference
170
171 // driver is the name of the driver to use for this volume. Required.
172 "driver"!: string
173
174 // fsType to mount. Must be a filesystem type supported by the host operating
175 // system. Ex. "ext4", "xfs", "ntfs".
176 "fsType"?: string
177
178 // nodeExpandSecretRef is a reference to the secret object containing sensitive
179 // information to pass to the CSI driver to complete the CSI NodeExpandVolume
180 // call. This field is optional, may be omitted if no secret is required. If
181 // the secret object contains more than one secret, all secrets are passed.
182 "nodeExpandSecretRef"?: #SecretReference
183
184 // nodePublishSecretRef is a reference to the secret object containing sensitive
185 // information to pass to the CSI driver to complete the CSI NodePublishVolume
186 // and NodeUnpublishVolume calls. This field is optional, and may be empty if
187 // no secret is required. If the secret object contains more than one secret,
188 // all secrets are passed.
189 "nodePublishSecretRef"?: #SecretReference
190
191 // nodeStageSecretRef is a reference to the secret object containing sensitive
192 // information to pass to the CSI driver to complete the CSI NodeStageVolume
193 // and NodeStageVolume and NodeUnstageVolume calls. This field is optional, and
194 // may be empty if no secret is required. If the secret object contains more
195 // than one secret, all secrets are passed.
196 "nodeStageSecretRef"?: #SecretReference
197
198 // readOnly value to pass to ControllerPublishVolumeRequest. Defaults to false (read/write).
199 "readOnly"?: bool
200
201 // volumeAttributes of the volume to publish.
202 "volumeAttributes"?: [string]: string
203
204 // volumeHandle is the unique volume name returned by the CSI volume plugin’s
205 // CreateVolume to refer to the volume on all subsequent calls. Required.
206 "volumeHandle"!: string
207}
208
209// Represents a source location of a volume to mount, managed by an external CSI driver
210#CSIVolumeSource: {
211 // driver is the name of the CSI driver that handles this volume. Consult with
212 // your admin for the correct name as registered in the cluster.
213 "driver"!: string
214
215 // fsType to mount. Ex. "ext4", "xfs", "ntfs". If not provided, the empty value
216 // is passed to the associated CSI driver which will determine the default
217 // filesystem to apply.
218 "fsType"?: string
219
220 // nodePublishSecretRef is a reference to the secret object containing sensitive
221 // information to pass to the CSI driver to complete the CSI NodePublishVolume
222 // and NodeUnpublishVolume calls. This field is optional, and may be empty if
223 // no secret is required. If the secret object contains more than one secret,
224 // all secret references are passed.
225 "nodePublishSecretRef"?: #LocalObjectReference
226
227 // readOnly specifies a read-only configuration for the volume. Defaults to false (read/write).
228 "readOnly"?: bool
229
230 // volumeAttributes stores driver-specific properties that are passed to the CSI
231 // driver. Consult your driver's documentation for supported values.
232 "volumeAttributes"?: [string]: string
233}
234
235// Adds and removes POSIX capabilities from running containers.
236#Capabilities: {
237 // Added capabilities
238 "add"?: [...string]
239
240 // Removed capabilities
241 "drop"?: [...string]
242}
243
244// Represents a Ceph Filesystem mount that lasts the lifetime of a pod Cephfs
245// volumes do not support ownership management or SELinux relabeling.
246#CephFSPersistentVolumeSource: {
247 // monitors is Required: Monitors is a collection of Ceph monitors More info:
248 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
249 "monitors"!: [...string]
250
251 // path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /
252 "path"?: string
253
254 // readOnly is Optional: Defaults to false (read/write). ReadOnly here will
255 // force the ReadOnly setting in VolumeMounts. More info:
256 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
257 "readOnly"?: bool
258
259 // secretFile is Optional: SecretFile is the path to key ring for User, default
260 // is /etc/ceph/user.secret More info:
261 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
262 "secretFile"?: string
263
264 // secretRef is Optional: SecretRef is reference to the authentication secret
265 // for User, default is empty. More info:
266 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
267 "secretRef"?: #SecretReference
268
269 // user is Optional: User is the rados user name, default is admin More info:
270 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
271 "user"?: string
272}
273
274// Represents a Ceph Filesystem mount that lasts the lifetime of a pod Cephfs
275// volumes do not support ownership management or SELinux relabeling.
276#CephFSVolumeSource: {
277 // monitors is Required: Monitors is a collection of Ceph monitors More info:
278 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
279 "monitors"!: [...string]
280
281 // path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /
282 "path"?: string
283
284 // readOnly is Optional: Defaults to false (read/write). ReadOnly here will
285 // force the ReadOnly setting in VolumeMounts. More info:
286 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
287 "readOnly"?: bool
288
289 // secretFile is Optional: SecretFile is the path to key ring for User, default
290 // is /etc/ceph/user.secret More info:
291 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
292 "secretFile"?: string
293
294 // secretRef is Optional: SecretRef is reference to the authentication secret
295 // for User, default is empty. More info:
296 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
297 "secretRef"?: #LocalObjectReference
298
299 // user is optional: User is the rados user name, default is admin More info:
300 // https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
301 "user"?: string
302}
303
304// Represents a cinder volume resource in Openstack. A Cinder volume must exist
305// before mounting to a container. The volume must also be in the same region
306// as the kubelet. Cinder volumes support ownership management and SELinux
307// relabeling.
308#CinderPersistentVolumeSource: {
309 // fsType Filesystem type to mount. Must be a filesystem type supported by the
310 // host operating system. Examples: "ext4", "xfs", "ntfs". Implicitly inferred
311 // to be "ext4" if unspecified. More info:
312 // https://examples.k8s.io/mysql-cinder-pd/README.md
313 "fsType"?: string
314
315 // readOnly is Optional: Defaults to false (read/write). ReadOnly here will
316 // force the ReadOnly setting in VolumeMounts. More info:
317 // https://examples.k8s.io/mysql-cinder-pd/README.md
318 "readOnly"?: bool
319
320 // secretRef is Optional: points to a secret object containing parameters used
321 // to connect to OpenStack.
322 "secretRef"?: #SecretReference
323
324 // volumeID used to identify the volume in cinder. More info:
325 // https://examples.k8s.io/mysql-cinder-pd/README.md
326 "volumeID"!: string
327}
328
329// Represents a cinder volume resource in Openstack. A Cinder volume must exist
330// before mounting to a container. The volume must also be in the same region
331// as the kubelet. Cinder volumes support ownership management and SELinux
332// relabeling.
333#CinderVolumeSource: {
334 // fsType is the filesystem type to mount. Must be a filesystem type supported
335 // by the host operating system. Examples: "ext4", "xfs", "ntfs". Implicitly
336 // inferred to be "ext4" if unspecified. More info:
337 // https://examples.k8s.io/mysql-cinder-pd/README.md
338 "fsType"?: string
339
340 // readOnly defaults to false (read/write). ReadOnly here will force the
341 // ReadOnly setting in VolumeMounts. More info:
342 // https://examples.k8s.io/mysql-cinder-pd/README.md
343 "readOnly"?: bool
344
345 // secretRef is optional: points to a secret object containing parameters used
346 // to connect to OpenStack.
347 "secretRef"?: #LocalObjectReference
348
349 // volumeID used to identify the volume in cinder. More info:
350 // https://examples.k8s.io/mysql-cinder-pd/README.md
351 "volumeID"!: string
352}
353
354// ClientIPConfig represents the configurations of Client IP based session affinity.
355#ClientIPConfig: {
356 // timeoutSeconds specifies the seconds of ClientIP type session sticky time.
357 // The value must be >0 && <=86400(for 1 day) if ServiceAffinity == "ClientIP".
358 // Default value is 10800(for 3 hours).
359 "timeoutSeconds"?: int32 & int
360}
361
362// ClusterTrustBundleProjection describes how to select a set of
363// ClusterTrustBundle objects and project their contents into the pod
364// filesystem.
365#ClusterTrustBundleProjection: {
366 // Select all ClusterTrustBundles that match this label selector. Only has
367 // effect if signerName is set. Mutually-exclusive with name. If unset,
368 // interpreted as "match nothing". If set but empty, interpreted as "match
369 // everything".
370 "labelSelector"?: v1.#LabelSelector
371
372 // Select a single ClusterTrustBundle by object name. Mutually-exclusive with
373 // signerName and labelSelector.
374 "name"?: string
375
376 // If true, don't block pod startup if the referenced ClusterTrustBundle(s)
377 // aren't available. If using name, then the named ClusterTrustBundle is
378 // allowed not to exist. If using signerName, then the combination of
379 // signerName and labelSelector is allowed to match zero ClusterTrustBundles.
380 "optional"?: bool
381
382 // Relative path from the volume root to write the bundle.
383 "path"!: string
384
385 // Select all ClusterTrustBundles that match this signer name.
386 // Mutually-exclusive with name. The contents of all selected
387 // ClusterTrustBundles will be unified and deduplicated.
388 "signerName"?: string
389}
390
391// Information about the condition of a component.
392#ComponentCondition: {
393 // Condition error code for a component. For example, a health check error code.
394 "error"?: string
395
396 // Message about the condition for a component. For example, information about a health check.
397 "message"?: string
398
399 // Status of the condition for a component. Valid values for "Healthy": "True",
400 // "False", or "Unknown".
401 "status"!: string
402
403 // Type of condition for a component. Valid value: "Healthy"
404 "type"!: string
405}
406
407// ComponentStatus (and ComponentStatusList) holds the cluster validation info.
408// Deprecated: This API is deprecated in v1.19+
409#ComponentStatus: {
410 // APIVersion defines the versioned schema of this representation of an object.
411 // Servers should convert recognized schemas to the latest internal value, and
412 // may reject unrecognized values. More info:
413 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
414 "apiVersion": "v1"
415
416 // List of component conditions observed
417 "conditions"?: [...#ComponentCondition]
418
419 // Kind is a string value representing the REST resource this object represents.
420 // Servers may infer this from the endpoint the client submits requests to.
421 // Cannot be updated. In CamelCase. More info:
422 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
423 "kind": "ComponentStatus"
424
425 // Standard object's metadata. More info:
426 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
427 "metadata"?: v1.#ObjectMeta
428}
429
430// Status of all the conditions for the component as a list of ComponentStatus
431// objects. Deprecated: This API is deprecated in v1.19+
432#ComponentStatusList: {
433 // APIVersion defines the versioned schema of this representation of an object.
434 // Servers should convert recognized schemas to the latest internal value, and
435 // may reject unrecognized values. More info:
436 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
437 "apiVersion": "v1"
438
439 // List of ComponentStatus objects.
440 "items"!: [...#ComponentStatus]
441
442 // Kind is a string value representing the REST resource this object represents.
443 // Servers may infer this from the endpoint the client submits requests to.
444 // Cannot be updated. In CamelCase. More info:
445 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
446 "kind": "ComponentStatusList"
447
448 // Standard list metadata. More info:
449 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
450 "metadata"?: v1.#ListMeta
451}
452
453// ConfigMap holds configuration data for pods to consume.
454#ConfigMap: {
455 // APIVersion defines the versioned schema of this representation of an object.
456 // Servers should convert recognized schemas to the latest internal value, and
457 // may reject unrecognized values. More info:
458 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
459 "apiVersion": "v1"
460
461 // BinaryData contains the binary data. Each key must consist of alphanumeric
462 // characters, '-', '_' or '.'. BinaryData can contain byte sequences that are
463 // not in the UTF-8 range. The keys stored in BinaryData must not overlap with
464 // the ones in the Data field, this is enforced during validation process.
465 // Using this field will require 1.10+ apiserver and kubelet.
466 "binaryData"?: [string]: string
467
468 // Data contains the configuration data. Each key must consist of alphanumeric
469 // characters, '-', '_' or '.'. Values with non-UTF-8 byte sequences must use
470 // the BinaryData field. The keys stored in Data must not overlap with the keys
471 // in the BinaryData field, this is enforced during validation process.
472 "data"?: [string]: string
473
474 // Immutable, if set to true, ensures that data stored in the ConfigMap cannot
475 // be updated (only object metadata can be modified). If not set to true, the
476 // field can be modified at any time. Defaulted to nil.
477 "immutable"?: bool
478
479 // Kind is a string value representing the REST resource this object represents.
480 // Servers may infer this from the endpoint the client submits requests to.
481 // Cannot be updated. In CamelCase. More info:
482 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
483 "kind": "ConfigMap"
484
485 // Standard object's metadata. More info:
486 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
487 "metadata"?: v1.#ObjectMeta
488}
489
490// ConfigMapEnvSource selects a ConfigMap to populate the environment variables with.
491//
492// The contents of the target ConfigMap's Data field will represent the
493// key-value pairs as environment variables.
494#ConfigMapEnvSource: {
495 // Name of the referent. This field is effectively required, but due to
496 // backwards compatibility is allowed to be empty. Instances of this type with
497 // an empty value here are almost certainly wrong. More info:
498 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
499 "name"?: string
500
501 // Specify whether the ConfigMap must be defined
502 "optional"?: bool
503}
504
505// Selects a key from a ConfigMap.
506#ConfigMapKeySelector: {
507 // The key to select.
508 "key"!: string
509
510 // Name of the referent. This field is effectively required, but due to
511 // backwards compatibility is allowed to be empty. Instances of this type with
512 // an empty value here are almost certainly wrong. More info:
513 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
514 "name"?: string
515
516 // Specify whether the ConfigMap or its key must be defined
517 "optional"?: bool
518}
519
520// ConfigMapList is a resource containing a list of ConfigMap objects.
521#ConfigMapList: {
522 // APIVersion defines the versioned schema of this representation of an object.
523 // Servers should convert recognized schemas to the latest internal value, and
524 // may reject unrecognized values. More info:
525 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
526 "apiVersion": "v1"
527
528 // Items is the list of ConfigMaps.
529 "items"!: [...#ConfigMap]
530
531 // Kind is a string value representing the REST resource this object represents.
532 // Servers may infer this from the endpoint the client submits requests to.
533 // Cannot be updated. In CamelCase. More info:
534 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
535 "kind": "ConfigMapList"
536
537 // More info:
538 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
539 "metadata"?: v1.#ListMeta
540}
541
542// ConfigMapNodeConfigSource contains the information to reference a ConfigMap
543// as a config source for the Node. This API is deprecated since 1.22:
544// https://git.k8s.io/enhancements/keps/sig-node/281-dynamic-kubelet-configuration
545#ConfigMapNodeConfigSource: {
546 // KubeletConfigKey declares which key of the referenced ConfigMap corresponds
547 // to the KubeletConfiguration structure This field is required in all cases.
548 "kubeletConfigKey"!: string
549
550 // Name is the metadata.name of the referenced ConfigMap. This field is required in all cases.
551 "name"!: string
552
553 // Namespace is the metadata.namespace of the referenced ConfigMap. This field
554 // is required in all cases.
555 "namespace"!: string
556
557 // ResourceVersion is the metadata.ResourceVersion of the referenced ConfigMap.
558 // This field is forbidden in Node.Spec, and required in Node.Status.
559 "resourceVersion"?: string
560
561 // UID is the metadata.UID of the referenced ConfigMap. This field is forbidden
562 // in Node.Spec, and required in Node.Status.
563 "uid"?: string
564}
565
566// Adapts a ConfigMap into a projected volume.
567//
568// The contents of the target ConfigMap's Data field will be presented in a
569// projected volume as files using the keys in the Data field as the file
570// names, unless the items element is populated with specific mappings of keys
571// to paths. Note that this is identical to a configmap volume source without
572// the default mode.
573#ConfigMapProjection: {
574 // items if unspecified, each key-value pair in the Data field of the referenced
575 // ConfigMap will be projected into the volume as a file whose name is the key
576 // and content is the value. If specified, the listed keys will be projected
577 // into the specified paths, and unlisted keys will not be present. If a key is
578 // specified which is not present in the ConfigMap, the volume setup will error
579 // unless it is marked optional. Paths must be relative and may not contain the
580 // '..' path or start with '..'.
581 "items"?: [...#KeyToPath]
582
583 // Name of the referent. This field is effectively required, but due to
584 // backwards compatibility is allowed to be empty. Instances of this type with
585 // an empty value here are almost certainly wrong. More info:
586 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
587 "name"?: string
588
589 // optional specify whether the ConfigMap or its keys must be defined
590 "optional"?: bool
591}
592
593// Adapts a ConfigMap into a volume.
594//
595// The contents of the target ConfigMap's Data field will be presented in a
596// volume as files using the keys in the Data field as the file names, unless
597// the items element is populated with specific mappings of keys to paths.
598// ConfigMap volumes support ownership management and SELinux relabeling.
599#ConfigMapVolumeSource: {
600 // defaultMode is optional: mode bits used to set permissions on created files
601 // by default. Must be an octal value between 0000 and 0777 or a decimal value
602 // between 0 and 511. YAML accepts both octal and decimal values, JSON requires
603 // decimal values for mode bits. Defaults to 0644. Directories within the path
604 // are not affected by this setting. This might be in conflict with other
605 // options that affect the file mode, like fsGroup, and the result can be other
606 // mode bits set.
607 "defaultMode"?: int32 & int
608
609 // items if unspecified, each key-value pair in the Data field of the referenced
610 // ConfigMap will be projected into the volume as a file whose name is the key
611 // and content is the value. If specified, the listed keys will be projected
612 // into the specified paths, and unlisted keys will not be present. If a key is
613 // specified which is not present in the ConfigMap, the volume setup will error
614 // unless it is marked optional. Paths must be relative and may not contain the
615 // '..' path or start with '..'.
616 "items"?: [...#KeyToPath]
617
618 // Name of the referent. This field is effectively required, but due to
619 // backwards compatibility is allowed to be empty. Instances of this type with
620 // an empty value here are almost certainly wrong. More info:
621 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
622 "name"?: string
623
624 // optional specify whether the ConfigMap or its keys must be defined
625 "optional"?: bool
626}
627
628// A single application container that you want to run within a pod.
629#Container: {
630 // Arguments to the entrypoint. The container image's CMD is used if this is not
631 // provided. Variable references $(VAR_NAME) are expanded using the container's
632 // environment. If a variable cannot be resolved, the reference in the input
633 // string will be unchanged. Double $$ are reduced to a single $, which allows
634 // for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the
635 // string literal "$(VAR_NAME)". Escaped references will never be expanded,
636 // regardless of whether the variable exists or not. Cannot be updated. More
637 // info:
638 // https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
639 "args"?: [...string]
640
641 // Entrypoint array. Not executed within a shell. The container image's
642 // ENTRYPOINT is used if this is not provided. Variable references $(VAR_NAME)
643 // are expanded using the container's environment. If a variable cannot be
644 // resolved, the reference in the input string will be unchanged. Double $$ are
645 // reduced to a single $, which allows for escaping the $(VAR_NAME) syntax:
646 // i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
647 // references will never be expanded, regardless of whether the variable exists
648 // or not. Cannot be updated. More info:
649 // https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
650 "command"?: [...string]
651
652 // List of environment variables to set in the container. Cannot be updated.
653 "env"?: [...#EnvVar]
654
655 // List of sources to populate environment variables in the container. The keys
656 // defined within a source may consist of any printable ASCII characters except
657 // '='. When a key exists in multiple sources, the value associated with the
658 // last source will take precedence. Values defined by an Env with a duplicate
659 // key will take precedence. Cannot be updated.
660 "envFrom"?: [...#EnvFromSource]
661
662 // Container image name. More info:
663 // https://kubernetes.io/docs/concepts/containers/images This field is optional
664 // to allow higher level config management to default or override container
665 // images in workload controllers like Deployments and StatefulSets.
666 "image"?: string
667
668 // Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if
669 // :latest tag is specified, or IfNotPresent otherwise. Cannot be updated. More
670 // info: https://kubernetes.io/docs/concepts/containers/images#updating-images
671 "imagePullPolicy"?: string
672
673 // Actions that the management system should take in response to container
674 // lifecycle events. Cannot be updated.
675 "lifecycle"?: #Lifecycle
676
677 // Periodic probe of container liveness. Container will be restarted if the
678 // probe fails. Cannot be updated. More info:
679 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
680 "livenessProbe"?: #Probe
681
682 // Name of the container specified as a DNS_LABEL. Each container in a pod must
683 // have a unique name (DNS_LABEL). Cannot be updated.
684 "name"!: string
685
686 // List of ports to expose from the container. Not specifying a port here DOES
687 // NOT prevent that port from being exposed. Any port which is listening on the
688 // default "0.0.0.0" address inside a container will be accessible from the
689 // network. Modifying this array with strategic merge patch may corrupt the
690 // data. For more information See
691 // https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
692 "ports"?: [...#ContainerPort]
693
694 // Periodic probe of container service readiness. Container will be removed from
695 // service endpoints if the probe fails. Cannot be updated. More info:
696 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
697 "readinessProbe"?: #Probe
698
699 // Resources resize policy for the container. This field cannot be set on ephemeral containers.
700 "resizePolicy"?: [...#ContainerResizePolicy]
701
702 // Compute Resources required by this container. Cannot be updated. More info:
703 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
704 "resources"?: #ResourceRequirements
705
706 // RestartPolicy defines the restart behavior of individual containers in a pod.
707 // This overrides the pod-level restart policy. When this field is not
708 // specified, the restart behavior is defined by the Pod's restart policy and
709 // the container type. Additionally, setting the RestartPolicy as "Always" for
710 // the init container will have the following effect: this init container will
711 // be continually restarted on exit until all regular containers have
712 // terminated. Once all regular containers have completed, all init containers
713 // with restartPolicy "Always" will be shut down. This lifecycle differs from
714 // normal init containers and is often referred to as a "sidecar" container.
715 // Although this init container still starts in the init container sequence, it
716 // does not wait for the container to complete before proceeding to the next
717 // init container. Instead, the next init container starts immediately after
718 // this init container is started, or after any startupProbe has successfully
719 // completed.
720 "restartPolicy"?: string
721
722 // Represents a list of rules to be checked to determine if the container should
723 // be restarted on exit. The rules are evaluated in order. Once a rule matches
724 // a container exit condition, the remaining rules are ignored. If no rule
725 // matches the container exit condition, the Container-level restart policy
726 // determines the whether the container is restarted or not. Constraints on the
727 // rules: - At most 20 rules are allowed. - Rules can have the same action. -
728 // Identical rules are not forbidden in validations. When rules are specified,
729 // container MUST set RestartPolicy explicitly even it if matches the Pod's
730 // RestartPolicy.
731 "restartPolicyRules"?: [...#ContainerRestartRule]
732
733 // SecurityContext defines the security options the container should be run
734 // with. If set, the fields of SecurityContext override the equivalent fields
735 // of PodSecurityContext. More info:
736 // https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
737 "securityContext"?: #SecurityContext
738
739 // StartupProbe indicates that the Pod has successfully initialized. If
740 // specified, no other probes are executed until this completes successfully.
741 // If this probe fails, the Pod will be restarted, just as if the livenessProbe
742 // failed. This can be used to provide different probe parameters at the
743 // beginning of a Pod's lifecycle, when it might take a long time to load data
744 // or warm a cache, than during steady-state operation. This cannot be updated.
745 // More info:
746 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
747 "startupProbe"?: #Probe
748
749 // Whether this container should allocate a buffer for stdin in the container
750 // runtime. If this is not set, reads from stdin in the container will always
751 // result in EOF. Default is false.
752 "stdin"?: bool
753
754 // Whether the container runtime should close the stdin channel after it has
755 // been opened by a single attach. When stdin is true the stdin stream will
756 // remain open across multiple attach sessions. If stdinOnce is set to true,
757 // stdin is opened on container start, is empty until the first client attaches
758 // to stdin, and then remains open and accepts data until the client
759 // disconnects, at which time stdin is closed and remains closed until the
760 // container is restarted. If this flag is false, a container processes that
761 // reads from stdin will never receive an EOF. Default is false
762 "stdinOnce"?: bool
763
764 // Optional: Path at which the file to which the container's termination message
765 // will be written is mounted into the container's filesystem. Message written
766 // is intended to be brief final status, such as an assertion failure message.
767 // Will be truncated by the node if greater than 4096 bytes. The total message
768 // length across all containers will be limited to 12kb. Defaults to
769 // /dev/termination-log. Cannot be updated.
770 "terminationMessagePath"?: string
771
772 // Indicate how the termination message should be populated. File will use the
773 // contents of terminationMessagePath to populate the container status message
774 // on both success and failure. FallbackToLogsOnError will use the last chunk
775 // of container log output if the termination message file is empty and the
776 // container exited with an error. The log output is limited to 2048 bytes or
777 // 80 lines, whichever is smaller. Defaults to File. Cannot be updated.
778 "terminationMessagePolicy"?: string
779
780 // Whether this container should allocate a TTY for itself, also requires
781 // 'stdin' to be true. Default is false.
782 "tty"?: bool
783
784 // volumeDevices is the list of block devices to be used by the container.
785 "volumeDevices"?: [...#VolumeDevice]
786
787 // Pod volumes to mount into the container's filesystem. Cannot be updated.
788 "volumeMounts"?: [...#VolumeMount]
789
790 // Container's working directory. If not specified, the container runtime's
791 // default will be used, which might be configured in the container image.
792 // Cannot be updated.
793 "workingDir"?: string
794}
795
796// ContainerExtendedResourceRequest has the mapping of container name, extended
797// resource name to the device request name.
798#ContainerExtendedResourceRequest: {
799 // The name of the container requesting resources.
800 "containerName"!: string
801
802 // The name of the request in the special ResourceClaim which corresponds to the extended resource.
803 "requestName"!: string
804
805 // The name of the extended resource in that container which gets backed by DRA.
806 "resourceName"!: string
807}
808
809// Describe a container image
810#ContainerImage: {
811 // Names by which this image is known. e.g.
812 // ["kubernetes.example/hyperkube:v1.0.7",
813 // "cloud-vendor.registry.example/cloud-vendor/hyperkube:v1.0.7"]
814 "names"?: [...string]
815
816 // The size of the image in bytes.
817 "sizeBytes"?: int64 & int
818}
819
820// ContainerPort represents a network port in a single container.
821#ContainerPort: {
822 // Number of port to expose on the pod's IP address. This must be a valid port
823 // number, 0 < x < 65536.
824 "containerPort"!: int32 & int
825
826 // What host IP to bind the external port to.
827 "hostIP"?: string
828
829 // Number of port to expose on the host. If specified, this must be a valid port
830 // number, 0 < x < 65536. If HostNetwork is specified, this must match
831 // ContainerPort. Most containers do not need this.
832 "hostPort"?: int32 & int
833
834 // If specified, this must be an IANA_SVC_NAME and unique within the pod. Each
835 // named port in a pod must have a unique name. Name for the port that can be
836 // referred to by services.
837 "name"?: string
838
839 // Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
840 "protocol"?: string
841}
842
843// ContainerResizePolicy represents resource resize policy for the container.
844#ContainerResizePolicy: {
845 // Name of the resource to which this resource resize policy applies. Supported values: cpu, memory.
846 "resourceName"!: string
847
848 // Restart policy to apply when specified resource is resized. If not specified,
849 // it defaults to NotRequired.
850 "restartPolicy"!: string
851}
852
853// ContainerRestartRule describes how a container exit is handled.
854#ContainerRestartRule: {
855 // Specifies the action taken on a container exit if the requirements are
856 // satisfied. The only possible value is "Restart" to restart the container.
857 "action"!: string
858
859 // Represents the exit codes to check on container exits.
860 "exitCodes"?: #ContainerRestartRuleOnExitCodes
861}
862
863// ContainerRestartRuleOnExitCodes describes the condition for handling an
864// exited container based on its exit codes.
865#ContainerRestartRuleOnExitCodes: {
866 // Represents the relationship between the container exit code(s) and the
867 // specified values. Possible values are: - In: the requirement is satisfied if
868 // the container exit code is in the
869 // set of specified values.
870 // - NotIn: the requirement is satisfied if the container exit code is
871 // not in the set of specified values.
872 "operator"!: string
873
874 // Specifies the set of values to check for container exit codes. At most 255 elements are allowed.
875 "values"?: [...int32 & int]
876}
877
878// ContainerState holds a possible state of container. Only one of its members
879// may be specified. If none of them is specified, the default one is
880// ContainerStateWaiting.
881#ContainerState: {
882 // Details about a running container
883 "running"?: #ContainerStateRunning
884
885 // Details about a terminated container
886 "terminated"?: #ContainerStateTerminated
887
888 // Details about a waiting container
889 "waiting"?: #ContainerStateWaiting
890}
891
892// ContainerStateRunning is a running state of a container.
893#ContainerStateRunning: {
894 // Time at which the container was last (re-)started
895 "startedAt"?: v1.#Time
896}
897
898// ContainerStateTerminated is a terminated state of a container.
899#ContainerStateTerminated: {
900 // Container's ID in the format '<type>://<container_id>'
901 "containerID"?: string
902
903 // Exit status from the last termination of the container
904 "exitCode"!: int32 & int
905
906 // Time at which the container last terminated
907 "finishedAt"?: v1.#Time
908
909 // Message regarding the last termination of the container
910 "message"?: string
911
912 // (brief) reason from the last termination of the container
913 "reason"?: string
914
915 // Signal from the last termination of the container
916 "signal"?: int32 & int
917
918 // Time at which previous execution of the container started
919 "startedAt"?: v1.#Time
920}
921
922// ContainerStateWaiting is a waiting state of a container.
923#ContainerStateWaiting: {
924 // Message regarding why the container is not yet running.
925 "message"?: string
926
927 // (brief) reason the container is not yet running.
928 "reason"?: string
929}
930
931// ContainerStatus contains details for the current status of this container.
932#ContainerStatus: {
933 // AllocatedResources represents the compute resources allocated for this
934 // container by the node. Kubelet sets this value to
935 // Container.Resources.Requests upon successful pod admission and after
936 // successfully admitting desired pod resize.
937 "allocatedResources"?: [string]: resource.#Quantity
938
939 // AllocatedResourcesStatus represents the status of various resources allocated for this Pod.
940 "allocatedResourcesStatus"?: [...#ResourceStatus]
941
942 // ContainerID is the ID of the container in the format
943 // '<type>://<container_id>'. Where type is a container runtime identifier,
944 // returned from Version call of CRI API (for example "containerd").
945 "containerID"?: string
946
947 // Image is the name of container image that the container is running. The
948 // container image may not match the image used in the PodSpec, as it may have
949 // been resolved by the runtime. More info:
950 // https://kubernetes.io/docs/concepts/containers/images.
951 "image"!: string
952
953 // ImageID is the image ID of the container's image. The image ID may not match
954 // the image ID of the image used in the PodSpec, as it may have been resolved
955 // by the runtime.
956 "imageID"!: string
957
958 // LastTerminationState holds the last termination state of the container to
959 // help debug container crashes and restarts. This field is not populated if
960 // the container is still running and RestartCount is 0.
961 "lastState"?: #ContainerState
962
963 // Name is a DNS_LABEL representing the unique name of the container. Each
964 // container in a pod must have a unique name across all container types.
965 // Cannot be updated.
966 "name"!: string
967
968 // Ready specifies whether the container is currently passing its readiness
969 // check. The value will change as readiness probes keep executing. If no
970 // readiness probes are specified, this field defaults to true once the
971 // container is fully started (see Started field).
972 //
973 // The value is typically used to determine whether a container is ready to accept traffic.
974 "ready"!: bool
975
976 // Resources represents the compute resource requests and limits that have been
977 // successfully enacted on the running container after it has been started or
978 // has been successfully resized.
979 "resources"?: #ResourceRequirements
980
981 // RestartCount holds the number of times the container has been restarted.
982 // Kubelet makes an effort to always increment the value, but there are cases
983 // when the state may be lost due to node restarts and then the value may be
984 // reset to 0. The value is never negative.
985 "restartCount"!: int32 & int
986
987 // Started indicates whether the container has finished its postStart lifecycle
988 // hook and passed its startup probe. Initialized as false, becomes true after
989 // startupProbe is considered successful. Resets to false when the container is
990 // restarted, or if kubelet loses state temporarily. In both cases, startup
991 // probes will run again. Is always true when no startupProbe is defined and
992 // container is running and has passed the postStart lifecycle hook. The null
993 // value must be treated the same as false.
994 "started"?: bool
995
996 // State holds details about the container's current condition.
997 "state"?: #ContainerState
998
999 // StopSignal reports the effective stop signal for this container
1000 "stopSignal"?: string
1001
1002 // User represents user identity information initially attached to the first
1003 // process of the container
1004 "user"?: #ContainerUser
1005
1006 // Status of volume mounts.
1007 "volumeMounts"?: [...#VolumeMountStatus]
1008}
1009
1010// ContainerUser represents user identity information
1011#ContainerUser: {
1012 // Linux holds user identity information initially attached to the first process
1013 // of the containers in Linux. Note that the actual running identity can be
1014 // changed if the process has enough privilege to do so.
1015 "linux"?: #LinuxContainerUser
1016}
1017
1018// DaemonEndpoint contains information about a single Daemon endpoint.
1019#DaemonEndpoint: {
1020 // Port number of the given endpoint.
1021 "Port"!: int32 & int
1022}
1023
1024// Represents downward API info for projecting into a projected volume. Note
1025// that this is identical to a downwardAPI volume source without the default
1026// mode.
1027#DownwardAPIProjection: {
1028 // Items is a list of DownwardAPIVolume file
1029 "items"?: [...#DownwardAPIVolumeFile]
1030}
1031
1032// DownwardAPIVolumeFile represents information to create the file containing the pod field
1033#DownwardAPIVolumeFile: {
1034 // Required: Selects a field of the pod: only annotations, labels, name,
1035 // namespace and uid are supported.
1036 "fieldRef"?: #ObjectFieldSelector
1037
1038 // Optional: mode bits used to set permissions on this file, must be an octal
1039 // value between 0000 and 0777 or a decimal value between 0 and 511. YAML
1040 // accepts both octal and decimal values, JSON requires decimal values for mode
1041 // bits. If not specified, the volume defaultMode will be used. This might be
1042 // in conflict with other options that affect the file mode, like fsGroup, and
1043 // the result can be other mode bits set.
1044 "mode"?: int32 & int
1045
1046 // Required: Path is the relative path name of the file to be created. Must not
1047 // be absolute or contain the '..' path. Must be utf-8 encoded. The first item
1048 // of the relative path must not start with '..'
1049 "path"!: string
1050
1051 // Selects a resource of the container: only resources limits and requests
1052 // (limits.cpu, limits.memory, requests.cpu and requests.memory) are currently
1053 // supported.
1054 "resourceFieldRef"?: #ResourceFieldSelector
1055}
1056
1057// DownwardAPIVolumeSource represents a volume containing downward API info.
1058// Downward API volumes support ownership management and SELinux relabeling.
1059#DownwardAPIVolumeSource: {
1060 // Optional: mode bits to use on created files by default. Must be a Optional:
1061 // mode bits used to set permissions on created files by default. Must be an
1062 // octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
1063 // accepts both octal and decimal values, JSON requires decimal values for mode
1064 // bits. Defaults to 0644. Directories within the path are not affected by this
1065 // setting. This might be in conflict with other options that affect the file
1066 // mode, like fsGroup, and the result can be other mode bits set.
1067 "defaultMode"?: int32 & int
1068
1069 // Items is a list of downward API volume file
1070 "items"?: [...#DownwardAPIVolumeFile]
1071}
1072
1073// Represents an empty directory for a pod. Empty directory volumes support
1074// ownership management and SELinux relabeling.
1075#EmptyDirVolumeSource: {
1076 // medium represents what type of storage medium should back this directory. The
1077 // default is "" which means to use the node's default medium. Must be an empty
1078 // string (default) or Memory. More info:
1079 // https://kubernetes.io/docs/concepts/storage/volumes#emptydir
1080 "medium"?: string
1081
1082 // sizeLimit is the total amount of local storage required for this EmptyDir
1083 // volume. The size limit is also applicable for memory medium. The maximum
1084 // usage on memory medium EmptyDir would be the minimum value between the
1085 // SizeLimit specified here and the sum of memory limits of all containers in a
1086 // pod. The default is nil which means that the limit is undefined. More info:
1087 // https://kubernetes.io/docs/concepts/storage/volumes#emptydir
1088 "sizeLimit"?: resource.#Quantity
1089}
1090
1091// EndpointAddress is a tuple that describes single IP address. Deprecated: This
1092// API is deprecated in v1.33+.
1093#EndpointAddress: {
1094 // The Hostname of this endpoint
1095 "hostname"?: string
1096
1097 // The IP of this endpoint. May not be loopback (127.0.0.0/8 or ::1), link-local
1098 // (169.254.0.0/16 or fe80::/10), or link-local multicast (224.0.0.0/24 or
1099 // ff02::/16).
1100 "ip"!: string
1101
1102 // Optional: Node hosting this endpoint. This can be used to determine endpoints local to a node.
1103 "nodeName"?: string
1104
1105 // Reference to object providing the endpoint.
1106 "targetRef"?: #ObjectReference
1107}
1108
1109// EndpointPort is a tuple that describes a single port. Deprecated: This API is
1110// deprecated in v1.33+.
1111#EndpointPort: {
1112 // The application protocol for this port. This is used as a hint for
1113 // implementations to offer richer behavior for protocols that they understand.
1114 // This field follows standard Kubernetes label syntax. Valid values are
1115 // either:
1116 //
1117 // * Un-prefixed protocol names - reserved for IANA standard service names (as
1118 // per RFC-6335 and https://www.iana.org/assignments/service-names).
1119 //
1120 // * Kubernetes-defined prefixed names:
1121 // * 'kubernetes.io/h2c' - HTTP/2 prior knowledge over cleartext as described in
1122 // https://www.rfc-editor.org/rfc/rfc9113.html#name-starting-http-2-with-prior-
1123 // * 'kubernetes.io/ws' - WebSocket over cleartext as described in
1124 // https://www.rfc-editor.org/rfc/rfc6455
1125 // * 'kubernetes.io/wss' - WebSocket over TLS as described in https://www.rfc-editor.org/rfc/rfc6455
1126 //
1127 // * Other protocols should use implementation-defined prefixed names such as
1128 // mycompany.com/my-custom-protocol.
1129 "appProtocol"?: string
1130
1131 // The name of this port. This must match the 'name' field in the corresponding
1132 // ServicePort. Must be a DNS_LABEL. Optional only if one port is defined.
1133 "name"?: string
1134
1135 // The port number of the endpoint.
1136 "port"!: int32 & int
1137
1138 // The IP protocol for this port. Must be UDP, TCP, or SCTP. Default is TCP.
1139 "protocol"?: string
1140}
1141
1142// EndpointSubset is a group of addresses with a common set of ports. The
1143// expanded set of endpoints is the Cartesian product of Addresses x Ports. For
1144// example, given:
1145//
1146// {
1147// Addresses: [{"ip": "10.10.1.1"}, {"ip": "10.10.2.2"}],
1148// Ports: [{"name": "a", "port": 8675}, {"name": "b", "port": 309}]
1149// }
1150//
1151// The resulting set of endpoints can be viewed as:
1152//
1153// a: [ 10.10.1.1:8675, 10.10.2.2:8675 ],
1154// b: [ 10.10.1.1:309, 10.10.2.2:309 ]
1155//
1156// Deprecated: This API is deprecated in v1.33+.
1157#EndpointSubset: {
1158 // IP addresses which offer the related ports that are marked as ready. These
1159 // endpoints should be considered safe for load balancers and clients to
1160 // utilize.
1161 "addresses"?: [...#EndpointAddress]
1162
1163 // IP addresses which offer the related ports but are not currently marked as
1164 // ready because they have not yet finished starting, have recently failed a
1165 // readiness check, or have recently failed a liveness check.
1166 "notReadyAddresses"?: [...#EndpointAddress]
1167
1168 // Port numbers available on the related IP addresses.
1169 "ports"?: [...#EndpointPort]
1170}
1171
1172// Endpoints is a collection of endpoints that implement the actual service. Example:
1173//
1174// Name: "mysvc",
1175// Subsets: [
1176// {
1177// Addresses: [{"ip": "10.10.1.1"}, {"ip": "10.10.2.2"}],
1178// Ports: [{"name": "a", "port": 8675}, {"name": "b", "port": 309}]
1179// },
1180// {
1181// Addresses: [{"ip": "10.10.3.3"}],
1182// Ports: [{"name": "a", "port": 93}, {"name": "b", "port": 76}]
1183// },
1184// ]
1185//
1186// Endpoints is a legacy API and does not contain information about all Service
1187// features. Use discoveryv1.EndpointSlice for complete information about
1188// Service endpoints.
1189//
1190// Deprecated: This API is deprecated in v1.33+. Use discoveryv1.EndpointSlice.
1191#Endpoints: {
1192 // APIVersion defines the versioned schema of this representation of an object.
1193 // Servers should convert recognized schemas to the latest internal value, and
1194 // may reject unrecognized values. More info:
1195 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1196 "apiVersion": "v1"
1197
1198 // Kind is a string value representing the REST resource this object represents.
1199 // Servers may infer this from the endpoint the client submits requests to.
1200 // Cannot be updated. In CamelCase. More info:
1201 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1202 "kind": "Endpoints"
1203
1204 // Standard object's metadata. More info:
1205 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
1206 "metadata"?: v1.#ObjectMeta
1207
1208 // The set of all endpoints is the union of all subsets. Addresses are placed
1209 // into subsets according to the IPs they share. A single address with multiple
1210 // ports, some of which are ready and some of which are not (because they come
1211 // from different containers) will result in the address being displayed in
1212 // different subsets for the different ports. No address will appear in both
1213 // Addresses and NotReadyAddresses in the same subset. Sets of addresses and
1214 // ports that comprise a service.
1215 "subsets"?: [...#EndpointSubset]
1216}
1217
1218// EndpointsList is a list of endpoints. Deprecated: This API is deprecated in v1.33+.
1219#EndpointsList: {
1220 // APIVersion defines the versioned schema of this representation of an object.
1221 // Servers should convert recognized schemas to the latest internal value, and
1222 // may reject unrecognized values. More info:
1223 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1224 "apiVersion": "v1"
1225
1226 // List of endpoints.
1227 "items"!: [...#Endpoints]
1228
1229 // Kind is a string value representing the REST resource this object represents.
1230 // Servers may infer this from the endpoint the client submits requests to.
1231 // Cannot be updated. In CamelCase. More info:
1232 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1233 "kind": "EndpointsList"
1234
1235 // Standard list metadata. More info:
1236 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1237 "metadata"?: v1.#ListMeta
1238}
1239
1240// EnvFromSource represents the source of a set of ConfigMaps or Secrets
1241#EnvFromSource: {
1242 // The ConfigMap to select from
1243 "configMapRef"?: #ConfigMapEnvSource
1244
1245 // Optional text to prepend to the name of each environment variable. May
1246 // consist of any printable ASCII characters except '='.
1247 "prefix"?: string
1248
1249 // The Secret to select from
1250 "secretRef"?: #SecretEnvSource
1251}
1252
1253// EnvVar represents an environment variable present in a Container.
1254#EnvVar: {
1255 // Name of the environment variable. May consist of any printable ASCII characters except '='.
1256 "name"!: string
1257
1258 // Variable references $(VAR_NAME) are expanded using the previously defined
1259 // environment variables in the container and any service environment
1260 // variables. If a variable cannot be resolved, the reference in the input
1261 // string will be unchanged. Double $$ are reduced to a single $, which allows
1262 // for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the
1263 // string literal "$(VAR_NAME)". Escaped references will never be expanded,
1264 // regardless of whether the variable exists or not. Defaults to "".
1265 "value"?: string
1266
1267 // Source for the environment variable's value. Cannot be used if value is not empty.
1268 "valueFrom"?: #EnvVarSource
1269}
1270
1271// EnvVarSource represents a source for the value of an EnvVar.
1272#EnvVarSource: {
1273 // Selects a key of a ConfigMap.
1274 "configMapKeyRef"?: #ConfigMapKeySelector
1275
1276 // Selects a field of the pod: supports metadata.name, metadata.namespace,
1277 // `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
1278 // spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
1279 "fieldRef"?: #ObjectFieldSelector
1280
1281 // FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be enabled.
1282 "fileKeyRef"?: #FileKeySelector
1283
1284 // Selects a resource of the container: only resources limits and requests
1285 // (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
1286 // requests.memory and requests.ephemeral-storage) are currently supported.
1287 "resourceFieldRef"?: #ResourceFieldSelector
1288
1289 // Selects a key of a secret in the pod's namespace
1290 "secretKeyRef"?: #SecretKeySelector
1291}
1292
1293// An EphemeralContainer is a temporary container that you may add to an
1294// existing Pod for user-initiated activities such as debugging. Ephemeral
1295// containers have no resource or scheduling guarantees, and they will not be
1296// restarted when they exit or when a Pod is removed or restarted. The kubelet
1297// may evict a Pod if an ephemeral container causes the Pod to exceed its
1298// resource allocation.
1299//
1300// To add an ephemeral container, use the ephemeralcontainers subresource of an
1301// existing Pod. Ephemeral containers may not be removed or restarted.
1302#EphemeralContainer: {
1303 // Arguments to the entrypoint. The image's CMD is used if this is not provided.
1304 // Variable references $(VAR_NAME) are expanded using the container's
1305 // environment. If a variable cannot be resolved, the reference in the input
1306 // string will be unchanged. Double $$ are reduced to a single $, which allows
1307 // for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the
1308 // string literal "$(VAR_NAME)". Escaped references will never be expanded,
1309 // regardless of whether the variable exists or not. Cannot be updated. More
1310 // info:
1311 // https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
1312 "args"?: [...string]
1313
1314 // Entrypoint array. Not executed within a shell. The image's ENTRYPOINT is used
1315 // if this is not provided. Variable references $(VAR_NAME) are expanded using
1316 // the container's environment. If a variable cannot be resolved, the reference
1317 // in the input string will be unchanged. Double $$ are reduced to a single $,
1318 // which allows for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will
1319 // produce the string literal "$(VAR_NAME)". Escaped references will never be
1320 // expanded, regardless of whether the variable exists or not. Cannot be
1321 // updated. More info:
1322 // https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
1323 "command"?: [...string]
1324
1325 // List of environment variables to set in the container. Cannot be updated.
1326 "env"?: [...#EnvVar]
1327
1328 // List of sources to populate environment variables in the container. The keys
1329 // defined within a source may consist of any printable ASCII characters except
1330 // '='. When a key exists in multiple sources, the value associated with the
1331 // last source will take precedence. Values defined by an Env with a duplicate
1332 // key will take precedence. Cannot be updated.
1333 "envFrom"?: [...#EnvFromSource]
1334
1335 // Container image name. More info: https://kubernetes.io/docs/concepts/containers/images
1336 "image"?: string
1337
1338 // Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if
1339 // :latest tag is specified, or IfNotPresent otherwise. Cannot be updated. More
1340 // info: https://kubernetes.io/docs/concepts/containers/images#updating-images
1341 "imagePullPolicy"?: string
1342
1343 // Lifecycle is not allowed for ephemeral containers.
1344 "lifecycle"?: #Lifecycle
1345
1346 // Probes are not allowed for ephemeral containers.
1347 "livenessProbe"?: #Probe
1348
1349 // Name of the ephemeral container specified as a DNS_LABEL. This name must be
1350 // unique among all containers, init containers and ephemeral containers.
1351 "name"!: string
1352
1353 // Ports are not allowed for ephemeral containers.
1354 "ports"?: [...#ContainerPort]
1355
1356 // Probes are not allowed for ephemeral containers.
1357 "readinessProbe"?: #Probe
1358
1359 // Resources resize policy for the container.
1360 "resizePolicy"?: [...#ContainerResizePolicy]
1361
1362 // Resources are not allowed for ephemeral containers. Ephemeral containers use
1363 // spare resources already allocated to the pod.
1364 "resources"?: #ResourceRequirements
1365
1366 // Restart policy for the container to manage the restart behavior of each
1367 // container within a pod. You cannot set this field on ephemeral containers.
1368 "restartPolicy"?: string
1369
1370 // Represents a list of rules to be checked to determine if the container should
1371 // be restarted on exit. You cannot set this field on ephemeral containers.
1372 "restartPolicyRules"?: [...#ContainerRestartRule]
1373
1374 // Optional: SecurityContext defines the security options the ephemeral
1375 // container should be run with. If set, the fields of SecurityContext override
1376 // the equivalent fields of PodSecurityContext.
1377 "securityContext"?: #SecurityContext
1378
1379 // Probes are not allowed for ephemeral containers.
1380 "startupProbe"?: #Probe
1381
1382 // Whether this container should allocate a buffer for stdin in the container
1383 // runtime. If this is not set, reads from stdin in the container will always
1384 // result in EOF. Default is false.
1385 "stdin"?: bool
1386
1387 // Whether the container runtime should close the stdin channel after it has
1388 // been opened by a single attach. When stdin is true the stdin stream will
1389 // remain open across multiple attach sessions. If stdinOnce is set to true,
1390 // stdin is opened on container start, is empty until the first client attaches
1391 // to stdin, and then remains open and accepts data until the client
1392 // disconnects, at which time stdin is closed and remains closed until the
1393 // container is restarted. If this flag is false, a container processes that
1394 // reads from stdin will never receive an EOF. Default is false
1395 "stdinOnce"?: bool
1396
1397 // If set, the name of the container from PodSpec that this ephemeral container
1398 // targets. The ephemeral container will be run in the namespaces (IPC, PID,
1399 // etc) of this container. If not set then the ephemeral container uses the
1400 // namespaces configured in the Pod spec.
1401 //
1402 // The container runtime must implement support for this feature. If the runtime
1403 // does not support namespace targeting then the result of setting this field
1404 // is undefined.
1405 "targetContainerName"?: string
1406
1407 // Optional: Path at which the file to which the container's termination message
1408 // will be written is mounted into the container's filesystem. Message written
1409 // is intended to be brief final status, such as an assertion failure message.
1410 // Will be truncated by the node if greater than 4096 bytes. The total message
1411 // length across all containers will be limited to 12kb. Defaults to
1412 // /dev/termination-log. Cannot be updated.
1413 "terminationMessagePath"?: string
1414
1415 // Indicate how the termination message should be populated. File will use the
1416 // contents of terminationMessagePath to populate the container status message
1417 // on both success and failure. FallbackToLogsOnError will use the last chunk
1418 // of container log output if the termination message file is empty and the
1419 // container exited with an error. The log output is limited to 2048 bytes or
1420 // 80 lines, whichever is smaller. Defaults to File. Cannot be updated.
1421 "terminationMessagePolicy"?: string
1422
1423 // Whether this container should allocate a TTY for itself, also requires
1424 // 'stdin' to be true. Default is false.
1425 "tty"?: bool
1426
1427 // volumeDevices is the list of block devices to be used by the container.
1428 "volumeDevices"?: [...#VolumeDevice]
1429
1430 // Pod volumes to mount into the container's filesystem. Subpath mounts are not
1431 // allowed for ephemeral containers. Cannot be updated.
1432 "volumeMounts"?: [...#VolumeMount]
1433
1434 // Container's working directory. If not specified, the container runtime's
1435 // default will be used, which might be configured in the container image.
1436 // Cannot be updated.
1437 "workingDir"?: string
1438}
1439
1440// Represents an ephemeral volume that is handled by a normal storage driver.
1441#EphemeralVolumeSource: {
1442 // Will be used to create a stand-alone PVC to provision the volume. The pod in
1443 // which this EphemeralVolumeSource is embedded will be the owner of the PVC,
1444 // i.e. the PVC will be deleted together with the pod. The name of the PVC will
1445 // be `<pod name>-<volume name>` where `<volume name>` is the name from the
1446 // `PodSpec.Volumes` array entry. Pod validation will reject the pod if the
1447 // concatenated name is not valid for a PVC (for example, too long).
1448 //
1449 // An existing PVC with that name that is not owned by the pod will *not* be
1450 // used for the pod to avoid using an unrelated volume by mistake. Starting the
1451 // pod is then blocked until the unrelated PVC is removed. If such a
1452 // pre-created PVC is meant to be used by the pod, the PVC has to updated with
1453 // an owner reference to the pod once the pod exists. Normally this should not
1454 // be necessary, but it may be useful when manually reconstructing a broken
1455 // cluster.
1456 //
1457 // This field is read-only and no changes will be made by Kubernetes to the PVC
1458 // after it has been created.
1459 //
1460 // Required, must not be nil.
1461 "volumeClaimTemplate"?: #PersistentVolumeClaimTemplate
1462}
1463
1464// Event is a report of an event somewhere in the cluster. Events have a limited
1465// retention time and triggers and messages may evolve with time. Event
1466// consumers should not rely on the timing of an event with a given Reason
1467// reflecting a consistent underlying trigger, or the continued existence of
1468// events with that Reason. Events should be treated as informative,
1469// best-effort, supplemental data.
1470#Event: {
1471 // What action was taken/failed regarding to the Regarding object.
1472 "action"?: string
1473
1474 // APIVersion defines the versioned schema of this representation of an object.
1475 // Servers should convert recognized schemas to the latest internal value, and
1476 // may reject unrecognized values. More info:
1477 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1478 "apiVersion": "v1"
1479
1480 // The number of times this event has occurred.
1481 "count"?: int32 & int
1482
1483 // Time when this Event was first observed.
1484 "eventTime"?: v1.#MicroTime
1485
1486 // The time at which the event was first recorded. (Time of server receipt is in TypeMeta.)
1487 "firstTimestamp"?: v1.#Time
1488
1489 // The object that this event is about.
1490 "involvedObject"!: #ObjectReference
1491
1492 // Kind is a string value representing the REST resource this object represents.
1493 // Servers may infer this from the endpoint the client submits requests to.
1494 // Cannot be updated. In CamelCase. More info:
1495 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1496 "kind": "Event"
1497
1498 // The time at which the most recent occurrence of this event was recorded.
1499 "lastTimestamp"?: v1.#Time
1500
1501 // A human-readable description of the status of this operation.
1502 "message"?: string
1503
1504 // Standard object's metadata. More info:
1505 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
1506 "metadata"!: v1.#ObjectMeta
1507
1508 // This should be a short, machine understandable string that gives the reason
1509 // for the transition into the object's current status.
1510 "reason"?: string
1511
1512 // Optional secondary object for more complex actions.
1513 "related"?: #ObjectReference
1514
1515 // Name of the controller that emitted this Event, e.g. `kubernetes.io/kubelet`.
1516 "reportingComponent"?: string
1517
1518 // ID of the controller instance, e.g. `kubelet-xyzf`.
1519 "reportingInstance"?: string
1520
1521 // Data about the Event series this event represents or nil if it's a singleton Event.
1522 "series"?: #EventSeries
1523
1524 // The component reporting this event. Should be a short machine understandable string.
1525 "source"?: #EventSource
1526
1527 // Type of this event (Normal, Warning), new types could be added in the future
1528 "type"?: string
1529}
1530
1531// EventList is a list of events.
1532#EventList: {
1533 // APIVersion defines the versioned schema of this representation of an object.
1534 // Servers should convert recognized schemas to the latest internal value, and
1535 // may reject unrecognized values. More info:
1536 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1537 "apiVersion": "v1"
1538
1539 // List of events
1540 "items"!: [...#Event]
1541
1542 // Kind is a string value representing the REST resource this object represents.
1543 // Servers may infer this from the endpoint the client submits requests to.
1544 // Cannot be updated. In CamelCase. More info:
1545 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1546 "kind": "EventList"
1547
1548 // Standard list metadata. More info:
1549 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1550 "metadata"?: v1.#ListMeta
1551}
1552
1553// EventSeries contain information on series of events, i.e. thing that was/is
1554// happening continuously for some time.
1555#EventSeries: {
1556 // Number of occurrences in this series up to the last heartbeat time
1557 "count"?: int32 & int
1558
1559 // Time of the last occurrence observed
1560 "lastObservedTime"?: v1.#MicroTime
1561}
1562
1563// EventSource contains information for an event.
1564#EventSource: {
1565 // Component from which the event is generated.
1566 "component"?: string
1567
1568 // Node name on which the event is generated.
1569 "host"?: string
1570}
1571
1572// ExecAction describes a "run in container" action.
1573#ExecAction: {
1574 // Command is the command line to execute inside the container, the working
1575 // directory for the command is root ('/') in the container's filesystem. The
1576 // command is simply exec'd, it is not run inside a shell, so traditional shell
1577 // instructions ('|', etc) won't work. To use a shell, you need to explicitly
1578 // call out to that shell. Exit status of 0 is treated as live/healthy and
1579 // non-zero is unhealthy.
1580 "command"?: [...string]
1581}
1582
1583// Represents a Fibre Channel volume. Fibre Channel volumes can only be mounted
1584// as read/write once. Fibre Channel volumes support ownership management and
1585// SELinux relabeling.
1586#FCVolumeSource: {
1587 // fsType is the filesystem type to mount. Must be a filesystem type supported
1588 // by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
1589 // to be "ext4" if unspecified.
1590 "fsType"?: string
1591
1592 // lun is Optional: FC target lun number
1593 "lun"?: int32 & int
1594
1595 // readOnly is Optional: Defaults to false (read/write). ReadOnly here will
1596 // force the ReadOnly setting in VolumeMounts.
1597 "readOnly"?: bool
1598
1599 // targetWWNs is Optional: FC target worldwide names (WWNs)
1600 "targetWWNs"?: [...string]
1601
1602 // wwids Optional: FC volume world wide identifiers (wwids) Either wwids or
1603 // combination of targetWWNs and lun must be set, but not both simultaneously.
1604 "wwids"?: [...string]
1605}
1606
1607// FileKeySelector selects a key of the env file.
1608#FileKeySelector: {
1609 // The key within the env file. An invalid key will prevent the pod from
1610 // starting. The keys defined within a source may consist of any printable
1611 // ASCII characters except '='. During Alpha stage of the EnvFiles feature
1612 // gate, the key size is limited to 128 characters.
1613 "key"!: string
1614
1615 // Specify whether the file or its key must be defined. If the file or key does
1616 // not exist, then the env var is not published. If optional is set to true and
1617 // the specified key does not exist, the environment variable will not be set
1618 // in the Pod's containers.
1619 //
1620 // If optional is set to false and the specified key does not exist, an error
1621 // will be returned during Pod creation.
1622 "optional"?: bool
1623
1624 // The path within the volume from which to select the file. Must be relative
1625 // and may not contain the '..' path or start with '..'.
1626 "path"!: string
1627
1628 // The name of the volume mount containing the env file.
1629 "volumeName"!: string
1630}
1631
1632// FlexPersistentVolumeSource represents a generic persistent volume resource
1633// that is provisioned/attached using an exec based plugin.
1634#FlexPersistentVolumeSource: {
1635 // driver is the name of the driver to use for this volume.
1636 "driver"!: string
1637
1638 // fsType is the Filesystem type to mount. Must be a filesystem type supported
1639 // by the host operating system. Ex. "ext4", "xfs", "ntfs". The default
1640 // filesystem depends on FlexVolume script.
1641 "fsType"?: string
1642
1643 // options is Optional: this field holds extra command options if any.
1644 "options"?: [string]: string
1645
1646 // readOnly is Optional: defaults to false (read/write). ReadOnly here will
1647 // force the ReadOnly setting in VolumeMounts.
1648 "readOnly"?: bool
1649
1650 // secretRef is Optional: SecretRef is reference to the secret object containing
1651 // sensitive information to pass to the plugin scripts. This may be empty if no
1652 // secret object is specified. If the secret object contains more than one
1653 // secret, all secrets are passed to the plugin scripts.
1654 "secretRef"?: #SecretReference
1655}
1656
1657// FlexVolume represents a generic volume resource that is provisioned/attached
1658// using an exec based plugin.
1659#FlexVolumeSource: {
1660 // driver is the name of the driver to use for this volume.
1661 "driver"!: string
1662
1663 // fsType is the filesystem type to mount. Must be a filesystem type supported
1664 // by the host operating system. Ex. "ext4", "xfs", "ntfs". The default
1665 // filesystem depends on FlexVolume script.
1666 "fsType"?: string
1667
1668 // options is Optional: this field holds extra command options if any.
1669 "options"?: [string]: string
1670
1671 // readOnly is Optional: defaults to false (read/write). ReadOnly here will
1672 // force the ReadOnly setting in VolumeMounts.
1673 "readOnly"?: bool
1674
1675 // secretRef is Optional: secretRef is reference to the secret object containing
1676 // sensitive information to pass to the plugin scripts. This may be empty if no
1677 // secret object is specified. If the secret object contains more than one
1678 // secret, all secrets are passed to the plugin scripts.
1679 "secretRef"?: #LocalObjectReference
1680}
1681
1682// Represents a Flocker volume mounted by the Flocker agent. One and only one of
1683// datasetName and datasetUUID should be set. Flocker volumes do not support
1684// ownership management or SELinux relabeling.
1685#FlockerVolumeSource: {
1686 // datasetName is Name of the dataset stored as metadata -> name on the dataset
1687 // for Flocker should be considered as deprecated
1688 "datasetName"?: string
1689
1690 // datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker dataset
1691 "datasetUUID"?: string
1692}
1693
1694// Represents a Persistent Disk resource in Google Compute Engine.
1695//
1696// A GCE PD must exist before mounting to a container. The disk must also be in
1697// the same GCE project and zone as the kubelet. A GCE PD can only be mounted
1698// as read/write once or read-only many times. GCE PDs support ownership
1699// management and SELinux relabeling.
1700#GCEPersistentDiskVolumeSource: {
1701 // fsType is filesystem type of the volume that you want to mount. Tip: Ensure
1702 // that the filesystem type is supported by the host operating system.
1703 // Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
1704 // unspecified. More info:
1705 // https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1706 "fsType"?: string
1707
1708 // partition is the partition in the volume that you want to mount. If omitted,
1709 // the default is to mount by volume name. Examples: For volume /dev/sda1, you
1710 // specify the partition as "1". Similarly, the volume partition for /dev/sda
1711 // is "0" (or you can leave the property empty). More info:
1712 // https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1713 "partition"?: int32 & int
1714
1715 // pdName is unique name of the PD resource in GCE. Used to identify the disk in
1716 // GCE. More info:
1717 // https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1718 "pdName"!: string
1719
1720 // readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to
1721 // false. More info:
1722 // https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1723 "readOnly"?: bool
1724}
1725
1726// GRPCAction specifies an action involving a GRPC service.
1727#GRPCAction: {
1728 // Port number of the gRPC service. Number must be in the range 1 to 65535.
1729 "port"!: int32 & int
1730
1731 // Service is the name of the service to place in the gRPC HealthCheckRequest
1732 // (see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
1733 //
1734 // If this is not specified, the default behavior is defined by gRPC.
1735 "service"?: string
1736}
1737
1738// Represents a volume that is populated with the contents of a git repository.
1739// Git repo volumes do not support ownership management. Git repo volumes
1740// support SELinux relabeling.
1741//
1742// DEPRECATED: GitRepo is deprecated. To provision a container with a git repo,
1743// mount an EmptyDir into an InitContainer that clones the repo using git, then
1744// mount the EmptyDir into the Pod's container.
1745#GitRepoVolumeSource: {
1746 // directory is the target directory name. Must not contain or start with '..'.
1747 // If '.' is supplied, the volume directory will be the git repository.
1748 // Otherwise, if specified, the volume will contain the git repository in the
1749 // subdirectory with the given name.
1750 "directory"?: string
1751
1752 // repository is the URL
1753 "repository"!: string
1754
1755 // revision is the commit hash for the specified revision.
1756 "revision"?: string
1757}
1758
1759// Represents a Glusterfs mount that lasts the lifetime of a pod. Glusterfs
1760// volumes do not support ownership management or SELinux relabeling.
1761#GlusterfsPersistentVolumeSource: {
1762 // endpoints is the endpoint name that details Glusterfs topology. More info:
1763 // https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1764 "endpoints"!: string
1765
1766 // endpointsNamespace is the namespace that contains Glusterfs endpoint. If this
1767 // field is empty, the EndpointNamespace defaults to the same namespace as the
1768 // bound PVC. More info:
1769 // https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1770 "endpointsNamespace"?: string
1771
1772 // path is the Glusterfs volume path. More info:
1773 // https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1774 "path"!: string
1775
1776 // readOnly here will force the Glusterfs volume to be mounted with read-only
1777 // permissions. Defaults to false. More info:
1778 // https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1779 "readOnly"?: bool
1780}
1781
1782// Represents a Glusterfs mount that lasts the lifetime of a pod. Glusterfs
1783// volumes do not support ownership management or SELinux relabeling.
1784#GlusterfsVolumeSource: {
1785 // endpoints is the endpoint name that details Glusterfs topology.
1786 "endpoints"!: string
1787
1788 // path is the Glusterfs volume path. More info:
1789 // https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1790 "path"!: string
1791
1792 // readOnly here will force the Glusterfs volume to be mounted with read-only
1793 // permissions. Defaults to false. More info:
1794 // https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1795 "readOnly"?: bool
1796}
1797
1798// HTTPGetAction describes an action based on HTTP Get requests.
1799#HTTPGetAction: {
1800 // Host name to connect to, defaults to the pod IP. You probably want to set
1801 // "Host" in httpHeaders instead.
1802 "host"?: string
1803
1804 // Custom headers to set in the request. HTTP allows repeated headers.
1805 "httpHeaders"?: [...#HTTPHeader]
1806
1807 // Path to access on the HTTP server.
1808 "path"?: string
1809
1810 // Name or number of the port to access on the container. Number must be in the
1811 // range 1 to 65535. Name must be an IANA_SVC_NAME.
1812 "port"!: intstr.#IntOrString
1813
1814 // Scheme to use for connecting to the host. Defaults to HTTP.
1815 "scheme"?: string
1816}
1817
1818// HTTPHeader describes a custom header to be used in HTTP probes
1819#HTTPHeader: {
1820 // The header field name. This will be canonicalized upon output, so
1821 // case-variant names will be understood as the same header.
1822 "name"!: string
1823
1824 // The header field value
1825 "value"!: string
1826}
1827
1828// HostAlias holds the mapping between IP and hostnames that will be injected as
1829// an entry in the pod's hosts file.
1830#HostAlias: {
1831 // Hostnames for the above IP address.
1832 "hostnames"?: [...string]
1833
1834 // IP address of the host file entry.
1835 "ip"!: string
1836}
1837
1838// HostIP represents a single IP address allocated to the host.
1839#HostIP: {
1840 // IP is the IP address assigned to the host
1841 "ip"!: string
1842}
1843
1844// Represents a host path mapped into a pod. Host path volumes do not support
1845// ownership management or SELinux relabeling.
1846#HostPathVolumeSource: {
1847 // path of the directory on the host. If the path is a symlink, it will follow
1848 // the link to the real path. More info:
1849 // https://kubernetes.io/docs/concepts/storage/volumes#hostpath
1850 "path"!: string
1851
1852 // type for HostPath Volume Defaults to "" More info:
1853 // https://kubernetes.io/docs/concepts/storage/volumes#hostpath
1854 "type"?: string
1855}
1856
1857// ISCSIPersistentVolumeSource represents an ISCSI disk. ISCSI volumes can only
1858// be mounted as read/write once. ISCSI volumes support ownership management
1859// and SELinux relabeling.
1860#ISCSIPersistentVolumeSource: {
1861 // chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication
1862 "chapAuthDiscovery"?: bool
1863
1864 // chapAuthSession defines whether support iSCSI Session CHAP authentication
1865 "chapAuthSession"?: bool
1866
1867 // fsType is the filesystem type of the volume that you want to mount. Tip:
1868 // Ensure that the filesystem type is supported by the host operating system.
1869 // Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
1870 // unspecified. More info:
1871 // https://kubernetes.io/docs/concepts/storage/volumes#iscsi
1872 "fsType"?: string
1873
1874 // initiatorName is the custom iSCSI Initiator Name. If initiatorName is
1875 // specified with iscsiInterface simultaneously, new iSCSI interface <target
1876 // portal>:<volume name> will be created for the connection.
1877 "initiatorName"?: string
1878
1879 // iqn is Target iSCSI Qualified Name.
1880 "iqn"!: string
1881
1882 // iscsiInterface is the interface Name that uses an iSCSI transport. Defaults to 'default' (tcp).
1883 "iscsiInterface"?: string
1884
1885 // lun is iSCSI Target Lun number.
1886 "lun"!: int32 & int
1887
1888 // portals is the iSCSI Target Portal List. The Portal is either an IP or
1889 // ip_addr:port if the port is other than default (typically TCP ports 860 and
1890 // 3260).
1891 "portals"?: [...string]
1892
1893 // readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
1894 "readOnly"?: bool
1895
1896 // secretRef is the CHAP Secret for iSCSI target and initiator authentication
1897 "secretRef"?: #SecretReference
1898
1899 // targetPortal is iSCSI Target Portal. The Portal is either an IP or
1900 // ip_addr:port if the port is other than default (typically TCP ports 860 and
1901 // 3260).
1902 "targetPortal"!: string
1903}
1904
1905// Represents an ISCSI disk. ISCSI volumes can only be mounted as read/write
1906// once. ISCSI volumes support ownership management and SELinux relabeling.
1907#ISCSIVolumeSource: {
1908 // chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication
1909 "chapAuthDiscovery"?: bool
1910
1911 // chapAuthSession defines whether support iSCSI Session CHAP authentication
1912 "chapAuthSession"?: bool
1913
1914 // fsType is the filesystem type of the volume that you want to mount. Tip:
1915 // Ensure that the filesystem type is supported by the host operating system.
1916 // Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
1917 // unspecified. More info:
1918 // https://kubernetes.io/docs/concepts/storage/volumes#iscsi
1919 "fsType"?: string
1920
1921 // initiatorName is the custom iSCSI Initiator Name. If initiatorName is
1922 // specified with iscsiInterface simultaneously, new iSCSI interface <target
1923 // portal>:<volume name> will be created for the connection.
1924 "initiatorName"?: string
1925
1926 // iqn is the target iSCSI Qualified Name.
1927 "iqn"!: string
1928
1929 // iscsiInterface is the interface Name that uses an iSCSI transport. Defaults to 'default' (tcp).
1930 "iscsiInterface"?: string
1931
1932 // lun represents iSCSI Target Lun number.
1933 "lun"!: int32 & int
1934
1935 // portals is the iSCSI Target Portal List. The portal is either an IP or
1936 // ip_addr:port if the port is other than default (typically TCP ports 860 and
1937 // 3260).
1938 "portals"?: [...string]
1939
1940 // readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
1941 "readOnly"?: bool
1942
1943 // secretRef is the CHAP Secret for iSCSI target and initiator authentication
1944 "secretRef"?: #LocalObjectReference
1945
1946 // targetPortal is iSCSI Target Portal. The Portal is either an IP or
1947 // ip_addr:port if the port is other than default (typically TCP ports 860 and
1948 // 3260).
1949 "targetPortal"!: string
1950}
1951
1952// ImageVolumeSource represents a image volume resource.
1953#ImageVolumeSource: {
1954 // Policy for pulling OCI objects. Possible values are: Always: the kubelet
1955 // always attempts to pull the reference. Container creation will fail If the
1956 // pull fails. Never: the kubelet never pulls the reference and only uses a
1957 // local image or artifact. Container creation will fail if the reference isn't
1958 // present. IfNotPresent: the kubelet pulls if the reference isn't already
1959 // present on disk. Container creation will fail if the reference isn't present
1960 // and the pull fails. Defaults to Always if :latest tag is specified, or
1961 // IfNotPresent otherwise.
1962 "pullPolicy"?: string
1963
1964 // Required: Image or artifact reference to be used. Behaves in the same way as
1965 // pod.spec.containers[*].image. Pull secrets will be assembled in the same way
1966 // as for the container image by looking up node credentials, SA image pull
1967 // secrets, and pod spec image pull secrets. More info:
1968 // https://kubernetes.io/docs/concepts/containers/images This field is optional
1969 // to allow higher level config management to default or override container
1970 // images in workload controllers like Deployments and StatefulSets.
1971 "reference"?: string
1972}
1973
1974// ImageVolumeStatus represents the image-based volume status.
1975#ImageVolumeStatus: {
1976 // ImageRef is the digest of the image used for this volume. It should have a
1977 // value that's similar to the pod's status.containerStatuses[i].imageID. The
1978 // ImageRef length should not exceed 256 characters.
1979 "imageRef"!: string
1980}
1981
1982// Maps a string key to a path within a volume.
1983#KeyToPath: {
1984 // key is the key to project.
1985 "key"!: string
1986
1987 // mode is Optional: mode bits used to set permissions on this file. Must be an
1988 // octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
1989 // accepts both octal and decimal values, JSON requires decimal values for mode
1990 // bits. If not specified, the volume defaultMode will be used. This might be
1991 // in conflict with other options that affect the file mode, like fsGroup, and
1992 // the result can be other mode bits set.
1993 "mode"?: int32 & int
1994
1995 // path is the relative path of the file to map the key to. May not be an
1996 // absolute path. May not contain the path element '..'. May not start with the
1997 // string '..'.
1998 "path"!: string
1999}
2000
2001// Lifecycle describes actions that the management system should take in
2002// response to container lifecycle events. For the PostStart and PreStop
2003// lifecycle handlers, management of the container blocks until the action is
2004// complete, unless the container process fails, in which case the handler is
2005// aborted.
2006#Lifecycle: {
2007 // PostStart is called immediately after a container is created. If the handler
2008 // fails, the container is terminated and restarted according to its restart
2009 // policy. Other management of the container blocks until the hook completes.
2010 // More info:
2011 // https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
2012 "postStart"?: #LifecycleHandler
2013
2014 // PreStop is called immediately before a container is terminated due to an API
2015 // request or management event such as liveness/startup probe failure,
2016 // preemption, resource contention, etc. The handler is not called if the
2017 // container crashes or exits. The Pod's termination grace period countdown
2018 // begins before the PreStop hook is executed. Regardless of the outcome of the
2019 // handler, the container will eventually terminate within the Pod's
2020 // termination grace period (unless delayed by finalizers). Other management of
2021 // the container blocks until the hook completes or until the termination grace
2022 // period is reached. More info:
2023 // https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
2024 "preStop"?: #LifecycleHandler
2025
2026 // StopSignal defines which signal will be sent to a container when it is being
2027 // stopped. If not specified, the default is defined by the container runtime
2028 // in use. StopSignal can only be set for Pods with a non-empty .spec.os.name
2029 "stopSignal"?: string
2030}
2031
2032// LifecycleHandler defines a specific action that should be taken in a
2033// lifecycle hook. One and only one of the fields, except TCPSocket must be
2034// specified.
2035#LifecycleHandler: {
2036 // Exec specifies a command to execute in the container.
2037 "exec"?: #ExecAction
2038
2039 // HTTPGet specifies an HTTP GET request to perform.
2040 "httpGet"?: #HTTPGetAction
2041
2042 // Sleep represents a duration that the container should sleep.
2043 "sleep"?: #SleepAction
2044
2045 // Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
2046 // backward compatibility. There is no validation of this field and lifecycle
2047 // hooks will fail at runtime when it is specified.
2048 "tcpSocket"?: #TCPSocketAction
2049}
2050
2051// LimitRange sets resource usage limits for each kind of resource in a Namespace.
2052#LimitRange: {
2053 // APIVersion defines the versioned schema of this representation of an object.
2054 // Servers should convert recognized schemas to the latest internal value, and
2055 // may reject unrecognized values. More info:
2056 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2057 "apiVersion": "v1"
2058
2059 // Kind is a string value representing the REST resource this object represents.
2060 // Servers may infer this from the endpoint the client submits requests to.
2061 // Cannot be updated. In CamelCase. More info:
2062 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2063 "kind": "LimitRange"
2064
2065 // Standard object's metadata. More info:
2066 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2067 "metadata"?: v1.#ObjectMeta
2068
2069 // Spec defines the limits enforced. More info:
2070 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2071 "spec"?: #LimitRangeSpec
2072}
2073
2074// LimitRangeItem defines a min/max usage limit for any resource that matches on kind.
2075#LimitRangeItem: {
2076 // Default resource requirement limit value by resource name if resource limit is omitted.
2077 "default"?: [string]: resource.#Quantity
2078
2079 // DefaultRequest is the default resource requirement request value by resource
2080 // name if resource request is omitted.
2081 "defaultRequest"?: [string]: resource.#Quantity
2082
2083 // Max usage constraints on this kind by resource name.
2084 "max"?: [string]: resource.#Quantity
2085
2086 // MaxLimitRequestRatio if specified, the named resource must have a request and
2087 // limit that are both non-zero where limit divided by request is less than or
2088 // equal to the enumerated value; this represents the max burst for the named
2089 // resource.
2090 "maxLimitRequestRatio"?: [string]: resource.#Quantity
2091
2092 // Min usage constraints on this kind by resource name.
2093 "min"?: [string]: resource.#Quantity
2094
2095 // Type of resource that this limit applies to.
2096 "type"!: string
2097}
2098
2099// LimitRangeList is a list of LimitRange items.
2100#LimitRangeList: {
2101 // APIVersion defines the versioned schema of this representation of an object.
2102 // Servers should convert recognized schemas to the latest internal value, and
2103 // may reject unrecognized values. More info:
2104 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2105 "apiVersion": "v1"
2106
2107 // Items is a list of LimitRange objects. More info:
2108 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
2109 "items"!: [...#LimitRange]
2110
2111 // Kind is a string value representing the REST resource this object represents.
2112 // Servers may infer this from the endpoint the client submits requests to.
2113 // Cannot be updated. In CamelCase. More info:
2114 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2115 "kind": "LimitRangeList"
2116
2117 // Standard list metadata. More info:
2118 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2119 "metadata"?: v1.#ListMeta
2120}
2121
2122// LimitRangeSpec defines a min/max usage limit for resources that match on kind.
2123#LimitRangeSpec: {
2124 // Limits is the list of LimitRangeItem objects that are enforced.
2125 "limits"!: [...#LimitRangeItem]
2126}
2127
2128// LinuxContainerUser represents user identity information in Linux containers
2129#LinuxContainerUser: {
2130 // GID is the primary gid initially attached to the first process in the container
2131 "gid"!: int64 & int
2132
2133 // SupplementalGroups are the supplemental groups initially attached to the
2134 // first process in the container
2135 "supplementalGroups"?: [...int64 & int]
2136
2137 // UID is the primary uid initially attached to the first process in the container
2138 "uid"!: int64 & int
2139}
2140
2141// LoadBalancerIngress represents the status of a load-balancer ingress point:
2142// traffic intended for the service should be sent to an ingress point.
2143#LoadBalancerIngress: {
2144 // Hostname is set for load-balancer ingress points that are DNS based
2145 // (typically AWS load-balancers)
2146 "hostname"?: string
2147
2148 // IP is set for load-balancer ingress points that are IP based (typically GCE
2149 // or OpenStack load-balancers)
2150 "ip"?: string
2151
2152 // IPMode specifies how the load-balancer IP behaves, and may only be specified
2153 // when the ip field is specified. Setting this to "VIP" indicates that traffic
2154 // is delivered to the node with the destination set to the load-balancer's IP
2155 // and port. Setting this to "Proxy" indicates that traffic is delivered to the
2156 // node or pod with the destination set to the node's IP and node port or the
2157 // pod's IP and port. Service implementations may use this information to
2158 // adjust traffic routing.
2159 "ipMode"?: string
2160
2161 // Ports is a list of records of service ports If used, every port defined in
2162 // the service should have an entry in it
2163 "ports"?: [...#PortStatus]
2164}
2165
2166// LoadBalancerStatus represents the status of a load-balancer.
2167#LoadBalancerStatus: {
2168 // Ingress is a list containing ingress points for the load-balancer. Traffic
2169 // intended for the service should be sent to these ingress points.
2170 "ingress"?: [...#LoadBalancerIngress]
2171}
2172
2173// LocalObjectReference contains enough information to let you locate the
2174// referenced object inside the same namespace.
2175#LocalObjectReference: {
2176 // Name of the referent. This field is effectively required, but due to
2177 // backwards compatibility is allowed to be empty. Instances of this type with
2178 // an empty value here are almost certainly wrong. More info:
2179 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
2180 "name"?: string
2181}
2182
2183// Local represents directly-attached storage with node affinity
2184#LocalVolumeSource: {
2185 // fsType is the filesystem type to mount. It applies only when the Path is a
2186 // block device. Must be a filesystem type supported by the host operating
2187 // system. Ex. "ext4", "xfs", "ntfs". The default value is to auto-select a
2188 // filesystem if unspecified.
2189 "fsType"?: string
2190
2191 // path of the full path to the volume on the node. It can be either a directory
2192 // or block device (disk, partition, ...).
2193 "path"!: string
2194}
2195
2196// ModifyVolumeStatus represents the status object of ControllerModifyVolume operation
2197#ModifyVolumeStatus: {
2198 // status is the status of the ControllerModifyVolume operation. It can be in
2199 // any of following states:
2200 // - Pending
2201 // Pending indicates that the PersistentVolumeClaim cannot be modified due to
2202 // unmet requirements, such as
2203 // the specified VolumeAttributesClass not existing.
2204 // - InProgress
2205 // InProgress indicates that the volume is being modified.
2206 // - Infeasible
2207 // Infeasible indicates that the request has been rejected as invalid by the CSI driver. To
2208 // resolve the error, a valid VolumeAttributesClass needs to be specified.
2209 // Note: New statuses can be added in the future. Consumers should check for
2210 // unknown statuses and fail appropriately.
2211 "status"!: string
2212
2213 // targetVolumeAttributesClassName is the name of the VolumeAttributesClass the
2214 // PVC currently being reconciled
2215 "targetVolumeAttributesClassName"?: string
2216}
2217
2218// Represents an NFS mount that lasts the lifetime of a pod. NFS volumes do not
2219// support ownership management or SELinux relabeling.
2220#NFSVolumeSource: {
2221 // path that is exported by the NFS server. More info:
2222 // https://kubernetes.io/docs/concepts/storage/volumes#nfs
2223 "path"!: string
2224
2225 // readOnly here will force the NFS export to be mounted with read-only
2226 // permissions. Defaults to false. More info:
2227 // https://kubernetes.io/docs/concepts/storage/volumes#nfs
2228 "readOnly"?: bool
2229
2230 // server is the hostname or IP address of the NFS server. More info:
2231 // https://kubernetes.io/docs/concepts/storage/volumes#nfs
2232 "server"!: string
2233}
2234
2235// Namespace provides a scope for Names. Use of multiple namespaces is optional.
2236#Namespace: {
2237 // APIVersion defines the versioned schema of this representation of an object.
2238 // Servers should convert recognized schemas to the latest internal value, and
2239 // may reject unrecognized values. More info:
2240 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2241 "apiVersion": "v1"
2242
2243 // Kind is a string value representing the REST resource this object represents.
2244 // Servers may infer this from the endpoint the client submits requests to.
2245 // Cannot be updated. In CamelCase. More info:
2246 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2247 "kind": "Namespace"
2248
2249 // Standard object's metadata. More info:
2250 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2251 "metadata"?: v1.#ObjectMeta
2252
2253 // Spec defines the behavior of the Namespace. More info:
2254 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2255 "spec"?: #NamespaceSpec
2256
2257 // Status describes the current status of a Namespace. More info:
2258 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2259 "status"?: #NamespaceStatus
2260}
2261
2262// NamespaceCondition contains details about state of namespace.
2263#NamespaceCondition: {
2264 // Last time the condition transitioned from one status to another.
2265 "lastTransitionTime"?: v1.#Time
2266
2267 // Human-readable message indicating details about last transition.
2268 "message"?: string
2269
2270 // Unique, one-word, CamelCase reason for the condition's last transition.
2271 "reason"?: string
2272
2273 // Status of the condition, one of True, False, Unknown.
2274 "status"!: string
2275
2276 // Type of namespace controller condition.
2277 "type"!: string
2278}
2279
2280// NamespaceList is a list of Namespaces.
2281#NamespaceList: {
2282 // APIVersion defines the versioned schema of this representation of an object.
2283 // Servers should convert recognized schemas to the latest internal value, and
2284 // may reject unrecognized values. More info:
2285 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2286 "apiVersion": "v1"
2287
2288 // Items is the list of Namespace objects in the list. More info:
2289 // https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
2290 "items"!: [...#Namespace]
2291
2292 // Kind is a string value representing the REST resource this object represents.
2293 // Servers may infer this from the endpoint the client submits requests to.
2294 // Cannot be updated. In CamelCase. More info:
2295 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2296 "kind": "NamespaceList"
2297
2298 // Standard list metadata. More info:
2299 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2300 "metadata"?: v1.#ListMeta
2301}
2302
2303// NamespaceSpec describes the attributes on a Namespace.
2304#NamespaceSpec: {
2305 // Finalizers is an opaque list of values that must be empty to permanently
2306 // remove object from storage. More info:
2307 // https://kubernetes.io/docs/tasks/administer-cluster/namespaces/
2308 "finalizers"?: [...string]
2309}
2310
2311// NamespaceStatus is information about the current status of a Namespace.
2312#NamespaceStatus: {
2313 // Represents the latest available observations of a namespace's current state.
2314 "conditions"?: [...#NamespaceCondition]
2315
2316 // Phase is the current lifecycle phase of the namespace. More info:
2317 // https://kubernetes.io/docs/tasks/administer-cluster/namespaces/
2318 "phase"?: string
2319}
2320
2321// Node is a worker node in Kubernetes. Each node will have a unique identifier
2322// in the cache (i.e. in etcd).
2323#Node: {
2324 // APIVersion defines the versioned schema of this representation of an object.
2325 // Servers should convert recognized schemas to the latest internal value, and
2326 // may reject unrecognized values. More info:
2327 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2328 "apiVersion": "v1"
2329
2330 // Kind is a string value representing the REST resource this object represents.
2331 // Servers may infer this from the endpoint the client submits requests to.
2332 // Cannot be updated. In CamelCase. More info:
2333 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2334 "kind": "Node"
2335
2336 // Standard object's metadata. More info:
2337 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2338 "metadata"?: v1.#ObjectMeta
2339
2340 // Spec defines the behavior of a node.
2341 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2342 "spec"?: #NodeSpec
2343
2344 // Most recently observed status of the node. Populated by the system.
2345 // Read-only. More info:
2346 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2347 "status"?: #NodeStatus
2348}
2349
2350// NodeAddress contains information for the node's address.
2351#NodeAddress: {
2352 // The node address.
2353 "address"!: string
2354
2355 // Node address type, one of Hostname, ExternalIP or InternalIP.
2356 "type"!: string
2357}
2358
2359// Node affinity is a group of node affinity scheduling rules.
2360#NodeAffinity: {
2361 // The scheduler will prefer to schedule pods to nodes that satisfy the affinity
2362 // expressions specified by this field, but it may choose a node that violates
2363 // one or more of the expressions. The node that is most preferred is the one
2364 // with the greatest sum of weights, i.e. for each node that meets all of the
2365 // scheduling requirements (resource request, requiredDuringScheduling affinity
2366 // expressions, etc.), compute a sum by iterating through the elements of this
2367 // field and adding "weight" to the sum if the node matches the corresponding
2368 // matchExpressions; the node(s) with the highest sum are the most preferred.
2369 "preferredDuringSchedulingIgnoredDuringExecution"?: [...#PreferredSchedulingTerm]
2370
2371 // If the affinity requirements specified by this field are not met at
2372 // scheduling time, the pod will not be scheduled onto the node. If the
2373 // affinity requirements specified by this field cease to be met at some point
2374 // during pod execution (e.g. due to an update), the system may or may not try
2375 // to eventually evict the pod from its node.
2376 "requiredDuringSchedulingIgnoredDuringExecution"?: #NodeSelector
2377}
2378
2379// NodeAllocatableResourceClaimStatus describes the status of node allocatable
2380// resources allocated via DRA.
2381#NodeAllocatableResourceClaimStatus: {
2382 // Containers lists the names of all containers in this pod that reference the claim.
2383 "containers"?: [...string]
2384
2385 // ResourceClaimName is the resource claim referenced by the pod that resulted
2386 // in this node allocatable resource allocation.
2387 "resourceClaimName"!: string
2388
2389 // Resources is a map of the node-allocatable resource name to the aggregate
2390 // quantity allocated to the claim.
2391 "resources"!: [string]: resource.#Quantity
2392}
2393
2394// NodeCondition contains condition information for a node.
2395#NodeCondition: {
2396 // Last time we got an update on a given condition.
2397 "lastHeartbeatTime"?: v1.#Time
2398
2399 // Last time the condition transit from one status to another.
2400 "lastTransitionTime"?: v1.#Time
2401
2402 // Human readable message indicating details about last transition.
2403 "message"?: string
2404
2405 // (brief) reason for the condition's last transition.
2406 "reason"?: string
2407
2408 // Status of the condition, one of True, False, Unknown.
2409 "status"!: string
2410
2411 // Type of node condition.
2412 "type"!: string
2413}
2414
2415// NodeConfigSource specifies a source of node configuration. Exactly one
2416// subfield (excluding metadata) must be non-nil. This API is deprecated since
2417// 1.22
2418#NodeConfigSource: {
2419 // ConfigMap is a reference to a Node's ConfigMap
2420 "configMap"?: #ConfigMapNodeConfigSource
2421}
2422
2423// NodeConfigStatus describes the status of the config assigned by Node.Spec.ConfigSource.
2424#NodeConfigStatus: {
2425 // Active reports the checkpointed config the node is actively using. Active
2426 // will represent either the current version of the Assigned config, or the
2427 // current LastKnownGood config, depending on whether attempting to use the
2428 // Assigned config results in an error.
2429 "active"?: #NodeConfigSource
2430
2431 // Assigned reports the checkpointed config the node will try to use. When
2432 // Node.Spec.ConfigSource is updated, the node checkpoints the associated
2433 // config payload to local disk, along with a record indicating intended
2434 // config. The node refers to this record to choose its config checkpoint, and
2435 // reports this record in Assigned. Assigned only updates in the status after
2436 // the record has been checkpointed to disk. When the Kubelet is restarted, it
2437 // tries to make the Assigned config the Active config by loading and
2438 // validating the checkpointed payload identified by Assigned.
2439 "assigned"?: #NodeConfigSource
2440
2441 // Error describes any problems reconciling the Spec.ConfigSource to the Active
2442 // config. Errors may occur, for example, attempting to checkpoint
2443 // Spec.ConfigSource to the local Assigned record, attempting to checkpoint the
2444 // payload associated with Spec.ConfigSource, attempting to load or validate
2445 // the Assigned config, etc. Errors may occur at different points while syncing
2446 // config. Earlier errors (e.g. download or checkpointing errors) will not
2447 // result in a rollback to LastKnownGood, and may resolve across Kubelet
2448 // retries. Later errors (e.g. loading or validating a checkpointed config)
2449 // will result in a rollback to LastKnownGood. In the latter case, it is
2450 // usually possible to resolve the error by fixing the config assigned in
2451 // Spec.ConfigSource. You can find additional information for debugging by
2452 // searching the error message in the Kubelet log. Error is a human-readable
2453 // description of the error state; machines can check whether or not Error is
2454 // empty, but should not rely on the stability of the Error text across Kubelet
2455 // versions.
2456 "error"?: string
2457
2458 // LastKnownGood reports the checkpointed config the node will fall back to when
2459 // it encounters an error attempting to use the Assigned config. The Assigned
2460 // config becomes the LastKnownGood config when the node determines that the
2461 // Assigned config is stable and correct. This is currently implemented as a
2462 // 10-minute soak period starting when the local record of Assigned config is
2463 // updated. If the Assigned config is Active at the end of this period, it
2464 // becomes the LastKnownGood. Note that if Spec.ConfigSource is reset to nil
2465 // (use local defaults), the LastKnownGood is also immediately reset to nil,
2466 // because the local default config is always assumed good. You should not make
2467 // assumptions about the node's method of determining config stability and
2468 // correctness, as this may change or become configurable in the future.
2469 "lastKnownGood"?: #NodeConfigSource
2470}
2471
2472// NodeDaemonEndpoints lists ports opened by daemons running on the Node.
2473#NodeDaemonEndpoints: {
2474 // Endpoint on which Kubelet is listening.
2475 "kubeletEndpoint"?: #DaemonEndpoint
2476}
2477
2478// NodeFeatures describes the set of features implemented by the CRI
2479// implementation. The features contained in the NodeFeatures should depend
2480// only on the cri implementation independent of runtime handlers.
2481#NodeFeatures: {
2482 // SupplementalGroupsPolicy is set to true if the runtime supports
2483 // SupplementalGroupsPolicy and ContainerUser.
2484 "supplementalGroupsPolicy"?: bool
2485}
2486
2487// NodeList is the whole list of all Nodes which have been registered with master.
2488#NodeList: {
2489 // APIVersion defines the versioned schema of this representation of an object.
2490 // Servers should convert recognized schemas to the latest internal value, and
2491 // may reject unrecognized values. More info:
2492 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2493 "apiVersion": "v1"
2494
2495 // List of nodes
2496 "items"!: [...#Node]
2497
2498 // Kind is a string value representing the REST resource this object represents.
2499 // Servers may infer this from the endpoint the client submits requests to.
2500 // Cannot be updated. In CamelCase. More info:
2501 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2502 "kind": "NodeList"
2503
2504 // Standard list metadata. More info:
2505 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2506 "metadata"?: v1.#ListMeta
2507}
2508
2509// NodeRuntimeHandler is a set of runtime handler information.
2510#NodeRuntimeHandler: {
2511 // Supported features.
2512 "features"?: #NodeRuntimeHandlerFeatures
2513
2514 // Runtime handler name. Empty for the default runtime handler.
2515 "name"?: string
2516}
2517
2518// NodeRuntimeHandlerFeatures is a set of features implemented by the runtime handler.
2519#NodeRuntimeHandlerFeatures: {
2520 // RecursiveReadOnlyMounts is set to true if the runtime handler supports RecursiveReadOnlyMounts.
2521 "recursiveReadOnlyMounts"?: bool
2522
2523 // UserNamespaces is set to true if the runtime handler supports UserNamespaces,
2524 // including for volumes.
2525 "userNamespaces"?: bool
2526}
2527
2528// A node selector represents the union of the results of one or more label
2529// queries over a set of nodes; that is, it represents the OR of the selectors
2530// represented by the node selector terms.
2531#NodeSelector: {
2532 // Required. A list of node selector terms. The terms are ORed.
2533 "nodeSelectorTerms"!: [...#NodeSelectorTerm]
2534}
2535
2536// A node selector requirement is a selector that contains values, a key, and an
2537// operator that relates the key and values.
2538#NodeSelectorRequirement: {
2539 // The label key that the selector applies to.
2540 "key"!: string
2541
2542 // Represents a key's relationship to a set of values. Valid operators are In,
2543 // NotIn, Exists, DoesNotExist. Gt, and Lt.
2544 "operator"!: string
2545
2546 // An array of string values. If the operator is In or NotIn, the values array
2547 // must be non-empty. If the operator is Exists or DoesNotExist, the values
2548 // array must be empty. If the operator is Gt or Lt, the values array must have
2549 // a single element, which will be interpreted as an integer. This array is
2550 // replaced during a strategic merge patch.
2551 "values"?: [...string]
2552}
2553
2554// A null or empty node selector term matches no objects. The requirements of
2555// them are ANDed. The TopologySelectorTerm type implements a subset of the
2556// NodeSelectorTerm.
2557#NodeSelectorTerm: {
2558 // A list of node selector requirements by node's labels.
2559 "matchExpressions"?: [...#NodeSelectorRequirement]
2560
2561 // A list of node selector requirements by node's fields.
2562 "matchFields"?: [...#NodeSelectorRequirement]
2563}
2564
2565// NodeSpec describes the attributes that a node is created with.
2566#NodeSpec: {
2567 // Deprecated: Previously used to specify the source of the node's configuration
2568 // for the DynamicKubeletConfig feature. This feature is removed.
2569 "configSource"?: #NodeConfigSource
2570
2571 // Deprecated. Not all kubelets will set this field. Remove field after 1.13.
2572 // see: https://issues.k8s.io/61966
2573 "externalID"?: string
2574
2575 // PodCIDR represents the pod IP range assigned to the node.
2576 "podCIDR"?: string
2577
2578 // podCIDRs represents the IP ranges assigned to the node for usage by Pods on
2579 // that node. If this field is specified, the 0th entry must match the podCIDR
2580 // field. It may contain at most 1 value for each of IPv4 and IPv6.
2581 "podCIDRs"?: [...string]
2582
2583 // ID of the node assigned by the cloud provider in the format:
2584 // <ProviderName>://<ProviderSpecificNodeID>
2585 "providerID"?: string
2586
2587 // If specified, the node's taints.
2588 "taints"?: [...#Taint]
2589
2590 // Unschedulable controls node schedulability of new pods. By default, node is
2591 // schedulable. More info:
2592 // https://kubernetes.io/docs/concepts/nodes/node/#manual-node-administration
2593 "unschedulable"?: bool
2594}
2595
2596// NodeStatus is information about the current status of a node.
2597#NodeStatus: {
2598 // List of addresses reachable to the node. Queried from cloud provider, if
2599 // available. More info:
2600 // https://kubernetes.io/docs/reference/node/node-status/#addresses Note: This
2601 // field is declared as mergeable, but the merge key is not sufficiently
2602 // unique, which can cause data corruption when it is merged. Callers should
2603 // instead use a full-replacement patch. See https://pr.k8s.io/79391 for an
2604 // example. Consumers should assume that addresses can change during the
2605 // lifetime of a Node. However, there are some exceptions where this may not be
2606 // possible, such as Pods that inherit a Node's address in its own status or
2607 // consumers of the downward API (status.hostIP).
2608 "addresses"?: [...#NodeAddress]
2609
2610 // Allocatable represents the resources of a node that are available for
2611 // scheduling. Defaults to Capacity.
2612 "allocatable"?: [string]: resource.#Quantity
2613
2614 // Capacity represents the total resources of a node. More info:
2615 // https://kubernetes.io/docs/reference/node/node-status/#capacity
2616 "capacity"?: [string]: resource.#Quantity
2617
2618 // Conditions is an array of current observed node conditions. More info:
2619 // https://kubernetes.io/docs/reference/node/node-status/#condition
2620 "conditions"?: [...#NodeCondition]
2621
2622 // Status of the config assigned to the node via the dynamic Kubelet config feature.
2623 "config"?: #NodeConfigStatus
2624
2625 // Endpoints of daemons running on the Node.
2626 "daemonEndpoints"?: #NodeDaemonEndpoints
2627
2628 // DeclaredFeatures represents the features related to feature gates that are declared by the node.
2629 "declaredFeatures"?: [...string]
2630
2631 // Features describes the set of features implemented by the CRI implementation.
2632 "features"?: #NodeFeatures
2633
2634 // List of container images on this node
2635 "images"?: [...#ContainerImage]
2636
2637 // Set of ids/uuids to uniquely identify the node. More info:
2638 // https://kubernetes.io/docs/reference/node/node-status/#info
2639 "nodeInfo"?: #NodeSystemInfo
2640
2641 // NodePhase is the recently observed lifecycle phase of the node. More info:
2642 // https://kubernetes.io/docs/concepts/nodes/node/#phase The field is never
2643 // populated, and now is deprecated.
2644 "phase"?: string
2645
2646 // The available runtime handlers.
2647 "runtimeHandlers"?: [...#NodeRuntimeHandler]
2648
2649 // List of volumes that are attached to the node.
2650 "volumesAttached"?: [...#AttachedVolume]
2651
2652 // List of attachable volumes in use (mounted) by the node.
2653 "volumesInUse"?: [...string]
2654}
2655
2656// NodeSwapStatus represents swap memory information.
2657#NodeSwapStatus: {
2658 // Total amount of swap memory in bytes.
2659 "capacity"?: int64 & int
2660}
2661
2662// NodeSystemInfo is a set of ids/uuids to uniquely identify the node.
2663#NodeSystemInfo: {
2664 // The Architecture reported by the node
2665 "architecture"!: string
2666
2667 // Boot ID reported by the node.
2668 "bootID"!: string
2669
2670 // ContainerRuntime Version reported by the node through runtime remote API
2671 // (e.g. containerd://1.4.2).
2672 "containerRuntimeVersion"!: string
2673
2674 // Kernel Version reported by the node from 'uname -r' (e.g. 3.16.0-0.bpo.4-amd64).
2675 "kernelVersion"!: string
2676
2677 // Deprecated: KubeProxy Version reported by the node.
2678 "kubeProxyVersion"!: string
2679
2680 // Kubelet Version reported by the node.
2681 "kubeletVersion"!: string
2682
2683 // MachineID reported by the node. For unique machine identification in the
2684 // cluster this field is preferred. Learn more from man(5) machine-id:
2685 // http://man7.org/linux/man-pages/man5/machine-id.5.html
2686 "machineID"!: string
2687
2688 // The Operating System reported by the node
2689 "operatingSystem"!: string
2690
2691 // OS Image reported by the node from /etc/os-release (e.g. Debian GNU/Linux 7 (wheezy)).
2692 "osImage"!: string
2693
2694 // Swap Info reported by the node.
2695 "swap"?: #NodeSwapStatus
2696
2697 // SystemUUID reported by the node. For unique machine identification MachineID
2698 // is preferred. This field is specific to Red Hat hosts
2699 // https://access.redhat.com/documentation/en-us/red_hat_subscription_management/1/html/rhsm/uuid
2700 "systemUUID"!: string
2701}
2702
2703// ObjectFieldSelector selects an APIVersioned field of an object.
2704#ObjectFieldSelector: {
2705 // Version of the schema the FieldPath is written in terms of, defaults to "v1".
2706 "apiVersion"?: string
2707
2708 // Path of the field to select in the specified API version.
2709 "fieldPath"!: string
2710}
2711
2712// ObjectReference contains enough information to let you inspect or modify the referred object.
2713#ObjectReference: {
2714 // API version of the referent.
2715 "apiVersion"?: string
2716
2717 // If referring to a piece of an object instead of an entire object, this string
2718 // should contain a valid JSON/Go field access statement, such as
2719 // desiredState.manifest.containers[2]. For example, if the object reference is
2720 // to a container within a pod, this would take on a value like:
2721 // "spec.containers{name}" (where "name" refers to the name of the container
2722 // that triggered the event) or if no container name is specified
2723 // "spec.containers[2]" (container with index 2 in this pod). This syntax is
2724 // chosen only to have some well-defined way of referencing a part of an
2725 // object.
2726 "fieldPath"?: string
2727
2728 // Kind of the referent. More info:
2729 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2730 "kind"?: string
2731
2732 // Name of the referent. More info:
2733 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
2734 "name"?: string
2735
2736 // Namespace of the referent. More info:
2737 // https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
2738 "namespace"?: string
2739
2740 // Specific resourceVersion to which this reference is made, if any. More info:
2741 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
2742 "resourceVersion"?: string
2743
2744 // UID of the referent. More info:
2745 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
2746 "uid"?: string
2747}
2748
2749// PersistentVolume (PV) is a storage resource provisioned by an administrator.
2750// It is analogous to a node. More info:
2751// https://kubernetes.io/docs/concepts/storage/persistent-volumes
2752#PersistentVolume: {
2753 // APIVersion defines the versioned schema of this representation of an object.
2754 // Servers should convert recognized schemas to the latest internal value, and
2755 // may reject unrecognized values. More info:
2756 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2757 "apiVersion": "v1"
2758
2759 // Kind is a string value representing the REST resource this object represents.
2760 // Servers may infer this from the endpoint the client submits requests to.
2761 // Cannot be updated. In CamelCase. More info:
2762 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2763 "kind": "PersistentVolume"
2764
2765 // Standard object's metadata. More info:
2766 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2767 "metadata"?: v1.#ObjectMeta
2768
2769 // spec defines a specification of a persistent volume owned by the cluster.
2770 // Provisioned by an administrator. More info:
2771 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistent-volumes
2772 "spec"?: #PersistentVolumeSpec
2773
2774 // status represents the current information/status for the persistent volume.
2775 // Populated by the system. Read-only. More info:
2776 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistent-volumes
2777 "status"?: #PersistentVolumeStatus
2778}
2779
2780// PersistentVolumeClaim is a user's request for and claim to a persistent volume
2781#PersistentVolumeClaim: {
2782 // APIVersion defines the versioned schema of this representation of an object.
2783 // Servers should convert recognized schemas to the latest internal value, and
2784 // may reject unrecognized values. More info:
2785 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2786 "apiVersion": "v1"
2787
2788 // Kind is a string value representing the REST resource this object represents.
2789 // Servers may infer this from the endpoint the client submits requests to.
2790 // Cannot be updated. In CamelCase. More info:
2791 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2792 "kind": "PersistentVolumeClaim"
2793
2794 // Standard object's metadata. More info:
2795 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2796 "metadata"?: v1.#ObjectMeta
2797
2798 // spec defines the desired characteristics of a volume requested by a pod
2799 // author. More info:
2800 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
2801 "spec"?: #PersistentVolumeClaimSpec
2802
2803 // status represents the current information/status of a persistent volume
2804 // claim. Read-only. More info:
2805 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
2806 "status"?: #PersistentVolumeClaimStatus
2807}
2808
2809// PersistentVolumeClaimCondition contains details about state of pvc
2810#PersistentVolumeClaimCondition: {
2811 // lastProbeTime is the time we probed the condition.
2812 "lastProbeTime"?: v1.#Time
2813
2814 // lastTransitionTime is the time the condition transitioned from one status to another.
2815 "lastTransitionTime"?: v1.#Time
2816
2817 // message is the human-readable message indicating details about last transition.
2818 "message"?: string
2819
2820 // reason is a unique, this should be a short, machine understandable string
2821 // that gives the reason for condition's last transition. If it reports
2822 // "Resizing" that means the underlying persistent volume is being resized.
2823 "reason"?: string
2824
2825 // Status is the status of the condition. Can be True, False, Unknown. More
2826 // info:
2827 // https://kubernetes.io/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-claim-v1/#:~:text=state%20of%20pvc-,conditions.status,-(string)%2C%20required
2828 "status"!: string
2829
2830 // Type is the type of the condition. More info:
2831 // https://kubernetes.io/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-claim-v1/#:~:text=set%20to%20%27ResizeStarted%27.-,PersistentVolumeClaimCondition,-contains%20details%20about
2832 "type"!: string
2833}
2834
2835// PersistentVolumeClaimList is a list of PersistentVolumeClaim items.
2836#PersistentVolumeClaimList: {
2837 // APIVersion defines the versioned schema of this representation of an object.
2838 // Servers should convert recognized schemas to the latest internal value, and
2839 // may reject unrecognized values. More info:
2840 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2841 "apiVersion": "v1"
2842
2843 // items is a list of persistent volume claims. More info:
2844 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
2845 "items"!: [...#PersistentVolumeClaim]
2846
2847 // Kind is a string value representing the REST resource this object represents.
2848 // Servers may infer this from the endpoint the client submits requests to.
2849 // Cannot be updated. In CamelCase. More info:
2850 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2851 "kind": "PersistentVolumeClaimList"
2852
2853 // Standard list metadata. More info:
2854 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2855 "metadata"?: v1.#ListMeta
2856}
2857
2858// PersistentVolumeClaimSpec describes the common attributes of storage devices
2859// and allows a Source for provider-specific attributes
2860#PersistentVolumeClaimSpec: {
2861 // accessModes contains the desired access modes the volume should have. More
2862 // info:
2863 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
2864 "accessModes"?: [...string]
2865
2866 // dataSource field can be used to specify either: * An existing VolumeSnapshot
2867 // object (snapshot.storage.k8s.io/VolumeSnapshot) * An existing PVC
2868 // (PersistentVolumeClaim) If the provisioner or an external controller can
2869 // support the specified data source, it will create a new volume based on the
2870 // contents of the specified data source. When the AnyVolumeDataSource feature
2871 // gate is enabled, dataSource contents will be copied to dataSourceRef, and
2872 // dataSourceRef contents will be copied to dataSource when
2873 // dataSourceRef.namespace is not specified. If the namespace is specified,
2874 // then dataSourceRef will not be copied to dataSource.
2875 "dataSource"?: #TypedLocalObjectReference
2876
2877 // dataSourceRef specifies the object from which to populate the volume with
2878 // data, if a non-empty volume is desired. This may be any object from a
2879 // non-empty API group (non core object) or a PersistentVolumeClaim object.
2880 // When this field is specified, volume binding will only succeed if the type
2881 // of the specified object matches some installed volume populator or dynamic
2882 // provisioner. This field will replace the functionality of the dataSource
2883 // field and as such if both fields are non-empty, they must have the same
2884 // value. For backwards compatibility, when namespace isn't specified in
2885 // dataSourceRef, both fields (dataSource and dataSourceRef) will be set to the
2886 // same value automatically if one of them is empty and the other is non-empty.
2887 // When namespace is specified in dataSourceRef, dataSource isn't set to the
2888 // same value and must be empty. There are three important differences between
2889 // dataSource and dataSourceRef: * While dataSource only allows two specific
2890 // types of objects, dataSourceRef
2891 // allows any non-core object, as well as PersistentVolumeClaim objects.
2892 // * While dataSource ignores disallowed values (dropping them), dataSourceRef
2893 // preserves all values, and generates an error if a disallowed value is
2894 // specified.
2895 // * While dataSource only allows local objects, dataSourceRef allows objects
2896 // in any namespaces.
2897 // (Beta) Using this field requires the AnyVolumeDataSource feature gate to be
2898 // enabled. (Alpha) Using the namespace field of dataSourceRef requires the
2899 // CrossNamespaceVolumeDataSource feature gate to be enabled.
2900 "dataSourceRef"?: #TypedObjectReference
2901
2902 // resources represents the minimum resources the volume should have. Users are
2903 // allowed to specify resource requirements that are lower than previous value
2904 // but must still be higher than capacity recorded in the status field of the
2905 // claim. More info:
2906 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources
2907 "resources"?: #VolumeResourceRequirements
2908
2909 // selector is a label query over volumes to consider for binding.
2910 "selector"?: v1.#LabelSelector
2911
2912 // storageClassName is the name of the StorageClass required by the claim. More
2913 // info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1
2914 "storageClassName"?: string
2915
2916 // volumeAttributesClassName may be used to set the VolumeAttributesClass used
2917 // by this claim. If specified, the CSI driver will create or update the volume
2918 // with the attributes defined in the corresponding VolumeAttributesClass. This
2919 // has a different purpose than storageClassName, it can be changed after the
2920 // claim is created. An empty string or nil value indicates that no
2921 // VolumeAttributesClass will be applied to the claim. If the claim enters an
2922 // Infeasible error state, this field can be reset to its previous value
2923 // (including nil) to cancel the modification. If the resource referred to by
2924 // volumeAttributesClass does not exist, this PersistentVolumeClaim will be set
2925 // to a Pending state, as reflected by the modifyVolumeStatus field, until such
2926 // as a resource exists. More info:
2927 // https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/
2928 "volumeAttributesClassName"?: string
2929
2930 // volumeMode defines what type of volume is required by the claim. Value of
2931 // Filesystem is implied when not included in claim spec.
2932 "volumeMode"?: string
2933
2934 // volumeName is the binding reference to the PersistentVolume backing this claim.
2935 "volumeName"?: string
2936}
2937
2938// PersistentVolumeClaimStatus is the current status of a persistent volume claim.
2939#PersistentVolumeClaimStatus: {
2940 // accessModes contains the actual access modes the volume backing the PVC has.
2941 // More info:
2942 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
2943 "accessModes"?: [...string]
2944
2945 // allocatedResourceStatuses stores status of resource being resized for the
2946 // given PVC. Key names follow standard Kubernetes label syntax. Valid values
2947 // are either:
2948 // * Un-prefixed keys:
2949 // - storage - the capacity of the volume.
2950 // * Custom resources must use implementation-defined prefixed names such as
2951 // "example.com/my-custom-resource"
2952 // Apart from above values - keys that are unprefixed or have kubernetes.io
2953 // prefix are considered reserved and hence may not be used.
2954 //
2955 // ClaimResourceStatus can be in any of following states:
2956 // - ControllerResizeInProgress:
2957 // State set when resize controller starts resizing the volume in control-plane.
2958 // - ControllerResizeFailed:
2959 // State set when resize has failed in resize controller with a terminal error.
2960 // - NodeResizePending:
2961 // State set when resize controller has finished resizing the volume but further resizing of
2962 // volume is needed on the node.
2963 // - NodeResizeInProgress:
2964 // State set when kubelet starts resizing the volume.
2965 // - NodeResizeFailed:
2966 // State set when resizing has failed in kubelet with a terminal error. Transient errors don't set
2967 // NodeResizeFailed.
2968 // For example: if expanding a PVC for more capacity - this field can be one of
2969 // the following states:
2970 // - pvc.status.allocatedResourceStatus['storage'] = "ControllerResizeInProgress"
2971 // - pvc.status.allocatedResourceStatus['storage'] = "ControllerResizeFailed"
2972 // - pvc.status.allocatedResourceStatus['storage'] = "NodeResizePending"
2973 // - pvc.status.allocatedResourceStatus['storage'] = "NodeResizeInProgress"
2974 // - pvc.status.allocatedResourceStatus['storage'] = "NodeResizeFailed"
2975 // When this field is not set, it means that no resize operation is in progress for the given PVC.
2976 //
2977 // A controller that receives PVC update with previously unknown resourceName or
2978 // ClaimResourceStatus should ignore the update for the purpose it was
2979 // designed. For example - a controller that only is responsible for resizing
2980 // capacity of the volume, should ignore PVC updates that change other valid
2981 // resources associated with PVC.
2982 "allocatedResourceStatuses"?: [string]: string
2983
2984 // allocatedResources tracks the resources allocated to a PVC including its
2985 // capacity. Key names follow standard Kubernetes label syntax. Valid values
2986 // are either:
2987 // * Un-prefixed keys:
2988 // - storage - the capacity of the volume.
2989 // * Custom resources must use implementation-defined prefixed names such as
2990 // "example.com/my-custom-resource"
2991 // Apart from above values - keys that are unprefixed or have kubernetes.io
2992 // prefix are considered reserved and hence may not be used.
2993 //
2994 // Capacity reported here may be larger than the actual capacity when a volume
2995 // expansion operation is requested. For storage quota, the larger value from
2996 // allocatedResources and PVC.spec.resources is used. If allocatedResources is
2997 // not set, PVC.spec.resources alone is used for quota calculation. If a volume
2998 // expansion capacity request is lowered, allocatedResources is only lowered if
2999 // there are no expansion operations in progress and if the actual volume
3000 // capacity is equal or lower than the requested capacity.
3001 //
3002 // A controller that receives PVC update with previously unknown resourceName
3003 // should ignore the update for the purpose it was designed. For example - a
3004 // controller that only is responsible for resizing capacity of the volume,
3005 // should ignore PVC updates that change other valid resources associated with
3006 // PVC.
3007 "allocatedResources"?: [string]: resource.#Quantity
3008
3009 // capacity represents the actual resources of the underlying volume.
3010 "capacity"?: [string]: resource.#Quantity
3011
3012 // conditions is the current Condition of persistent volume claim. If underlying
3013 // persistent volume is being resized then the Condition will be set to
3014 // 'Resizing'.
3015 "conditions"?: [...#PersistentVolumeClaimCondition]
3016
3017 // currentVolumeAttributesClassName is the current name of the
3018 // VolumeAttributesClass the PVC is using. When unset, there is no
3019 // VolumeAttributeClass applied to this PersistentVolumeClaim
3020 "currentVolumeAttributesClassName"?: string
3021
3022 // ModifyVolumeStatus represents the status object of ControllerModifyVolume
3023 // operation. When this is unset, there is no ModifyVolume operation being
3024 // attempted.
3025 "modifyVolumeStatus"?: #ModifyVolumeStatus
3026
3027 // phase represents the current phase of PersistentVolumeClaim.
3028 "phase"?: string
3029}
3030
3031// PersistentVolumeClaimTemplate is used to produce PersistentVolumeClaim
3032// objects as part of an EphemeralVolumeSource.
3033#PersistentVolumeClaimTemplate: {
3034 // May contain labels and annotations that will be copied into the PVC when
3035 // creating it. No other fields are allowed and will be rejected during
3036 // validation.
3037 "metadata"?: v1.#ObjectMeta
3038
3039 // The specification for the PersistentVolumeClaim. The entire content is copied
3040 // unchanged into the PVC that gets created from this template. The same fields
3041 // as in a PersistentVolumeClaim are also valid here.
3042 "spec"!: #PersistentVolumeClaimSpec
3043}
3044
3045// PersistentVolumeClaimVolumeSource references the user's PVC in the same
3046// namespace. This volume finds the bound PV and mounts that volume for the
3047// pod. A PersistentVolumeClaimVolumeSource is, essentially, a wrapper around
3048// another type of volume that is owned by someone else (the system).
3049#PersistentVolumeClaimVolumeSource: {
3050 // claimName is the name of a PersistentVolumeClaim in the same namespace as the
3051 // pod using this volume. More info:
3052 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
3053 "claimName"!: string
3054
3055 // readOnly Will force the ReadOnly setting in VolumeMounts. Default false.
3056 "readOnly"?: bool
3057}
3058
3059// PersistentVolumeList is a list of PersistentVolume items.
3060#PersistentVolumeList: {
3061 // APIVersion defines the versioned schema of this representation of an object.
3062 // Servers should convert recognized schemas to the latest internal value, and
3063 // may reject unrecognized values. More info:
3064 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
3065 "apiVersion": "v1"
3066
3067 // items is a list of persistent volumes. More info:
3068 // https://kubernetes.io/docs/concepts/storage/persistent-volumes
3069 "items"!: [...#PersistentVolume]
3070
3071 // Kind is a string value representing the REST resource this object represents.
3072 // Servers may infer this from the endpoint the client submits requests to.
3073 // Cannot be updated. In CamelCase. More info:
3074 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3075 "kind": "PersistentVolumeList"
3076
3077 // Standard list metadata. More info:
3078 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3079 "metadata"?: v1.#ListMeta
3080}
3081
3082// PersistentVolumeSpec is the specification of a persistent volume.
3083#PersistentVolumeSpec: {
3084 // accessModes contains all ways the volume can be mounted. More info:
3085 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes
3086 "accessModes"?: [...string]
3087
3088 // awsElasticBlockStore represents an AWS Disk resource that is attached to a
3089 // kubelet's host machine and then exposed to the pod. Deprecated:
3090 // AWSElasticBlockStore is deprecated. All operations for the in-tree
3091 // awsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.
3092 // More info:
3093 // https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
3094 "awsElasticBlockStore"?: #AWSElasticBlockStoreVolumeSource
3095
3096 // azureDisk represents an Azure Data Disk mount on the host and bind mount to
3097 // the pod. Deprecated: AzureDisk is deprecated. All operations for the in-tree
3098 // azureDisk type are redirected to the disk.csi.azure.com CSI driver.
3099 "azureDisk"?: #AzureDiskVolumeSource
3100
3101 // azureFile represents an Azure File Service mount on the host and bind mount
3102 // to the pod. Deprecated: AzureFile is deprecated. All operations for the
3103 // in-tree azureFile type are redirected to the file.csi.azure.com CSI driver.
3104 "azureFile"?: #AzureFilePersistentVolumeSource
3105
3106 // capacity is the description of the persistent volume's resources and
3107 // capacity. More info:
3108 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#capacity
3109 "capacity"?: [string]: resource.#Quantity
3110
3111 // cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
3112 // Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer
3113 // supported.
3114 "cephfs"?: #CephFSPersistentVolumeSource
3115
3116 // cinder represents a cinder volume attached and mounted on kubelets host
3117 // machine. Deprecated: Cinder is deprecated. All operations for the in-tree
3118 // cinder type are redirected to the cinder.csi.openstack.org CSI driver. More
3119 // info: https://examples.k8s.io/mysql-cinder-pd/README.md
3120 "cinder"?: #CinderPersistentVolumeSource
3121
3122 // claimRef is part of a bi-directional binding between PersistentVolume and
3123 // PersistentVolumeClaim. Expected to be non-nil when bound. claim.VolumeName
3124 // is the authoritative bind between PV and PVC. More info:
3125 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#binding
3126 "claimRef"?: #ObjectReference
3127
3128 // csi represents storage that is handled by an external CSI driver.
3129 "csi"?: #CSIPersistentVolumeSource
3130
3131 // fc represents a Fibre Channel resource that is attached to a kubelet's host
3132 // machine and then exposed to the pod.
3133 "fc"?: #FCVolumeSource
3134
3135 // flexVolume represents a generic volume resource that is provisioned/attached
3136 // using an exec based plugin. Deprecated: FlexVolume is deprecated. Consider
3137 // using a CSIDriver instead.
3138 "flexVolume"?: #FlexPersistentVolumeSource
3139
3140 // flocker represents a Flocker volume attached to a kubelet's host machine and
3141 // exposed to the pod for its usage. This depends on the Flocker control
3142 // service being running. Deprecated: Flocker is deprecated and the in-tree
3143 // flocker type is no longer supported.
3144 "flocker"?: #FlockerVolumeSource
3145
3146 // gcePersistentDisk represents a GCE Disk resource that is attached to a
3147 // kubelet's host machine and then exposed to the pod. Provisioned by an admin.
3148 // Deprecated: GCEPersistentDisk is deprecated. All operations for the in-tree
3149 // gcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI
3150 // driver. More info:
3151 // https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
3152 "gcePersistentDisk"?: #GCEPersistentDiskVolumeSource
3153
3154 // glusterfs represents a Glusterfs volume that is attached to a host and
3155 // exposed to the pod. Provisioned by an admin. Deprecated: Glusterfs is
3156 // deprecated and the in-tree glusterfs type is no longer supported. More info:
3157 // https://examples.k8s.io/volumes/glusterfs/README.md
3158 "glusterfs"?: #GlusterfsPersistentVolumeSource
3159
3160 // hostPath represents a directory on the host. Provisioned by a developer or
3161 // tester. This is useful for single-node development and testing only! On-host
3162 // storage is not supported in any way and WILL NOT WORK in a multi-node
3163 // cluster. More info:
3164 // https://kubernetes.io/docs/concepts/storage/volumes#hostpath
3165 "hostPath"?: #HostPathVolumeSource
3166
3167 // iscsi represents an ISCSI Disk resource that is attached to a kubelet's host
3168 // machine and then exposed to the pod. Provisioned by an admin.
3169 "iscsi"?: #ISCSIPersistentVolumeSource
3170
3171 // local represents directly-attached storage with node affinity
3172 "local"?: #LocalVolumeSource
3173
3174 // mountOptions is the list of mount options, e.g. ["ro", "soft"]. Not validated
3175 // - mount will simply fail if one is invalid. More info:
3176 // https://kubernetes.io/docs/concepts/storage/persistent-volumes/#mount-options
3177 "mountOptions"?: [...string]
3178
3179 // nfs represents an NFS mount on the host. Provisioned by an admin. More info:
3180 // https://kubernetes.io/docs/concepts/storage/volumes#nfs
3181 "nfs"?: #NFSVolumeSource
3182
3183 // nodeAffinity defines constraints that limit what nodes this volume can be
3184 // accessed from. This field influences the scheduling of pods that use this
3185 // volume. This field is mutable if MutablePVNodeAffinity feature gate is
3186 // enabled.
3187 "nodeAffinity"?: #VolumeNodeAffinity
3188
3189 // persistentVolumeReclaimPolicy defines what happens to a persistent volume
3190 // when released from its claim. Valid options are Retain (default for manually
3191 // created PersistentVolumes), Delete (default for dynamically provisioned
3192 // PersistentVolumes), and Recycle (deprecated). Recycle must be supported by
3193 // the volume plugin underlying this PersistentVolume. More info:
3194 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#reclaiming
3195 "persistentVolumeReclaimPolicy"?: string
3196
3197 // photonPersistentDisk represents a PhotonController persistent disk attached
3198 // and mounted on kubelets host machine. Deprecated: PhotonPersistentDisk is
3199 // deprecated and the in-tree photonPersistentDisk type is no longer supported.
3200 "photonPersistentDisk"?: #PhotonPersistentDiskVolumeSource
3201
3202 // portworxVolume represents a portworx volume attached and mounted on kubelets
3203 // host machine. Deprecated: PortworxVolume is deprecated. All operations for
3204 // the in-tree portworxVolume type are redirected to the pxd.portworx.com CSI
3205 // driver.
3206 "portworxVolume"?: #PortworxVolumeSource
3207
3208 // quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
3209 // Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer
3210 // supported.
3211 "quobyte"?: #QuobyteVolumeSource
3212
3213 // rbd represents a Rados Block Device mount on the host that shares a pod's
3214 // lifetime. Deprecated: RBD is deprecated and the in-tree rbd type is no
3215 // longer supported. More info: https://examples.k8s.io/volumes/rbd/README.md
3216 "rbd"?: #RBDPersistentVolumeSource
3217
3218 // scaleIO represents a ScaleIO persistent volume attached and mounted on
3219 // Kubernetes nodes. Deprecated: ScaleIO is deprecated and the in-tree scaleIO
3220 // type is no longer supported.
3221 "scaleIO"?: #ScaleIOPersistentVolumeSource
3222
3223 // storageClassName is the name of StorageClass to which this persistent volume
3224 // belongs. Empty value means that this volume does not belong to any
3225 // StorageClass.
3226 "storageClassName"?: string
3227
3228 // storageOS represents a StorageOS volume that is attached to the kubelet's
3229 // host machine and mounted into the pod. Deprecated: StorageOS is deprecated
3230 // and the in-tree storageos type is no longer supported. More info:
3231 // https://examples.k8s.io/volumes/storageos/README.md
3232 "storageos"?: #StorageOSPersistentVolumeSource
3233
3234 // Name of VolumeAttributesClass to which this persistent volume belongs. Empty
3235 // value is not allowed. When this field is not set, it indicates that this
3236 // volume does not belong to any VolumeAttributesClass. This field is mutable
3237 // and can be changed by the CSI driver after a volume has been updated
3238 // successfully to a new class. For an unbound PersistentVolume, the
3239 // volumeAttributesClassName will be matched with unbound
3240 // PersistentVolumeClaims during the binding process.
3241 "volumeAttributesClassName"?: string
3242
3243 // volumeMode defines if a volume is intended to be used with a formatted
3244 // filesystem or to remain in raw block state. Value of Filesystem is implied
3245 // when not included in spec.
3246 "volumeMode"?: string
3247
3248 // vsphereVolume represents a vSphere volume attached and mounted on kubelets
3249 // host machine. Deprecated: VsphereVolume is deprecated. All operations for
3250 // the in-tree vsphereVolume type are redirected to the csi.vsphere.vmware.com
3251 // CSI driver.
3252 "vsphereVolume"?: #VsphereVirtualDiskVolumeSource
3253}
3254
3255// PersistentVolumeStatus is the current status of a persistent volume.
3256#PersistentVolumeStatus: {
3257 // lastPhaseTransitionTime is the time the phase transitioned from one to
3258 // another and automatically resets to current time everytime a volume phase
3259 // transitions.
3260 "lastPhaseTransitionTime"?: v1.#Time
3261
3262 // message is a human-readable message indicating details about why the volume is in this state.
3263 "message"?: string
3264
3265 // phase indicates if a volume is available, bound to a claim, or released by a
3266 // claim. More info:
3267 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#phase
3268 "phase"?: string
3269
3270 // reason is a brief CamelCase string that describes any failure and is meant
3271 // for machine parsing and tidy display in the CLI.
3272 "reason"?: string
3273}
3274
3275// Represents a Photon Controller persistent disk resource.
3276#PhotonPersistentDiskVolumeSource: {
3277 // fsType is the filesystem type to mount. Must be a filesystem type supported
3278 // by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
3279 // to be "ext4" if unspecified.
3280 "fsType"?: string
3281
3282 // pdID is the ID that identifies Photon Controller persistent disk
3283 "pdID"!: string
3284}
3285
3286// Pod is a collection of containers that can run on a host. This resource is
3287// created by clients and scheduled onto hosts.
3288#Pod: {
3289 // APIVersion defines the versioned schema of this representation of an object.
3290 // Servers should convert recognized schemas to the latest internal value, and
3291 // may reject unrecognized values. More info:
3292 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
3293 "apiVersion": "v1"
3294
3295 // Kind is a string value representing the REST resource this object represents.
3296 // Servers may infer this from the endpoint the client submits requests to.
3297 // Cannot be updated. In CamelCase. More info:
3298 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3299 "kind": "Pod"
3300
3301 // Standard object's metadata. More info:
3302 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
3303 "metadata"?: v1.#ObjectMeta
3304
3305 // Specification of the desired behavior of the pod. More info:
3306 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
3307 "spec"?: #PodSpec
3308
3309 // Most recently observed status of the pod. This data may not be up to date.
3310 // Populated by the system. Read-only. More info:
3311 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
3312 "status"?: #PodStatus
3313}
3314
3315// Pod affinity is a group of inter pod affinity scheduling rules.
3316#PodAffinity: {
3317 // The scheduler will prefer to schedule pods to nodes that satisfy the affinity
3318 // expressions specified by this field, but it may choose a node that violates
3319 // one or more of the expressions. The node that is most preferred is the one
3320 // with the greatest sum of weights, i.e. for each node that meets all of the
3321 // scheduling requirements (resource request, requiredDuringScheduling affinity
3322 // expressions, etc.), compute a sum by iterating through the elements of this
3323 // field and adding "weight" to the sum if the node has pods which matches the
3324 // corresponding podAffinityTerm; the node(s) with the highest sum are the most
3325 // preferred.
3326 "preferredDuringSchedulingIgnoredDuringExecution"?: [...#WeightedPodAffinityTerm]
3327
3328 // If the affinity requirements specified by this field are not met at
3329 // scheduling time, the pod will not be scheduled onto the node. If the
3330 // affinity requirements specified by this field cease to be met at some point
3331 // during pod execution (e.g. due to a pod label update), the system may or may
3332 // not try to eventually evict the pod from its node. When there are multiple
3333 // elements, the lists of nodes corresponding to each podAffinityTerm are
3334 // intersected, i.e. all terms must be satisfied.
3335 "requiredDuringSchedulingIgnoredDuringExecution"?: [...#PodAffinityTerm]
3336}
3337
3338// Defines a set of pods (namely those matching the labelSelector relative to
3339// the given namespace(s)) that this pod should be co-located (affinity) or not
3340// co-located (anti-affinity) with, where co-located is defined as running on a
3341// node whose value of the label with key <topologyKey> matches that of any
3342// node on which a pod of the set of pods is running
3343#PodAffinityTerm: {
3344 // A label query over a set of resources, in this case pods. If it's null, this
3345 // PodAffinityTerm matches with no Pods.
3346 "labelSelector"?: v1.#LabelSelector
3347
3348 // MatchLabelKeys is a set of pod label keys to select which pods will be taken
3349 // into consideration. The keys are used to lookup values from the incoming pod
3350 // labels, those key-value labels are merged with `labelSelector` as `key in
3351 // (value)` to select the group of existing pods which pods will be taken into
3352 // consideration for the incoming pod's pod (anti) affinity. Keys that don't
3353 // exist in the incoming pod labels will be ignored. The default value is
3354 // empty. The same key is forbidden to exist in both matchLabelKeys and
3355 // labelSelector. Also, matchLabelKeys cannot be set when labelSelector isn't
3356 // set.
3357 "matchLabelKeys"?: [...string]
3358
3359 // MismatchLabelKeys is a set of pod label keys to select which pods will be
3360 // taken into consideration. The keys are used to lookup values from the
3361 // incoming pod labels, those key-value labels are merged with `labelSelector`
3362 // as `key notin (value)` to select the group of existing pods which pods will
3363 // be taken into consideration for the incoming pod's pod (anti) affinity. Keys
3364 // that don't exist in the incoming pod labels will be ignored. The default
3365 // value is empty. The same key is forbidden to exist in both mismatchLabelKeys
3366 // and labelSelector. Also, mismatchLabelKeys cannot be set when labelSelector
3367 // isn't set.
3368 "mismatchLabelKeys"?: [...string]
3369
3370 // A label query over the set of namespaces that the term applies to. The term
3371 // is applied to the union of the namespaces selected by this field and the
3372 // ones listed in the namespaces field. null selector and null or empty
3373 // namespaces list means "this pod's namespace". An empty selector ({}) matches
3374 // all namespaces.
3375 "namespaceSelector"?: v1.#LabelSelector
3376
3377 // namespaces specifies a static list of namespace names that the term applies
3378 // to. The term is applied to the union of the namespaces listed in this field
3379 // and the ones selected by namespaceSelector. null or empty namespaces list
3380 // and null namespaceSelector means "this pod's namespace".
3381 "namespaces"?: [...string]
3382
3383 // This pod should be co-located (affinity) or not co-located (anti-affinity)
3384 // with the pods matching the labelSelector in the specified namespaces, where
3385 // co-located is defined as running on a node whose value of the label with key
3386 // topologyKey matches that of any node on which any of the selected pods is
3387 // running. Empty topologyKey is not allowed.
3388 "topologyKey"!: string
3389}
3390
3391// Pod anti affinity is a group of inter pod anti affinity scheduling rules.
3392#PodAntiAffinity: {
3393 // The scheduler will prefer to schedule pods to nodes that satisfy the
3394 // anti-affinity expressions specified by this field, but it may choose a node
3395 // that violates one or more of the expressions. The node that is most
3396 // preferred is the one with the greatest sum of weights, i.e. for each node
3397 // that meets all of the scheduling requirements (resource request,
3398 // requiredDuringScheduling anti-affinity expressions, etc.), compute a sum by
3399 // iterating through the elements of this field and subtracting "weight" from
3400 // the sum if the node has pods which matches the corresponding
3401 // podAffinityTerm; the node(s) with the highest sum are the most preferred.
3402 "preferredDuringSchedulingIgnoredDuringExecution"?: [...#WeightedPodAffinityTerm]
3403
3404 // If the anti-affinity requirements specified by this field are not met at
3405 // scheduling time, the pod will not be scheduled onto the node. If the
3406 // anti-affinity requirements specified by this field cease to be met at some
3407 // point during pod execution (e.g. due to a pod label update), the system may
3408 // or may not try to eventually evict the pod from its node. When there are
3409 // multiple elements, the lists of nodes corresponding to each podAffinityTerm
3410 // are intersected, i.e. all terms must be satisfied.
3411 "requiredDuringSchedulingIgnoredDuringExecution"?: [...#PodAffinityTerm]
3412}
3413
3414// PodCertificateProjection provides a private key and X.509 certificate in the pod filesystem.
3415#PodCertificateProjection: {
3416 // Write the certificate chain at this path in the projected volume.
3417 //
3418 // Most applications should use credentialBundlePath. When using keyPath and
3419 // certificateChainPath, your application needs to check that the key and leaf
3420 // certificate are consistent, because it is possible to read the files
3421 // mid-rotation.
3422 "certificateChainPath"?: string
3423
3424 // Write the credential bundle at this path in the projected volume.
3425 //
3426 // The credential bundle is a single file that contains multiple PEM blocks. The
3427 // first PEM block is a PRIVATE KEY block, containing a PKCS#8 private key.
3428 //
3429 // The remaining blocks are CERTIFICATE blocks, containing the issued
3430 // certificate chain from the signer (leaf and any intermediates).
3431 //
3432 // Using credentialBundlePath lets your Pod's application code make a single
3433 // atomic read that retrieves a consistent key and certificate chain. If you
3434 // project them to separate files, your application code will need to
3435 // additionally check that the leaf certificate was issued to the key.
3436 "credentialBundlePath"?: string
3437
3438 // Write the key at this path in the projected volume.
3439 //
3440 // Most applications should use credentialBundlePath. When using keyPath and
3441 // certificateChainPath, your application needs to check that the key and leaf
3442 // certificate are consistent, because it is possible to read the files
3443 // mid-rotation.
3444 "keyPath"?: string
3445
3446 // The type of keypair Kubelet will generate for the pod.
3447 //
3448 // Valid values are "RSA3072", "RSA4096", "ECDSAP256", "ECDSAP384", "ECDSAP521", and "ED25519".
3449 "keyType"!: string
3450
3451 // maxExpirationSeconds is the maximum lifetime permitted for the certificate.
3452 //
3453 // Kubelet copies this value verbatim into the PodCertificateRequests it
3454 // generates for this projection.
3455 //
3456 // If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver
3457 // will reject values shorter than 3600 (1 hour). The maximum allowable value
3458 // is 7862400 (91 days).
3459 //
3460 // The signer implementation is then free to issue a certificate with any
3461 // lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600
3462 // seconds (1 hour). This constraint is enforced by kube-apiserver.
3463 // `kubernetes.io` signers will never issue certificates with a lifetime longer
3464 // than 24 hours.
3465 "maxExpirationSeconds"?: int32 & int
3466
3467 // Kubelet's generated CSRs will be addressed to this signer.
3468 "signerName"!: string
3469
3470 // userAnnotations allow pod authors to pass additional information to the
3471 // signer implementation. Kubernetes does not restrict or validate this
3472 // metadata in any way.
3473 //
3474 // These values are copied verbatim into the `spec.unverifiedUserAnnotations`
3475 // field of the PodCertificateRequest objects that Kubelet creates.
3476 //
3477 // Entries are subject to the same validation as object metadata annotations,
3478 // with the addition that all keys must be domain-prefixed. No restrictions are
3479 // placed on values, except an overall size limitation on the entire field.
3480 //
3481 // Signers should document the keys and values they support. Signers should deny
3482 // requests that contain keys they do not recognize.
3483 "userAnnotations"?: [string]: string
3484}
3485
3486// PodCondition contains details for the current condition of this pod.
3487#PodCondition: {
3488 // Last time we probed the condition.
3489 "lastProbeTime"?: v1.#Time
3490
3491 // Last time the condition transitioned from one status to another.
3492 "lastTransitionTime"?: v1.#Time
3493
3494 // Human-readable message indicating details about last transition.
3495 "message"?: string
3496
3497 // If set, this represents the .metadata.generation that the pod condition was set based upon.
3498 "observedGeneration"?: int64 & int
3499
3500 // Unique, one-word, CamelCase reason for the condition's last transition.
3501 "reason"?: string
3502
3503 // Status is the status of the condition. Can be True, False, Unknown. More
3504 // info:
3505 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-conditions
3506 "status"!: string
3507
3508 // Type is the type of the condition. More info:
3509 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-conditions
3510 "type"!: string
3511}
3512
3513// PodDNSConfig defines the DNS parameters of a pod in addition to those generated from DNSPolicy.
3514#PodDNSConfig: {
3515 // A list of DNS name server IP addresses. This will be appended to the base
3516 // nameservers generated from DNSPolicy. Duplicated nameservers will be
3517 // removed.
3518 "nameservers"?: [...string]
3519
3520 // A list of DNS resolver options. This will be merged with the base options
3521 // generated from DNSPolicy. Duplicated entries will be removed. Resolution
3522 // options given in Options will override those that appear in the base
3523 // DNSPolicy.
3524 "options"?: [...#PodDNSConfigOption]
3525
3526 // A list of DNS search domains for host-name lookup. This will be appended to
3527 // the base search paths generated from DNSPolicy. Duplicated search paths will
3528 // be removed.
3529 "searches"?: [...string]
3530}
3531
3532// PodDNSConfigOption defines DNS resolver options of a pod.
3533#PodDNSConfigOption: {
3534 // Name is this DNS resolver option's name. Required.
3535 "name"?: string
3536
3537 // Value is this DNS resolver option's value.
3538 "value"?: string
3539}
3540
3541// PodExtendedResourceClaimStatus is stored in the PodStatus for the extended
3542// resource requests backed by DRA. It stores the generated name for the
3543// corresponding special ResourceClaim created by the scheduler.
3544#PodExtendedResourceClaimStatus: {
3545 // RequestMappings identifies the mapping of <container, extended resource
3546 // backed by DRA> to device request in the generated ResourceClaim.
3547 "requestMappings"!: [...#ContainerExtendedResourceRequest]
3548
3549 // ResourceClaimName is the name of the ResourceClaim that was generated for the
3550 // Pod in the namespace of the Pod.
3551 "resourceClaimName"!: string
3552}
3553
3554// PodIP represents a single IP address allocated to the pod.
3555#PodIP: {
3556 // IP is the IP address assigned to the pod
3557 "ip"!: string
3558}
3559
3560// PodList is a list of Pods.
3561#PodList: {
3562 // APIVersion defines the versioned schema of this representation of an object.
3563 // Servers should convert recognized schemas to the latest internal value, and
3564 // may reject unrecognized values. More info:
3565 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
3566 "apiVersion": "v1"
3567
3568 // List of pods. More info:
3569 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
3570 "items"!: [...#Pod]
3571
3572 // Kind is a string value representing the REST resource this object represents.
3573 // Servers may infer this from the endpoint the client submits requests to.
3574 // Cannot be updated. In CamelCase. More info:
3575 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3576 "kind": "PodList"
3577
3578 // Standard list metadata. More info:
3579 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3580 "metadata"?: v1.#ListMeta
3581}
3582
3583// PodOS defines the OS parameters of a pod.
3584#PodOS: {
3585 // Name is the name of the operating system. The currently supported values are
3586 // linux and windows. Additional value may be defined in future and can be one
3587 // of:
3588 // https://github.com/opencontainers/runtime-spec/blob/master/config.md#platform-specific-configuration
3589 // Clients should expect to handle additional values and treat unrecognized
3590 // values in this field as os: null
3591 "name"!: string
3592}
3593
3594// PodReadinessGate contains the reference to a pod condition
3595#PodReadinessGate: {
3596 // ConditionType refers to a condition in the pod's condition list with matching type.
3597 "conditionType"!: string
3598}
3599
3600// PodResourceClaim references exactly one ResourceClaim, either directly or by
3601// naming a ResourceClaimTemplate which is then turned into a ResourceClaim for
3602// the pod.
3603//
3604// It adds a name to it that uniquely identifies the ResourceClaim inside the
3605// Pod. Containers that need access to the ResourceClaim reference it with this
3606// name.
3607//
3608// When the DRAWorkloadResourceClaims feature gate is enabled and this Pod
3609// belongs to a PodGroup, a PodResourceClaim is matched to a
3610// PodGroupResourceClaim if all of their fields are equal (Name,
3611// ResourceClaimName, and ResourceClaimTemplateName). A matched claim
3612// references a single ResourceClaim shared across all Pods in the PodGroup,
3613// reserved for the PodGroup in ResourceClaimStatus.ReservedFor rather than for
3614// individual Pods.
3615#PodResourceClaim: {
3616 // Name uniquely identifies this resource claim inside the pod. This must be a DNS_LABEL.
3617 "name"!: string
3618
3619 // ResourceClaimName is the name of a ResourceClaim object in the same namespace as this pod.
3620 //
3621 // Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
3622 "resourceClaimName"?: string
3623
3624 // ResourceClaimTemplateName is the name of a ResourceClaimTemplate object in
3625 // the same namespace as this pod.
3626 //
3627 // The template will be used to create a new ResourceClaim, which will be bound
3628 // to this pod. When this pod is deleted, the ResourceClaim will also be
3629 // deleted. The pod name and resource name, along with a generated component,
3630 // will be used to form a unique name for the ResourceClaim, which will be
3631 // recorded in pod.status.resourceClaimStatuses.
3632 //
3633 // When the DRAWorkloadResourceClaims feature gate is enabled and the pod
3634 // belongs to a PodGroup that defines a PodGroupResourceClaim with the same
3635 // Name and ResourceClaimTemplateName, this PodResourceClaim resolves to the
3636 // ResourceClaim generated for the PodGroup. All pods in the group that define
3637 // an equivalent PodResourceClaim matching the PodGroupResourceClaim's Name and
3638 // ResourceClaimTemplateName share the same generated ResourceClaim.
3639 // ResourceClaims generated for a PodGroup are owned by the PodGroup and their
3640 // lifecycles are tied to the PodGroup instead of any individual pod.
3641 //
3642 // This field is immutable and no changes will be made to the corresponding
3643 // ResourceClaim by the control plane after creating the ResourceClaim.
3644 //
3645 // Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
3646 "resourceClaimTemplateName"?: string
3647}
3648
3649// PodResourceClaimStatus is stored in the PodStatus for each PodResourceClaim
3650// which references a ResourceClaimTemplate. It stores the generated name for
3651// the corresponding ResourceClaim.
3652#PodResourceClaimStatus: {
3653 // Name uniquely identifies this resource claim inside the pod. This must match
3654 // the name of an entry in pod.spec.resourceClaims, which implies that the
3655 // string must be a DNS_LABEL.
3656 "name"!: string
3657
3658 // ResourceClaimName is the name of the ResourceClaim that was generated for the
3659 // Pod in the namespace of the Pod.
3660 //
3661 // When the DRAWorkloadResourceClaims feature is enabled and the corresponding
3662 // PodResourceClaim matches a PodGroupResourceClaim made by the Pod's PodGroup,
3663 // then this is the name of the ResourceClaim generated and reserved for the
3664 // PodGroup.
3665 //
3666 // If this is unset, then generating a ResourceClaim was not necessary. The
3667 // pod.spec.resourceClaims entry can be ignored in this case.
3668 "resourceClaimName"?: string
3669}
3670
3671// PodSchedulingGate is associated to a Pod to guard its scheduling.
3672#PodSchedulingGate: {
3673 // Name of the scheduling gate. Each scheduling gate must have a unique name field.
3674 "name"!: string
3675}
3676
3677// PodSchedulingGroup identifies the runtime scheduling group instance that a
3678// Pod belongs to. The scheduler uses this information to apply workload-aware
3679// scheduling semantics. Exactly one field must be specified.
3680#PodSchedulingGroup: {
3681 // PodGroupName specifies the name of the standalone PodGroup object that
3682 // represents the runtime instance of this group. Must be a DNS subdomain.
3683 "podGroupName"?: string
3684}
3685
3686// PodSecurityContext holds pod-level security attributes and common container
3687// settings. Some fields are also present in container.securityContext. Field
3688// values of container.securityContext take precedence over field values of
3689// PodSecurityContext.
3690#PodSecurityContext: {
3691 // appArmorProfile is the AppArmor options to use by the containers in this pod.
3692 // Note that this field cannot be set when spec.os.name is windows.
3693 "appArmorProfile"?: #AppArmorProfile
3694
3695 // A special supplemental group that applies to all containers in a pod. Some
3696 // volume types allow the Kubelet to change the ownership of that volume to be
3697 // owned by the pod:
3698 //
3699 // 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files
3700 // created in the volume will be owned by FSGroup) 3. The permission bits are
3701 // OR'd with rw-rw----
3702 //
3703 // If unset, the Kubelet will not modify the ownership and permissions of any
3704 // volume. Note that this field cannot be set when spec.os.name is windows.
3705 "fsGroup"?: int64 & int
3706
3707 // fsGroupChangePolicy defines behavior of changing ownership and permission of
3708 // the volume before being exposed inside Pod. This field will only apply to
3709 // volume types which support fsGroup based ownership(and permissions). It will
3710 // have no effect on ephemeral volume types such as: secret, configmaps and
3711 // emptydir. Valid values are "OnRootMismatch" and "Always". If not specified,
3712 // "Always" is used. Note that this field cannot be set when spec.os.name is
3713 // windows.
3714 "fsGroupChangePolicy"?: string
3715
3716 // The GID to run the entrypoint of the container process. Uses runtime default
3717 // if unset. May also be set in SecurityContext. If set in both SecurityContext
3718 // and PodSecurityContext, the value specified in SecurityContext takes
3719 // precedence for that container. Note that this field cannot be set when
3720 // spec.os.name is windows.
3721 "runAsGroup"?: int64 & int
3722
3723 // Indicates that the container must run as a non-root user. If true, the
3724 // Kubelet will validate the image at runtime to ensure that it does not run as
3725 // UID 0 (root) and fail to start the container if it does. If unset or false,
3726 // no such validation will be performed. May also be set in SecurityContext. If
3727 // set in both SecurityContext and PodSecurityContext, the value specified in
3728 // SecurityContext takes precedence.
3729 "runAsNonRoot"?: bool
3730
3731 // The UID to run the entrypoint of the container process. Defaults to user
3732 // specified in image metadata if unspecified. May also be set in
3733 // SecurityContext. If set in both SecurityContext and PodSecurityContext, the
3734 // value specified in SecurityContext takes precedence for that container. Note
3735 // that this field cannot be set when spec.os.name is windows.
3736 "runAsUser"?: int64 & int
3737
3738 // seLinuxChangePolicy defines how the container's SELinux label is applied to
3739 // all volumes used by the Pod. It has no effect on nodes that do not support
3740 // SELinux or to volumes does not support SELinux. Valid values are
3741 // "MountOption" and "Recursive".
3742 //
3743 // "Recursive" means relabeling of all files on all Pod volumes by the container
3744 // runtime. This may be slow for large volumes, but allows mixing privileged
3745 // and unprivileged Pods sharing the same volume on the same node.
3746 //
3747 // "MountOption" mounts all eligible Pod volumes with `-o context` mount option.
3748 // This requires all Pods that share the same volume to use the same SELinux
3749 // label. It is not possible to share the same volume among privileged and
3750 // unprivileged Pods. Eligible volumes are in-tree FibreChannel and iSCSI
3751 // volumes, and all CSI volumes whose CSI driver announces SELinux support by
3752 // setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes
3753 // are always re-labelled recursively. "MountOption" value is allowed only when
3754 // SELinuxMount feature gate is enabled.
3755 //
3756 // If not specified and SELinuxMount feature gate is enabled, "MountOption" is
3757 // used. If not specified and SELinuxMount feature gate is disabled,
3758 // "MountOption" is used for ReadWriteOncePod volumes and "Recursive" for all
3759 // other volumes.
3760 //
3761 // This field affects only Pods that have SELinux label set, either in
3762 // PodSecurityContext or in SecurityContext of all containers.
3763 //
3764 // All Pods that use the same volume should use the same seLinuxChangePolicy,
3765 // otherwise some pods can get stuck in ContainerCreating state. Note that this
3766 // field cannot be set when spec.os.name is windows.
3767 "seLinuxChangePolicy"?: string
3768
3769 // The SELinux context to be applied to all containers. If unspecified, the
3770 // container runtime will allocate a random SELinux context for each container.
3771 // May also be set in SecurityContext. If set in both SecurityContext and
3772 // PodSecurityContext, the value specified in SecurityContext takes precedence
3773 // for that container. Note that this field cannot be set when spec.os.name is
3774 // windows.
3775 "seLinuxOptions"?: #SELinuxOptions
3776
3777 // The seccomp options to use by the containers in this pod. Note that this
3778 // field cannot be set when spec.os.name is windows.
3779 "seccompProfile"?: #SeccompProfile
3780
3781 // A list of groups applied to the first process run in each container, in
3782 // addition to the container's primary GID and fsGroup (if specified). If the
3783 // SupplementalGroupsPolicy feature is enabled, the supplementalGroupsPolicy
3784 // field determines whether these are in addition to or instead of any group
3785 // memberships defined in the container image. If unspecified, no additional
3786 // groups are added, though group memberships defined in the container image
3787 // may still be used, depending on the supplementalGroupsPolicy field. Note
3788 // that this field cannot be set when spec.os.name is windows.
3789 "supplementalGroups"?: [...int64 & int]
3790
3791 // Defines how supplemental groups of the first container processes are
3792 // calculated. Valid values are "Merge" and "Strict". If not specified, "Merge"
3793 // is used. (Alpha) Using the field requires the SupplementalGroupsPolicy
3794 // feature gate to be enabled and the container runtime must implement support
3795 // for this feature. Note that this field cannot be set when spec.os.name is
3796 // windows.
3797 "supplementalGroupsPolicy"?: string
3798
3799 // Sysctls hold a list of namespaced sysctls used for the pod. Pods with
3800 // unsupported sysctls (by the container runtime) might fail to launch. Note
3801 // that this field cannot be set when spec.os.name is windows.
3802 "sysctls"?: [...#Sysctl]
3803
3804 // The Windows specific settings applied to all containers. If unspecified, the
3805 // options within a container's SecurityContext will be used. If set in both
3806 // SecurityContext and PodSecurityContext, the value specified in
3807 // SecurityContext takes precedence. Note that this field cannot be set when
3808 // spec.os.name is linux.
3809 "windowsOptions"?: #WindowsSecurityContextOptions
3810}
3811
3812// PodSpec is a description of a pod.
3813#PodSpec: {
3814 // Optional duration in seconds the pod may be active on the node relative to
3815 // StartTime before the system will actively try to mark it failed and kill
3816 // associated containers. Value must be a positive integer.
3817 "activeDeadlineSeconds"?: int64 & int
3818
3819 // If specified, the pod's scheduling constraints
3820 "affinity"?: #Affinity
3821
3822 // AutomountServiceAccountToken indicates whether a service account token should
3823 // be automatically mounted.
3824 "automountServiceAccountToken"?: bool
3825
3826 // List of containers belonging to the pod. Containers cannot currently be added
3827 // or removed. There must be at least one container in a Pod. Cannot be
3828 // updated.
3829 "containers"!: [...#Container]
3830
3831 // Specifies the DNS parameters of a pod. Parameters specified here will be
3832 // merged to the generated DNS configuration based on DNSPolicy.
3833 "dnsConfig"?: #PodDNSConfig
3834
3835 // Set DNS policy for the pod. Defaults to "ClusterFirst". Valid values are
3836 // 'ClusterFirstWithHostNet', 'ClusterFirst', 'Default' or 'None'. DNS
3837 // parameters given in DNSConfig will be merged with the policy selected with
3838 // DNSPolicy. To have DNS options set along with hostNetwork, you have to
3839 // specify DNS policy explicitly to 'ClusterFirstWithHostNet'.
3840 "dnsPolicy"?: string
3841
3842 // EnableServiceLinks indicates whether information about services should be
3843 // injected into pod's environment variables, matching the syntax of Docker
3844 // links. Optional: Defaults to true.
3845 "enableServiceLinks"?: bool
3846
3847 // List of ephemeral containers run in this pod. Ephemeral containers may be run
3848 // in an existing pod to perform user-initiated actions such as debugging. This
3849 // list cannot be specified when creating a pod, and it cannot be modified by
3850 // updating the pod spec. In order to add an ephemeral container to an existing
3851 // pod, use the pod's ephemeralcontainers subresource.
3852 "ephemeralContainers"?: [...#EphemeralContainer]
3853
3854 // HostAliases is an optional list of hosts and IPs that will be injected into
3855 // the pod's hosts file if specified.
3856 "hostAliases"?: [...#HostAlias]
3857
3858 // Use the host's ipc namespace. Optional: Default to false.
3859 "hostIPC"?: bool
3860
3861 // Host networking requested for this pod. Use the host's network namespace.
3862 // When using HostNetwork you should specify ports so the scheduler is aware.
3863 // When `hostNetwork` is true, specified `hostPort` fields in port definitions
3864 // must match `containerPort`, and unspecified `hostPort` fields in port
3865 // definitions are defaulted to match `containerPort`. Default to false.
3866 "hostNetwork"?: bool
3867
3868 // Use the host's pid namespace. Optional: Default to false.
3869 "hostPID"?: bool
3870
3871 // Use the host's user namespace. Optional: Default to true. If set to true or
3872 // not present, the pod will be run in the host user namespace, useful for when
3873 // the pod needs a feature only available to the host user namespace, such as
3874 // loading a kernel module with CAP_SYS_MODULE. When set to false, a new userns
3875 // is created for the pod. Setting false is useful for mitigating container
3876 // breakout vulnerabilities even allowing users to run their containers as root
3877 // without actually having root privileges on the host.
3878 "hostUsers"?: bool
3879
3880 // Specifies the hostname of the Pod If not specified, the pod's hostname will
3881 // be set to a system-defined value.
3882 "hostname"?: string
3883
3884 // HostnameOverride specifies an explicit override for the pod's hostname as
3885 // perceived by the pod. This field only specifies the pod's hostname and does
3886 // not affect its DNS records. When this field is set to a non-empty string: -
3887 // It takes precedence over the values set in `hostname` and `subdomain`. - The
3888 // Pod's hostname will be set to this value. - `setHostnameAsFQDN` must be nil
3889 // or set to false. - `hostNetwork` must be set to false.
3890 //
3891 // This field must be a valid DNS subdomain as defined in RFC 1123 and contain
3892 // at most 64 characters. Requires the HostnameOverride feature gate to be
3893 // enabled.
3894 "hostnameOverride"?: string
3895
3896 // ImagePullSecrets is an optional list of references to secrets in the same
3897 // namespace to use for pulling any of the images used by this PodSpec. If
3898 // specified, these secrets will be passed to individual puller implementations
3899 // for them to use. More info:
3900 // https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod
3901 "imagePullSecrets"?: [...#LocalObjectReference]
3902
3903 // List of initialization containers belonging to the pod. Init containers are
3904 // executed in order prior to containers being started. If any init container
3905 // fails, the pod is considered to have failed and is handled according to its
3906 // restartPolicy. The name for an init container or normal container must be
3907 // unique among all containers. Init containers may not have Lifecycle actions,
3908 // Readiness probes, Liveness probes, or Startup probes. The
3909 // resourceRequirements of an init container are taken into account during
3910 // scheduling by finding the highest request/limit for each resource type, and
3911 // then using the max of that value or the sum of the normal containers. Limits
3912 // are applied to init containers in a similar fashion. Init containers cannot
3913 // currently be added or removed. Cannot be updated. More info:
3914 // https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
3915 "initContainers"?: [...#Container]
3916
3917 // NodeName indicates in which node this pod is scheduled. If empty, this pod is
3918 // a candidate for scheduling by the scheduler defined in schedulerName. Once
3919 // this field is set, the kubelet for this node becomes responsible for the
3920 // lifecycle of this pod. This field should not be used to express a desire for
3921 // the pod to be scheduled on a specific node.
3922 // https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodename
3923 "nodeName"?: string
3924
3925 // NodeSelector is a selector which must be true for the pod to fit on a node.
3926 // Selector which must match a node's labels for the pod to be scheduled on
3927 // that node. More info:
3928 // https://kubernetes.io/docs/concepts/configuration/assign-pod-node/
3929 "nodeSelector"?: [string]: string
3930
3931 // Specifies the OS of the containers in the pod. Some pod and container fields
3932 // are restricted if this is set.
3933 //
3934 // If the OS field is set to linux, the following fields must be unset:
3935 // -securityContext.windowsOptions
3936 //
3937 // If the OS field is set to windows, following fields must be unset: -
3938 // spec.hostPID - spec.hostIPC - spec.hostUsers - spec.resources -
3939 // spec.securityContext.appArmorProfile - spec.securityContext.seLinuxOptions -
3940 // spec.securityContext.seccompProfile - spec.securityContext.fsGroup -
3941 // spec.securityContext.fsGroupChangePolicy - spec.securityContext.sysctls -
3942 // spec.shareProcessNamespace - spec.securityContext.runAsUser -
3943 // spec.securityContext.runAsGroup - spec.securityContext.supplementalGroups -
3944 // spec.securityContext.supplementalGroupsPolicy -
3945 // spec.containers[*].securityContext.appArmorProfile -
3946 // spec.containers[*].securityContext.seLinuxOptions -
3947 // spec.containers[*].securityContext.seccompProfile -
3948 // spec.containers[*].securityContext.capabilities -
3949 // spec.containers[*].securityContext.readOnlyRootFilesystem -
3950 // spec.containers[*].securityContext.privileged -
3951 // spec.containers[*].securityContext.allowPrivilegeEscalation -
3952 // spec.containers[*].securityContext.procMount -
3953 // spec.containers[*].securityContext.runAsUser -
3954 // spec.containers[*].securityContext.runAsGroup
3955 "os"?: #PodOS
3956
3957 // Overhead represents the resource overhead associated with running a pod for a
3958 // given RuntimeClass. This field will be autopopulated at admission time by
3959 // the RuntimeClass admission controller. If the RuntimeClass admission
3960 // controller is enabled, overhead must not be set in Pod create requests. The
3961 // RuntimeClass admission controller will reject Pod create requests which have
3962 // the overhead already set. If RuntimeClass is configured and selected in the
3963 // PodSpec, Overhead will be set to the value defined in the corresponding
3964 // RuntimeClass, otherwise it will remain unset and treated as zero. More info:
3965 // https://git.k8s.io/enhancements/keps/sig-node/688-pod-overhead/README.md
3966 "overhead"?: [string]: resource.#Quantity
3967
3968 // PreemptionPolicy is the Policy for preempting pods with lower priority. One
3969 // of Never, PreemptLowerPriority. Defaults to PreemptLowerPriority if unset.
3970 "preemptionPolicy"?: string
3971
3972 // The priority value. Various system components use this field to find the
3973 // priority of the pod. When Priority Admission Controller is enabled, it
3974 // prevents users from setting this field. The admission controller populates
3975 // this field from PriorityClassName. The higher the value, the higher the
3976 // priority.
3977 "priority"?: int32 & int
3978
3979 // If specified, indicates the pod's priority. "system-node-critical" and
3980 // "system-cluster-critical" are two special keywords which indicate the
3981 // highest priorities with the former being the highest priority. Any other
3982 // name must be defined by creating a PriorityClass object with that name. If
3983 // not specified, the pod priority will be default or zero if there is no
3984 // default.
3985 "priorityClassName"?: string
3986
3987 // If specified, all readiness gates will be evaluated for pod readiness. A pod
3988 // is ready when all its containers are ready AND all conditions specified in
3989 // the readiness gates have status equal to "True" More info:
3990 // https://git.k8s.io/enhancements/keps/sig-network/580-pod-readiness-gates
3991 "readinessGates"?: [...#PodReadinessGate]
3992
3993 // ResourceClaims defines which ResourceClaims must be allocated and reserved
3994 // before the Pod is allowed to start. The resources will be made available to
3995 // those containers which consume them by name.
3996 //
3997 // This is a stable field but requires that the DynamicResourceAllocation feature gate is enabled.
3998 //
3999 // This field is immutable.
4000 "resourceClaims"?: [...#PodResourceClaim]
4001
4002 // Resources is the total amount of CPU and Memory resources required by all
4003 // containers in the pod. It supports specifying Requests and Limits for "cpu",
4004 // "memory" and "hugepages-" resource names only. ResourceClaims are not
4005 // supported.
4006 //
4007 // This field enables fine-grained control over resource allocation for the
4008 // entire pod, allowing resource sharing among containers in a pod.
4009 //
4010 // This is an alpha field and requires enabling the PodLevelResources feature gate.
4011 "resources"?: #ResourceRequirements
4012
4013 // Restart policy for all containers within the pod. One of Always, OnFailure,
4014 // Never. In some contexts, only a subset of those values may be permitted.
4015 // Default to Always. More info:
4016 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#restart-policy
4017 "restartPolicy"?: string
4018
4019 // RuntimeClassName refers to a RuntimeClass object in the node.k8s.io group,
4020 // which should be used to run this pod. If no RuntimeClass resource matches
4021 // the named class, the pod will not be run. If unset or empty, the "legacy"
4022 // RuntimeClass will be used, which is an implicit class with an empty
4023 // definition that uses the default runtime handler. More info:
4024 // https://git.k8s.io/enhancements/keps/sig-node/585-runtime-class
4025 "runtimeClassName"?: string
4026
4027 // If specified, the pod will be dispatched by specified scheduler. If not
4028 // specified, the pod will be dispatched by default scheduler.
4029 "schedulerName"?: string
4030
4031 // SchedulingGates is an opaque list of values that if specified will block
4032 // scheduling the pod. If schedulingGates is not empty, the pod will stay in
4033 // the SchedulingGated state and the scheduler will not attempt to schedule the
4034 // pod.
4035 //
4036 // SchedulingGates can only be set at pod creation time, and be removed only afterwards.
4037 "schedulingGates"?: [...#PodSchedulingGate]
4038
4039 // SchedulingGroup provides a reference to the immediate scheduling runtime
4040 // grouping object that this Pod belongs to. This field is used by the
4041 // scheduler to identify the group and apply the correct group scheduling
4042 // policies. The association with a group also impacts other lifecycle aspects
4043 // of a Pod that are relevant in a wider context of scheduling like preemption,
4044 // resource attachment, etc. If not specified, the Pod is treated as a single
4045 // unit in all of these aspects. The group object referenced by this field may
4046 // not exist at the time the Pod is created. This field is immutable, but a
4047 // group object with the same name may be recreated with different policies.
4048 // Doing this during pod scheduling may result in the placement not conforming
4049 // to the expected policies.
4050 "schedulingGroup"?: #PodSchedulingGroup
4051
4052 // SecurityContext holds pod-level security attributes and common container
4053 // settings. Optional: Defaults to empty. See type description for default
4054 // values of each field.
4055 "securityContext"?: #PodSecurityContext
4056
4057 // DeprecatedServiceAccount is a deprecated alias for ServiceAccountName.
4058 // Deprecated: Use serviceAccountName instead.
4059 "serviceAccount"?: string
4060
4061 // ServiceAccountName is the name of the ServiceAccount to use to run this pod.
4062 // More info:
4063 // https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
4064 "serviceAccountName"?: string
4065
4066 // If true the pod's hostname will be configured as the pod's FQDN, rather than
4067 // the leaf name (the default). In Linux containers, this means setting the
4068 // FQDN in the hostname field of the kernel (the nodename field of struct
4069 // utsname). In Windows containers, this means setting the registry value of
4070 // hostname for the registry key
4071 // HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters
4072 // to FQDN. If a pod does not have FQDN, this has no effect. Default to false.
4073 "setHostnameAsFQDN"?: bool
4074
4075 // Share a single process namespace between all of the containers in a pod. When
4076 // this is set containers will be able to view and signal processes from other
4077 // containers in the same pod, and the first process in each container will not
4078 // be assigned PID 1. HostPID and ShareProcessNamespace cannot both be set.
4079 // Optional: Default to false.
4080 "shareProcessNamespace"?: bool
4081
4082 // If specified, the fully qualified Pod hostname will be
4083 // "<hostname>.<subdomain>.<pod namespace>.svc.<cluster domain>". If not
4084 // specified, the pod will not have a domainname at all.
4085 "subdomain"?: string
4086
4087 // Optional duration in seconds the pod needs to terminate gracefully. May be
4088 // decreased in delete request. Value must be non-negative integer. The value
4089 // zero indicates stop immediately via the kill signal (no opportunity to shut
4090 // down). If this value is nil, the default grace period will be used instead.
4091 // The grace period is the duration in seconds after the processes running in
4092 // the pod are sent a termination signal and the time when the processes are
4093 // forcibly halted with a kill signal. Set this value longer than the expected
4094 // cleanup time for your process. Defaults to 30 seconds.
4095 "terminationGracePeriodSeconds"?: int64 & int
4096
4097 // If specified, the pod's tolerations.
4098 "tolerations"?: [...#Toleration]
4099
4100 // TopologySpreadConstraints describes how a group of pods ought to spread
4101 // across topology domains. Scheduler will schedule pods in a way which abides
4102 // by the constraints. All topologySpreadConstraints are ANDed.
4103 "topologySpreadConstraints"?: [...#TopologySpreadConstraint]
4104
4105 // List of volumes that can be mounted by containers belonging to the pod. More
4106 // info: https://kubernetes.io/docs/concepts/storage/volumes
4107 "volumes"?: [...#Volume]
4108}
4109
4110// PodStatus represents information about the status of a pod. Status may trail
4111// the actual state of a system, especially if the node that hosts the pod
4112// cannot contact the control plane.
4113#PodStatus: {
4114 // AllocatedResources is the total requests allocated for this pod by the node.
4115 // If pod-level requests are not set, this will be the total requests
4116 // aggregated across containers in the pod.
4117 "allocatedResources"?: [string]: resource.#Quantity
4118
4119 // Current service state of pod. More info:
4120 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-conditions
4121 "conditions"?: [...#PodCondition]
4122
4123 // Statuses of containers in this pod. Each container in the pod should have at
4124 // most one status in this list, and all statuses should be for containers in
4125 // the pod. However this is not enforced. If a status for a non-existent
4126 // container is present in the list, or the list has duplicate names, the
4127 // behavior of various Kubernetes components is not defined and those statuses
4128 // might be ignored. More info:
4129 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-and-container-status
4130 "containerStatuses"?: [...#ContainerStatus]
4131
4132 // Statuses for any ephemeral containers that have run in this pod. Each
4133 // ephemeral container in the pod should have at most one status in this list,
4134 // and all statuses should be for containers in the pod. However this is not
4135 // enforced. If a status for a non-existent container is present in the list,
4136 // or the list has duplicate names, the behavior of various Kubernetes
4137 // components is not defined and those statuses might be ignored. More info:
4138 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-and-container-status
4139 "ephemeralContainerStatuses"?: [...#ContainerStatus]
4140
4141 // Status of extended resource claim backed by DRA.
4142 "extendedResourceClaimStatus"?: #PodExtendedResourceClaimStatus
4143
4144 // hostIP holds the IP address of the host to which the pod is assigned. Empty
4145 // if the pod has not started yet. A pod can be assigned to a node that has a
4146 // problem in kubelet which in turns mean that HostIP will not be updated even
4147 // if there is a node is assigned to pod
4148 "hostIP"?: string
4149
4150 // hostIPs holds the IP addresses allocated to the host. If this field is
4151 // specified, the first entry must match the hostIP field. This list is empty
4152 // if the pod has not started yet. A pod can be assigned to a node that has a
4153 // problem in kubelet which in turns means that HostIPs will not be updated
4154 // even if there is a node is assigned to this pod.
4155 "hostIPs"?: [...#HostIP]
4156
4157 // Statuses of init containers in this pod. The most recent successful
4158 // non-restartable init container will have ready = true, the most recently
4159 // started container will have startTime set. Each init container in the pod
4160 // should have at most one status in this list, and all statuses should be for
4161 // containers in the pod. However this is not enforced. If a status for a
4162 // non-existent container is present in the list, or the list has duplicate
4163 // names, the behavior of various Kubernetes components is not defined and
4164 // those statuses might be ignored. More info:
4165 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-and-container-status
4166 "initContainerStatuses"?: [...#ContainerStatus]
4167
4168 // A human readable message indicating details about why the pod is in this condition.
4169 "message"?: string
4170
4171 // NodeAllocatableResourceClaimStatuses contains the status of node-allocatable
4172 // resources that were allocated for this pod through DRA claims. This includes
4173 // resources currently reported in v1.Node `status.allocatable` that are not
4174 // extended resources (see
4175 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#extended-resources).
4176 // Examples include "cpu", "memory", "ephemeral-storage", and hugepages.
4177 "nodeAllocatableResourceClaimStatuses"?: [...#NodeAllocatableResourceClaimStatus]
4178
4179 // nominatedNodeName is set only when this pod preempts other pods on the node,
4180 // but it cannot be scheduled right away as preemption victims receive their
4181 // graceful termination periods. This field does not guarantee that the pod
4182 // will be scheduled on this node. Scheduler may decide to place the pod
4183 // elsewhere if other nodes become available sooner. Scheduler may also decide
4184 // to give the resources on this node to a higher priority pod that is created
4185 // after preemption. As a result, this field may be different than
4186 // PodSpec.nodeName when the pod is scheduled.
4187 "nominatedNodeName"?: string
4188
4189 // If set, this represents the .metadata.generation that the pod status was set
4190 // based upon. The PodObservedGenerationTracking feature gate must be enabled
4191 // to use this field.
4192 "observedGeneration"?: int64 & int
4193
4194 // The phase of a Pod is a simple, high-level summary of where the Pod is in its
4195 // lifecycle. The conditions array, the reason and message fields, and the
4196 // individual container status arrays contain more detail about the pod's
4197 // status. There are five possible phase values:
4198 //
4199 // Pending: The pod has been accepted by the Kubernetes system, but one or more
4200 // of the container images has not been created. This includes time before
4201 // being scheduled as well as time spent downloading images over the network,
4202 // which could take a while. Running: The pod has been bound to a node, and all
4203 // of the containers have been created. At least one container is still
4204 // running, or is in the process of starting or restarting. Succeeded: All
4205 // containers in the pod have terminated in success, and will not be restarted.
4206 // Failed: All containers in the pod have terminated, and at least one
4207 // container has terminated in failure. The container either exited with
4208 // non-zero status or was terminated by the system. Unknown: For some reason
4209 // the state of the pod could not be obtained, typically due to an error in
4210 // communicating with the host of the pod.
4211 //
4212 // More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-phase
4213 "phase"?: string
4214
4215 // podIP address allocated to the pod. Routable at least within the cluster.
4216 // Empty if not yet allocated.
4217 "podIP"?: string
4218
4219 // podIPs holds the IP addresses allocated to the pod. If this field is
4220 // specified, the 0th entry must match the podIP field. Pods may be allocated
4221 // at most 1 value for each of IPv4 and IPv6. This list is empty if no IPs have
4222 // been allocated yet.
4223 "podIPs"?: [...#PodIP]
4224
4225 // The Quality of Service (QOS) classification assigned to the pod based on
4226 // resource requirements See PodQOSClass type for available QOS classes More
4227 // info:
4228 // https://kubernetes.io/docs/concepts/workloads/pods/pod-qos/#quality-of-service-classes
4229 "qosClass"?: string
4230
4231 // A brief CamelCase message indicating details about why the pod is in this state. e.g. 'Evicted'
4232 "reason"?: string
4233
4234 // Status of resources resize desired for pod's containers. It is empty if no
4235 // resources resize is pending. Any changes to container resources will
4236 // automatically set this to "Proposed" Deprecated: Resize status is moved to
4237 // two pod conditions PodResizePending and PodResizeInProgress.
4238 // PodResizePending will track states where the spec has been resized, but the
4239 // Kubelet has not yet allocated the resources. PodResizeInProgress will track
4240 // in-progress resizes, and should be present whenever allocated resources !=
4241 // acknowledged resources.
4242 "resize"?: string
4243
4244 // Status of resource claims.
4245 "resourceClaimStatuses"?: [...#PodResourceClaimStatus]
4246
4247 // Resources represents the compute resource requests and limits that have been
4248 // applied at the pod level if pod-level requests or limits are set in
4249 // PodSpec.Resources
4250 "resources"?: #ResourceRequirements
4251
4252 // RFC 3339 date and time at which the object was acknowledged by the Kubelet.
4253 // This is before the Kubelet pulled the container image(s) for the pod.
4254 "startTime"?: v1.#Time
4255}
4256
4257// PodTemplate describes a template for creating copies of a predefined pod.
4258#PodTemplate: {
4259 // APIVersion defines the versioned schema of this representation of an object.
4260 // Servers should convert recognized schemas to the latest internal value, and
4261 // may reject unrecognized values. More info:
4262 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4263 "apiVersion": "v1"
4264
4265 // Kind is a string value representing the REST resource this object represents.
4266 // Servers may infer this from the endpoint the client submits requests to.
4267 // Cannot be updated. In CamelCase. More info:
4268 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4269 "kind": "PodTemplate"
4270
4271 // Standard object's metadata. More info:
4272 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4273 "metadata"?: v1.#ObjectMeta
4274
4275 // Template defines the pods that will be created from this pod template.
4276 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4277 "template"?: #PodTemplateSpec
4278}
4279
4280// PodTemplateList is a list of PodTemplates.
4281#PodTemplateList: {
4282 // APIVersion defines the versioned schema of this representation of an object.
4283 // Servers should convert recognized schemas to the latest internal value, and
4284 // may reject unrecognized values. More info:
4285 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4286 "apiVersion": "v1"
4287
4288 // List of pod templates
4289 "items"!: [...#PodTemplate]
4290
4291 // Kind is a string value representing the REST resource this object represents.
4292 // Servers may infer this from the endpoint the client submits requests to.
4293 // Cannot be updated. In CamelCase. More info:
4294 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4295 "kind": "PodTemplateList"
4296
4297 // Standard list metadata. More info:
4298 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4299 "metadata"?: v1.#ListMeta
4300}
4301
4302// PodTemplateSpec describes the data a pod should have when created from a template
4303#PodTemplateSpec: {
4304 // Standard object's metadata. More info:
4305 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4306 "metadata"?: v1.#ObjectMeta
4307
4308 // Specification of the desired behavior of the pod. More info:
4309 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4310 "spec"?: #PodSpec
4311}
4312
4313// PortStatus represents the error condition of a service port
4314#PortStatus: {
4315 // Error is to record the problem with the service port The format of the error
4316 // shall comply with the following rules: - built-in error values shall be
4317 // specified in this file and those shall use
4318 // CamelCase names
4319 // - cloud provider specific error values must have names that comply with the
4320 // format foo.example.com/CamelCase.
4321 "error"?: string
4322
4323 // Port is the port number of the service port of which status is recorded here
4324 "port"!: int32 & int
4325
4326 // Protocol is the protocol of the service port of which status is recorded here
4327 // The supported values are: "TCP", "UDP", "SCTP"
4328 "protocol"!: string
4329}
4330
4331// PortworxVolumeSource represents a Portworx volume resource.
4332#PortworxVolumeSource: {
4333 // fSType represents the filesystem type to mount Must be a filesystem type
4334 // supported by the host operating system. Ex. "ext4", "xfs". Implicitly
4335 // inferred to be "ext4" if unspecified.
4336 "fsType"?: string
4337
4338 // readOnly defaults to false (read/write). ReadOnly here will force the
4339 // ReadOnly setting in VolumeMounts.
4340 "readOnly"?: bool
4341
4342 // volumeID uniquely identifies a Portworx volume
4343 "volumeID"!: string
4344}
4345
4346// An empty preferred scheduling term matches all objects with implicit weight 0
4347// (i.e. it's a no-op). A null preferred scheduling term matches no objects
4348// (i.e. is also a no-op).
4349#PreferredSchedulingTerm: {
4350 // A node selector term, associated with the corresponding weight.
4351 "preference"!: #NodeSelectorTerm
4352
4353 // Weight associated with matching the corresponding nodeSelectorTerm, in the range 1-100.
4354 "weight"!: int32 & int
4355}
4356
4357// Probe describes a health check to be performed against a container to
4358// determine whether it is alive or ready to receive traffic.
4359#Probe: {
4360 // Exec specifies a command to execute in the container.
4361 "exec"?: #ExecAction
4362
4363 // Minimum consecutive failures for the probe to be considered failed after
4364 // having succeeded. Defaults to 3. Minimum value is 1.
4365 "failureThreshold"?: int32 & int
4366
4367 // GRPC specifies a GRPC HealthCheckRequest.
4368 "grpc"?: #GRPCAction
4369
4370 // HTTPGet specifies an HTTP GET request to perform.
4371 "httpGet"?: #HTTPGetAction
4372
4373 // Number of seconds after the container has started before liveness probes are
4374 // initiated. More info:
4375 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
4376 "initialDelaySeconds"?: int32 & int
4377
4378 // How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is 1.
4379 "periodSeconds"?: int32 & int
4380
4381 // Minimum consecutive successes for the probe to be considered successful after
4382 // having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum
4383 // value is 1.
4384 "successThreshold"?: int32 & int
4385
4386 // TCPSocket specifies a connection to a TCP port.
4387 "tcpSocket"?: #TCPSocketAction
4388
4389 // Optional duration in seconds the pod needs to terminate gracefully upon probe
4390 // failure. The grace period is the duration in seconds after the processes
4391 // running in the pod are sent a termination signal and the time when the
4392 // processes are forcibly halted with a kill signal. Set this value longer than
4393 // the expected cleanup time for your process. If this value is nil, the pod's
4394 // terminationGracePeriodSeconds will be used. Otherwise, this value overrides
4395 // the value provided by the pod spec. Value must be non-negative integer. The
4396 // value zero indicates stop immediately via the kill signal (no opportunity to
4397 // shut down). This is a beta field and requires enabling
4398 // ProbeTerminationGracePeriod feature gate. Minimum value is 1.
4399 // spec.terminationGracePeriodSeconds is used if unset.
4400 "terminationGracePeriodSeconds"?: int64 & int
4401
4402 // Number of seconds after which the probe times out. Defaults to 1 second.
4403 // Minimum value is 1. More info:
4404 // https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
4405 "timeoutSeconds"?: int32 & int
4406}
4407
4408// Represents a projected volume source
4409#ProjectedVolumeSource: {
4410 // defaultMode are the mode bits used to set permissions on created files by
4411 // default. Must be an octal value between 0000 and 0777 or a decimal value
4412 // between 0 and 511. YAML accepts both octal and decimal values, JSON requires
4413 // decimal values for mode bits. Directories within the path are not affected
4414 // by this setting. This might be in conflict with other options that affect
4415 // the file mode, like fsGroup, and the result can be other mode bits set.
4416 "defaultMode"?: int32 & int
4417
4418 // sources is the list of volume projections. Each entry in this list handles one source.
4419 "sources"?: [...#VolumeProjection]
4420}
4421
4422// Represents a Quobyte mount that lasts the lifetime of a pod. Quobyte volumes
4423// do not support ownership management or SELinux relabeling.
4424#QuobyteVolumeSource: {
4425 // group to map volume access to Default is no group
4426 "group"?: string
4427
4428 // readOnly here will force the Quobyte volume to be mounted with read-only
4429 // permissions. Defaults to false.
4430 "readOnly"?: bool
4431
4432 // registry represents a single or multiple Quobyte Registry services specified
4433 // as a string as host:port pair (multiple entries are separated with commas)
4434 // which acts as the central registry for volumes
4435 "registry"!: string
4436
4437 // tenant owning the given Quobyte volume in the Backend Used with dynamically
4438 // provisioned Quobyte volumes, value is set by the plugin
4439 "tenant"?: string
4440
4441 // user to map volume access to Defaults to serivceaccount user
4442 "user"?: string
4443
4444 // volume is a string that references an already created Quobyte volume by name.
4445 "volume"!: string
4446}
4447
4448// Represents a Rados Block Device mount that lasts the lifetime of a pod. RBD
4449// volumes support ownership management and SELinux relabeling.
4450#RBDPersistentVolumeSource: {
4451 // fsType is the filesystem type of the volume that you want to mount. Tip:
4452 // Ensure that the filesystem type is supported by the host operating system.
4453 // Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
4454 // unspecified. More info:
4455 // https://kubernetes.io/docs/concepts/storage/volumes#rbd
4456 "fsType"?: string
4457
4458 // image is the rados image name. More info:
4459 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4460 "image"!: string
4461
4462 // keyring is the path to key ring for RBDUser. Default is /etc/ceph/keyring.
4463 // More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4464 "keyring"?: string
4465
4466 // monitors is a collection of Ceph monitors. More info:
4467 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4468 "monitors"!: [...string]
4469
4470 // pool is the rados pool name. Default is rbd. More info:
4471 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4472 "pool"?: string
4473
4474 // readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to
4475 // false. More info:
4476 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4477 "readOnly"?: bool
4478
4479 // secretRef is name of the authentication secret for RBDUser. If provided
4480 // overrides keyring. Default is nil. More info:
4481 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4482 "secretRef"?: #SecretReference
4483
4484 // user is the rados user name. Default is admin. More info:
4485 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4486 "user"?: string
4487}
4488
4489// Represents a Rados Block Device mount that lasts the lifetime of a pod. RBD
4490// volumes support ownership management and SELinux relabeling.
4491#RBDVolumeSource: {
4492 // fsType is the filesystem type of the volume that you want to mount. Tip:
4493 // Ensure that the filesystem type is supported by the host operating system.
4494 // Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
4495 // unspecified. More info:
4496 // https://kubernetes.io/docs/concepts/storage/volumes#rbd
4497 "fsType"?: string
4498
4499 // image is the rados image name. More info:
4500 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4501 "image"!: string
4502
4503 // keyring is the path to key ring for RBDUser. Default is /etc/ceph/keyring.
4504 // More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4505 "keyring"?: string
4506
4507 // monitors is a collection of Ceph monitors. More info:
4508 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4509 "monitors"!: [...string]
4510
4511 // pool is the rados pool name. Default is rbd. More info:
4512 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4513 "pool"?: string
4514
4515 // readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to
4516 // false. More info:
4517 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4518 "readOnly"?: bool
4519
4520 // secretRef is name of the authentication secret for RBDUser. If provided
4521 // overrides keyring. Default is nil. More info:
4522 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4523 "secretRef"?: #LocalObjectReference
4524
4525 // user is the rados user name. Default is admin. More info:
4526 // https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4527 "user"?: string
4528}
4529
4530// ReplicationController represents the configuration of a replication controller.
4531#ReplicationController: {
4532 // APIVersion defines the versioned schema of this representation of an object.
4533 // Servers should convert recognized schemas to the latest internal value, and
4534 // may reject unrecognized values. More info:
4535 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4536 "apiVersion": "v1"
4537
4538 // Kind is a string value representing the REST resource this object represents.
4539 // Servers may infer this from the endpoint the client submits requests to.
4540 // Cannot be updated. In CamelCase. More info:
4541 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4542 "kind": "ReplicationController"
4543
4544 // If the Labels of a ReplicationController are empty, they are defaulted to be
4545 // the same as the Pod(s) that the replication controller manages. Standard
4546 // object's metadata. More info:
4547 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4548 "metadata"?: v1.#ObjectMeta
4549
4550 // Spec defines the specification of the desired behavior of the replication
4551 // controller. More info:
4552 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4553 "spec"?: #ReplicationControllerSpec
4554
4555 // Status is the most recently observed status of the replication controller.
4556 // This data may be out of date by some window of time. Populated by the
4557 // system. Read-only. More info:
4558 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4559 "status"?: #ReplicationControllerStatus
4560}
4561
4562// ReplicationControllerCondition describes the state of a replication
4563// controller at a certain point.
4564#ReplicationControllerCondition: {
4565 // The last time the condition transitioned from one status to another.
4566 "lastTransitionTime"?: v1.#Time
4567
4568 // A human readable message indicating details about the transition.
4569 "message"?: string
4570
4571 // The reason for the condition's last transition.
4572 "reason"?: string
4573
4574 // Status of the condition, one of True, False, Unknown.
4575 "status"!: string
4576
4577 // Type of replication controller condition.
4578 "type"!: string
4579}
4580
4581// ReplicationControllerList is a collection of replication controllers.
4582#ReplicationControllerList: {
4583 // APIVersion defines the versioned schema of this representation of an object.
4584 // Servers should convert recognized schemas to the latest internal value, and
4585 // may reject unrecognized values. More info:
4586 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4587 "apiVersion": "v1"
4588
4589 // List of replication controllers. More info:
4590 // https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller
4591 "items"!: [...#ReplicationController]
4592
4593 // Kind is a string value representing the REST resource this object represents.
4594 // Servers may infer this from the endpoint the client submits requests to.
4595 // Cannot be updated. In CamelCase. More info:
4596 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4597 "kind": "ReplicationControllerList"
4598
4599 // Standard list metadata. More info:
4600 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4601 "metadata"?: v1.#ListMeta
4602}
4603
4604// ReplicationControllerSpec is the specification of a replication controller.
4605#ReplicationControllerSpec: {
4606 // Minimum number of seconds for which a newly created pod should be ready
4607 // without any of its container crashing, for it to be considered available.
4608 // Defaults to 0 (pod will be considered available as soon as it is ready)
4609 "minReadySeconds"?: int32 & int
4610
4611 // Replicas is the number of desired replicas. This is a pointer to distinguish
4612 // between explicit zero and unspecified. Defaults to 1. More info:
4613 // https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#what-is-a-replicationcontroller
4614 "replicas"?: int32 & int
4615
4616 // Selector is a label query over pods that should match the Replicas count. If
4617 // Selector is empty, it is defaulted to the labels present on the Pod
4618 // template. Label keys and values that must match in order to be controlled by
4619 // this replication controller, if empty defaulted to labels on Pod template.
4620 // More info:
4621 // https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors
4622 "selector"?: [string]: string
4623
4624 // Template is the object that describes the pod that will be created if
4625 // insufficient replicas are detected. This takes precedence over a
4626 // TemplateRef. The only allowed template.spec.restartPolicy value is "Always".
4627 // More info:
4628 // https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#pod-template
4629 "template"?: #PodTemplateSpec
4630}
4631
4632// ReplicationControllerStatus represents the current status of a replication controller.
4633#ReplicationControllerStatus: {
4634 // The number of available replicas (ready for at least minReadySeconds) for
4635 // this replication controller.
4636 "availableReplicas"?: int32 & int
4637
4638 // Represents the latest available observations of a replication controller's current state.
4639 "conditions"?: [...#ReplicationControllerCondition]
4640
4641 // The number of pods that have labels matching the labels of the pod template
4642 // of the replication controller.
4643 "fullyLabeledReplicas"?: int32 & int
4644
4645 // ObservedGeneration reflects the generation of the most recently observed replication controller.
4646 "observedGeneration"?: int64 & int
4647
4648 // The number of ready replicas for this replication controller.
4649 "readyReplicas"?: int32 & int
4650
4651 // Replicas is the most recently observed number of replicas. More info:
4652 // https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#what-is-a-replicationcontroller
4653 "replicas"!: int32 & int
4654}
4655
4656// ResourceClaim references one entry in PodSpec.ResourceClaims.
4657#ResourceClaim: {
4658 // Name must match the name of one entry in pod.spec.resourceClaims of the Pod
4659 // where this field is used. It makes that resource available inside a
4660 // container.
4661 "name"!: string
4662
4663 // Request is the name chosen for a request in the referenced claim. If empty,
4664 // everything from the claim is made available, otherwise only the result of
4665 // this request.
4666 "request"?: string
4667}
4668
4669// ResourceFieldSelector represents container resources (cpu, memory) and their output format
4670#ResourceFieldSelector: {
4671 // Container name: required for volumes, optional for env vars
4672 "containerName"?: string
4673
4674 // Specifies the output format of the exposed resources, defaults to "1"
4675 "divisor"?: resource.#Quantity
4676
4677 // Required: resource to select
4678 "resource"!: string
4679}
4680
4681// ResourceHealth represents the health of a resource. It has the latest device
4682// health information. This is a part of KEP https://kep.k8s.io/4680.
4683#ResourceHealth: {
4684 // Health of the resource. can be one of:
4685 // - Healthy: operates as normal
4686 // - Unhealthy: reported unhealthy. We consider this a temporary health issue
4687 // since we do not have a mechanism today to distinguish
4688 // temporary and permanent issues.
4689 // - Unknown: The status cannot be determined.
4690 // For example, Device Plugin got unregistered and hasn't been re-registered since.
4691 //
4692 // In future we may want to introduce the PermanentlyUnhealthy Status.
4693 "health"?: string
4694
4695 // Message provides human-readable context for Health (e.g. "ECC error count
4696 // exceeded threshold"). This field is populated by the kubelet when
4697 // ResourceHealthStatusMessage is enabled if the DRA plugin returns a message,
4698 // and is null otherwise.
4699 "message"?: string
4700
4701 // ResourceID is the unique identifier of the resource. See the ResourceID type
4702 // for more information.
4703 "resourceID"!: string
4704}
4705
4706// ResourceQuota sets aggregate quota restrictions enforced per namespace
4707#ResourceQuota: {
4708 // APIVersion defines the versioned schema of this representation of an object.
4709 // Servers should convert recognized schemas to the latest internal value, and
4710 // may reject unrecognized values. More info:
4711 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4712 "apiVersion": "v1"
4713
4714 // Kind is a string value representing the REST resource this object represents.
4715 // Servers may infer this from the endpoint the client submits requests to.
4716 // Cannot be updated. In CamelCase. More info:
4717 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4718 "kind": "ResourceQuota"
4719
4720 // Standard object's metadata. More info:
4721 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4722 "metadata"?: v1.#ObjectMeta
4723
4724 // Spec defines the desired quota.
4725 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4726 "spec"?: #ResourceQuotaSpec
4727
4728 // Status defines the actual enforced quota and its current usage.
4729 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4730 "status"?: #ResourceQuotaStatus
4731}
4732
4733// ResourceQuotaList is a list of ResourceQuota items.
4734#ResourceQuotaList: {
4735 // APIVersion defines the versioned schema of this representation of an object.
4736 // Servers should convert recognized schemas to the latest internal value, and
4737 // may reject unrecognized values. More info:
4738 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4739 "apiVersion": "v1"
4740
4741 // Items is a list of ResourceQuota objects. More info:
4742 // https://kubernetes.io/docs/concepts/policy/resource-quotas/
4743 "items"!: [...#ResourceQuota]
4744
4745 // Kind is a string value representing the REST resource this object represents.
4746 // Servers may infer this from the endpoint the client submits requests to.
4747 // Cannot be updated. In CamelCase. More info:
4748 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4749 "kind": "ResourceQuotaList"
4750
4751 // Standard list metadata. More info:
4752 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4753 "metadata"?: v1.#ListMeta
4754}
4755
4756// ResourceQuotaSpec defines the desired hard limits to enforce for Quota.
4757#ResourceQuotaSpec: {
4758 // hard is the set of desired hard limits for each named resource. More info:
4759 // https://kubernetes.io/docs/concepts/policy/resource-quotas/
4760 "hard"?: [string]: resource.#Quantity
4761
4762 // scopeSelector is also a collection of filters like scopes that must match
4763 // each object tracked by a quota but expressed using ScopeSelectorOperator in
4764 // combination with possible values. For a resource to match, both scopes AND
4765 // scopeSelector (if specified in spec), must be matched.
4766 "scopeSelector"?: #ScopeSelector
4767
4768 // A collection of filters that must match each object tracked by a quota. If
4769 // not specified, the quota matches all objects.
4770 "scopes"?: [...string]
4771}
4772
4773// ResourceQuotaStatus defines the enforced hard limits and observed use.
4774#ResourceQuotaStatus: {
4775 // Hard is the set of enforced hard limits for each named resource. More info:
4776 // https://kubernetes.io/docs/concepts/policy/resource-quotas/
4777 "hard"?: [string]: resource.#Quantity
4778
4779 // Used is the current observed total usage of the resource in the namespace.
4780 "used"?: [string]: resource.#Quantity
4781}
4782
4783// ResourceRequirements describes the compute resource requirements.
4784#ResourceRequirements: {
4785 // Claims lists the names of resources, defined in spec.resourceClaims, that are
4786 // used by this container.
4787 //
4788 // This field depends on the DynamicResourceAllocation feature gate.
4789 //
4790 // This field is immutable. It can only be set for containers.
4791 "claims"?: [...#ResourceClaim]
4792
4793 // Limits describes the maximum amount of compute resources allowed. More info:
4794 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
4795 "limits"?: [string]: resource.#Quantity
4796
4797 // Requests describes the minimum amount of compute resources required. If
4798 // Requests is omitted for a container, it defaults to Limits if that is
4799 // explicitly specified, otherwise to an implementation-defined value. Requests
4800 // cannot exceed Limits. More info:
4801 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
4802 "requests"?: [string]: resource.#Quantity
4803}
4804
4805// ResourceStatus represents the status of a single resource allocated to a Pod.
4806#ResourceStatus: {
4807 // Name of the resource. Must be unique within the pod and in case of non-DRA
4808 // resource, match one of the resources from the pod spec. For DRA resources,
4809 // the value must be "claim:<claim_name>/<request>". When this status is
4810 // reported about a container, the "claim_name" and "request" must match one of
4811 // the claims of this container.
4812 "name"!: string
4813
4814 // List of unique resources health. Each element in the list contains an unique
4815 // resource ID and its health. At a minimum, for the lifetime of a Pod,
4816 // resource ID must uniquely identify the resource allocated to the Pod on the
4817 // Node. If other Pod on the same Node reports the status with the same
4818 // resource ID, it must be the same resource they share. See ResourceID type
4819 // definition for a specific format it has in various use cases.
4820 "resources"?: [...#ResourceHealth]
4821}
4822
4823// SELinuxOptions are the labels to be applied to the container
4824#SELinuxOptions: {
4825 // Level is SELinux level label that applies to the container.
4826 "level"?: string
4827
4828 // Role is a SELinux role label that applies to the container.
4829 "role"?: string
4830
4831 // Type is a SELinux type label that applies to the container.
4832 "type"?: string
4833
4834 // User is a SELinux user label that applies to the container.
4835 "user"?: string
4836}
4837
4838// ScaleIOPersistentVolumeSource represents a persistent ScaleIO volume
4839#ScaleIOPersistentVolumeSource: {
4840 // fsType is the filesystem type to mount. Must be a filesystem type supported
4841 // by the host operating system. Ex. "ext4", "xfs", "ntfs". Default is "xfs"
4842 "fsType"?: string
4843
4844 // gateway is the host address of the ScaleIO API Gateway.
4845 "gateway"!: string
4846
4847 // protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.
4848 "protectionDomain"?: string
4849
4850 // readOnly defaults to false (read/write). ReadOnly here will force the
4851 // ReadOnly setting in VolumeMounts.
4852 "readOnly"?: bool
4853
4854 // secretRef references to the secret for ScaleIO user and other sensitive
4855 // information. If this is not provided, Login operation will fail.
4856 "secretRef"!: #SecretReference
4857
4858 // sslEnabled is the flag to enable/disable SSL communication with Gateway, default false
4859 "sslEnabled"?: bool
4860
4861 // storageMode indicates whether the storage for a volume should be
4862 // ThickProvisioned or ThinProvisioned. Default is ThinProvisioned.
4863 "storageMode"?: string
4864
4865 // storagePool is the ScaleIO Storage Pool associated with the protection domain.
4866 "storagePool"?: string
4867
4868 // system is the name of the storage system as configured in ScaleIO.
4869 "system"!: string
4870
4871 // volumeName is the name of a volume already created in the ScaleIO system that
4872 // is associated with this volume source.
4873 "volumeName"?: string
4874}
4875
4876// ScaleIOVolumeSource represents a persistent ScaleIO volume
4877#ScaleIOVolumeSource: {
4878 // fsType is the filesystem type to mount. Must be a filesystem type supported
4879 // by the host operating system. Ex. "ext4", "xfs", "ntfs". Default is "xfs".
4880 "fsType"?: string
4881
4882 // gateway is the host address of the ScaleIO API Gateway.
4883 "gateway"!: string
4884
4885 // protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.
4886 "protectionDomain"?: string
4887
4888 // readOnly Defaults to false (read/write). ReadOnly here will force the
4889 // ReadOnly setting in VolumeMounts.
4890 "readOnly"?: bool
4891
4892 // secretRef references to the secret for ScaleIO user and other sensitive
4893 // information. If this is not provided, Login operation will fail.
4894 "secretRef"!: #LocalObjectReference
4895
4896 // sslEnabled Flag enable/disable SSL communication with Gateway, default false
4897 "sslEnabled"?: bool
4898
4899 // storageMode indicates whether the storage for a volume should be
4900 // ThickProvisioned or ThinProvisioned. Default is ThinProvisioned.
4901 "storageMode"?: string
4902
4903 // storagePool is the ScaleIO Storage Pool associated with the protection domain.
4904 "storagePool"?: string
4905
4906 // system is the name of the storage system as configured in ScaleIO.
4907 "system"!: string
4908
4909 // volumeName is the name of a volume already created in the ScaleIO system that
4910 // is associated with this volume source.
4911 "volumeName"?: string
4912}
4913
4914// A scope selector represents the AND of the selectors represented by the
4915// scoped-resource selector requirements.
4916#ScopeSelector: {
4917 // A list of scope selector requirements by scope of the resources.
4918 "matchExpressions"?: [...#ScopedResourceSelectorRequirement]
4919}
4920
4921// A scoped-resource selector requirement is a selector that contains values, a
4922// scope name, and an operator that relates the scope name and values.
4923#ScopedResourceSelectorRequirement: {
4924 // Represents a scope's relationship to a set of values. Valid operators are In,
4925 // NotIn, Exists, DoesNotExist.
4926 "operator"!: string
4927
4928 // The name of the scope that the selector applies to.
4929 "scopeName"!: string
4930
4931 // An array of string values. If the operator is In or NotIn, the values array
4932 // must be non-empty. If the operator is Exists or DoesNotExist, the values
4933 // array must be empty. This array is replaced during a strategic merge patch.
4934 "values"?: [...string]
4935}
4936
4937// SeccompProfile defines a pod/container's seccomp profile settings. Only one
4938// profile source may be set.
4939#SeccompProfile: {
4940 // localhostProfile indicates a profile defined in a file on the node should be
4941 // used. The profile must be preconfigured on the node to work. Must be a
4942 // descending path, relative to the kubelet's configured seccomp profile
4943 // location. Must be set if type is "Localhost". Must NOT be set for any other
4944 // type.
4945 "localhostProfile"?: string
4946
4947 // type indicates which kind of seccomp profile will be applied. Valid options are:
4948 //
4949 // Localhost - a profile defined in a file on the node should be used.
4950 // RuntimeDefault - the container runtime default profile should be used.
4951 // Unconfined - no profile should be applied.
4952 "type"!: string
4953}
4954
4955// Secret holds secret data of a certain type. The total bytes of the values in
4956// the Data field must be less than MaxSecretSize bytes.
4957#Secret: {
4958 // APIVersion defines the versioned schema of this representation of an object.
4959 // Servers should convert recognized schemas to the latest internal value, and
4960 // may reject unrecognized values. More info:
4961 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4962 "apiVersion": "v1"
4963
4964 // Data contains the secret data. Each key must consist of alphanumeric
4965 // characters, '-', '_' or '.'. The serialized form of the secret data is a
4966 // base64 encoded string, representing the arbitrary (possibly non-string) data
4967 // value here. Described in https://tools.ietf.org/html/rfc4648#section-4
4968 "data"?: [string]: string
4969
4970 // Immutable, if set to true, ensures that data stored in the Secret cannot be
4971 // updated (only object metadata can be modified). If not set to true, the
4972 // field can be modified at any time. Defaulted to nil.
4973 "immutable"?: bool
4974
4975 // Kind is a string value representing the REST resource this object represents.
4976 // Servers may infer this from the endpoint the client submits requests to.
4977 // Cannot be updated. In CamelCase. More info:
4978 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4979 "kind": "Secret"
4980
4981 // Standard object's metadata. More info:
4982 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4983 "metadata"?: v1.#ObjectMeta
4984
4985 // stringData allows specifying non-binary secret data in string form. It is
4986 // provided as a write-only input field for convenience. All keys and values
4987 // are merged into the data field on write, overwriting any existing values.
4988 // The stringData field is never output when reading from the API.
4989 "stringData"?: [string]: string
4990
4991 // Used to facilitate programmatic handling of secret data. More info:
4992 // https://kubernetes.io/docs/concepts/configuration/secret/#secret-types
4993 "type"?: string
4994}
4995
4996// SecretEnvSource selects a Secret to populate the environment variables with.
4997//
4998// The contents of the target Secret's Data field will represent the key-value
4999// pairs as environment variables.
5000#SecretEnvSource: {
5001 // Name of the referent. This field is effectively required, but due to
5002 // backwards compatibility is allowed to be empty. Instances of this type with
5003 // an empty value here are almost certainly wrong. More info:
5004 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
5005 "name"?: string
5006
5007 // Specify whether the Secret must be defined
5008 "optional"?: bool
5009}
5010
5011// SecretKeySelector selects a key of a Secret.
5012#SecretKeySelector: {
5013 // The key of the secret to select from. Must be a valid secret key.
5014 "key"!: string
5015
5016 // Name of the referent. This field is effectively required, but due to
5017 // backwards compatibility is allowed to be empty. Instances of this type with
5018 // an empty value here are almost certainly wrong. More info:
5019 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
5020 "name"?: string
5021
5022 // Specify whether the Secret or its key must be defined
5023 "optional"?: bool
5024}
5025
5026// SecretList is a list of Secret.
5027#SecretList: {
5028 // APIVersion defines the versioned schema of this representation of an object.
5029 // Servers should convert recognized schemas to the latest internal value, and
5030 // may reject unrecognized values. More info:
5031 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5032 "apiVersion": "v1"
5033
5034 // Items is a list of secret objects. More info:
5035 // https://kubernetes.io/docs/concepts/configuration/secret
5036 "items"!: [...#Secret]
5037
5038 // Kind is a string value representing the REST resource this object represents.
5039 // Servers may infer this from the endpoint the client submits requests to.
5040 // Cannot be updated. In CamelCase. More info:
5041 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5042 "kind": "SecretList"
5043
5044 // Standard list metadata. More info:
5045 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5046 "metadata"?: v1.#ListMeta
5047}
5048
5049// Adapts a secret into a projected volume.
5050//
5051// The contents of the target Secret's Data field will be presented in a
5052// projected volume as files using the keys in the Data field as the file
5053// names. Note that this is identical to a secret volume source without the
5054// default mode.
5055#SecretProjection: {
5056 // items if unspecified, each key-value pair in the Data field of the referenced
5057 // Secret will be projected into the volume as a file whose name is the key and
5058 // content is the value. If specified, the listed keys will be projected into
5059 // the specified paths, and unlisted keys will not be present. If a key is
5060 // specified which is not present in the Secret, the volume setup will error
5061 // unless it is marked optional. Paths must be relative and may not contain the
5062 // '..' path or start with '..'.
5063 "items"?: [...#KeyToPath]
5064
5065 // Name of the referent. This field is effectively required, but due to
5066 // backwards compatibility is allowed to be empty. Instances of this type with
5067 // an empty value here are almost certainly wrong. More info:
5068 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
5069 "name"?: string
5070
5071 // optional field specify whether the Secret or its key must be defined
5072 "optional"?: bool
5073}
5074
5075// SecretReference represents a Secret Reference. It has enough information to
5076// retrieve secret in any namespace
5077#SecretReference: {
5078 // name is unique within a namespace to reference a secret resource.
5079 "name"?: string
5080
5081 // namespace defines the space within which the secret name must be unique.
5082 "namespace"?: string
5083}
5084
5085// Adapts a Secret into a volume.
5086//
5087// The contents of the target Secret's Data field will be presented in a volume
5088// as files using the keys in the Data field as the file names. Secret volumes
5089// support ownership management and SELinux relabeling.
5090#SecretVolumeSource: {
5091 // defaultMode is Optional: mode bits used to set permissions on created files
5092 // by default. Must be an octal value between 0000 and 0777 or a decimal value
5093 // between 0 and 511. YAML accepts both octal and decimal values, JSON requires
5094 // decimal values for mode bits. Defaults to 0644. Directories within the path
5095 // are not affected by this setting. This might be in conflict with other
5096 // options that affect the file mode, like fsGroup, and the result can be other
5097 // mode bits set.
5098 "defaultMode"?: int32 & int
5099
5100 // items If unspecified, each key-value pair in the Data field of the referenced
5101 // Secret will be projected into the volume as a file whose name is the key and
5102 // content is the value. If specified, the listed keys will be projected into
5103 // the specified paths, and unlisted keys will not be present. If a key is
5104 // specified which is not present in the Secret, the volume setup will error
5105 // unless it is marked optional. Paths must be relative and may not contain the
5106 // '..' path or start with '..'.
5107 "items"?: [...#KeyToPath]
5108
5109 // optional field specify whether the Secret or its keys must be defined
5110 "optional"?: bool
5111
5112 // secretName is the name of the secret in the pod's namespace to use. More
5113 // info: https://kubernetes.io/docs/concepts/storage/volumes#secret
5114 "secretName"?: string
5115}
5116
5117// SecurityContext holds security configuration that will be applied to a
5118// container. Some fields are present in both SecurityContext and
5119// PodSecurityContext. When both are set, the values in SecurityContext take
5120// precedence.
5121#SecurityContext: {
5122 // AllowPrivilegeEscalation controls whether a process can gain more privileges
5123 // than its parent process. This bool directly controls if the no_new_privs
5124 // flag will be set on the container process. AllowPrivilegeEscalation is true
5125 // always when the container is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note
5126 // that this field cannot be set when spec.os.name is windows.
5127 "allowPrivilegeEscalation"?: bool
5128
5129 // appArmorProfile is the AppArmor options to use by this container. If set,
5130 // this profile overrides the pod's appArmorProfile. Note that this field
5131 // cannot be set when spec.os.name is windows.
5132 "appArmorProfile"?: #AppArmorProfile
5133
5134 // The capabilities to add/drop when running containers. Defaults to the default
5135 // set of capabilities granted by the container runtime. Note that this field
5136 // cannot be set when spec.os.name is windows.
5137 "capabilities"?: #Capabilities
5138
5139 // Run container in privileged mode. Processes in privileged containers are
5140 // essentially equivalent to root on the host. Defaults to false. Note that
5141 // this field cannot be set when spec.os.name is windows.
5142 "privileged"?: bool
5143
5144 // procMount denotes the type of proc mount to use for the containers. The
5145 // default value is Default which uses the container runtime defaults for
5146 // readonly paths and masked paths. Note that this field cannot be set when
5147 // spec.os.name is windows.
5148 "procMount"?: string
5149
5150 // Whether this container has a read-only root filesystem. Default is false.
5151 // Note that this field cannot be set when spec.os.name is windows.
5152 "readOnlyRootFilesystem"?: bool
5153
5154 // The GID to run the entrypoint of the container process. Uses runtime default
5155 // if unset. May also be set in PodSecurityContext. If set in both
5156 // SecurityContext and PodSecurityContext, the value specified in
5157 // SecurityContext takes precedence. Note that this field cannot be set when
5158 // spec.os.name is windows.
5159 "runAsGroup"?: int64 & int
5160
5161 // Indicates that the container must run as a non-root user. If true, the
5162 // Kubelet will validate the image at runtime to ensure that it does not run as
5163 // UID 0 (root) and fail to start the container if it does. If unset or false,
5164 // no such validation will be performed. May also be set in PodSecurityContext.
5165 // If set in both SecurityContext and PodSecurityContext, the value specified
5166 // in SecurityContext takes precedence.
5167 "runAsNonRoot"?: bool
5168
5169 // The UID to run the entrypoint of the container process. Defaults to user
5170 // specified in image metadata if unspecified. May also be set in
5171 // PodSecurityContext. If set in both SecurityContext and PodSecurityContext,
5172 // the value specified in SecurityContext takes precedence. Note that this
5173 // field cannot be set when spec.os.name is windows.
5174 "runAsUser"?: int64 & int
5175
5176 // The SELinux context to be applied to the container. If unspecified, the
5177 // container runtime will allocate a random SELinux context for each container.
5178 // May also be set in PodSecurityContext. If set in both SecurityContext and
5179 // PodSecurityContext, the value specified in SecurityContext takes precedence.
5180 // Note that this field cannot be set when spec.os.name is windows.
5181 "seLinuxOptions"?: #SELinuxOptions
5182
5183 // The seccomp options to use by this container. If seccomp options are provided
5184 // at both the pod & container level, the container options override the pod
5185 // options. Note that this field cannot be set when spec.os.name is windows.
5186 "seccompProfile"?: #SeccompProfile
5187
5188 // The Windows specific settings applied to all containers. If unspecified, the
5189 // options from the PodSecurityContext will be used. If set in both
5190 // SecurityContext and PodSecurityContext, the value specified in
5191 // SecurityContext takes precedence. Note that this field cannot be set when
5192 // spec.os.name is linux.
5193 "windowsOptions"?: #WindowsSecurityContextOptions
5194}
5195
5196// Service is a named abstraction of software service (for example, mysql)
5197// consisting of local port (for example 3306) that the proxy listens on, and
5198// the selector that determines which pods will answer requests sent through
5199// the proxy.
5200#Service: {
5201 // APIVersion defines the versioned schema of this representation of an object.
5202 // Servers should convert recognized schemas to the latest internal value, and
5203 // may reject unrecognized values. More info:
5204 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5205 "apiVersion": "v1"
5206
5207 // Kind is a string value representing the REST resource this object represents.
5208 // Servers may infer this from the endpoint the client submits requests to.
5209 // Cannot be updated. In CamelCase. More info:
5210 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5211 "kind": "Service"
5212
5213 // Standard object's metadata. More info:
5214 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
5215 "metadata"?: v1.#ObjectMeta
5216
5217 // Spec defines the behavior of a service.
5218 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
5219 "spec"?: #ServiceSpec
5220
5221 // Most recently observed status of the service. Populated by the system.
5222 // Read-only. More info:
5223 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
5224 "status"?: #ServiceStatus
5225}
5226
5227// ServiceAccount binds together: * a name, understood by users, and perhaps by
5228// peripheral systems, for an identity * a principal that can be authenticated
5229// and authorized * a set of secrets
5230#ServiceAccount: {
5231 // APIVersion defines the versioned schema of this representation of an object.
5232 // Servers should convert recognized schemas to the latest internal value, and
5233 // may reject unrecognized values. More info:
5234 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5235 "apiVersion": "v1"
5236
5237 // AutomountServiceAccountToken indicates whether pods running as this service
5238 // account should have an API token automatically mounted. Can be overridden at
5239 // the pod level.
5240 "automountServiceAccountToken"?: bool
5241
5242 // ImagePullSecrets is a list of references to secrets in the same namespace to
5243 // use for pulling any images in pods that reference this ServiceAccount.
5244 // ImagePullSecrets are distinct from Secrets because Secrets can be mounted in
5245 // the pod, but ImagePullSecrets are only accessed by the kubelet. More info:
5246 // https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
5247 "imagePullSecrets"?: [...#LocalObjectReference]
5248
5249 // Kind is a string value representing the REST resource this object represents.
5250 // Servers may infer this from the endpoint the client submits requests to.
5251 // Cannot be updated. In CamelCase. More info:
5252 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5253 "kind": "ServiceAccount"
5254
5255 // Standard object's metadata. More info:
5256 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
5257 "metadata"?: v1.#ObjectMeta
5258
5259 // Secrets is a list of the secrets in the same namespace that pods running
5260 // using this ServiceAccount are allowed to use. Pods are only limited to this
5261 // list if this service account has a "kubernetes.io/enforce-mountable-secrets"
5262 // annotation set to "true". The "kubernetes.io/enforce-mountable-secrets"
5263 // annotation is deprecated since v1.32. Prefer separate namespaces to isolate
5264 // access to mounted secrets. This field should not be used to find
5265 // auto-generated service account token secrets for use outside of pods.
5266 // Instead, tokens can be requested directly using the TokenRequest API, or
5267 // service account token secrets can be manually created. More info:
5268 // https://kubernetes.io/docs/concepts/configuration/secret
5269 "secrets"?: [...#ObjectReference]
5270}
5271
5272// ServiceAccountList is a list of ServiceAccount objects
5273#ServiceAccountList: {
5274 // APIVersion defines the versioned schema of this representation of an object.
5275 // Servers should convert recognized schemas to the latest internal value, and
5276 // may reject unrecognized values. More info:
5277 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5278 "apiVersion": "v1"
5279
5280 // List of ServiceAccounts. More info:
5281 // https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
5282 "items"!: [...#ServiceAccount]
5283
5284 // Kind is a string value representing the REST resource this object represents.
5285 // Servers may infer this from the endpoint the client submits requests to.
5286 // Cannot be updated. In CamelCase. More info:
5287 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5288 "kind": "ServiceAccountList"
5289
5290 // Standard list metadata. More info:
5291 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5292 "metadata"?: v1.#ListMeta
5293}
5294
5295// ServiceAccountTokenProjection represents a projected service account token
5296// volume. This projection can be used to insert a service account token into
5297// the pods runtime filesystem for use against APIs (Kubernetes API Server or
5298// otherwise).
5299#ServiceAccountTokenProjection: {
5300 // audience is the intended audience of the token. A recipient of a token must
5301 // identify itself with an identifier specified in the audience of the token,
5302 // and otherwise should reject the token. The audience defaults to the
5303 // identifier of the apiserver.
5304 "audience"?: string
5305
5306 // expirationSeconds is the requested duration of validity of the service
5307 // account token. As the token approaches expiration, the kubelet volume plugin
5308 // will proactively rotate the service account token. The kubelet will start
5309 // trying to rotate the token if the token is older than 80 percent of its time
5310 // to live or if the token is older than 24 hours.Defaults to 1 hour and must
5311 // be at least 10 minutes.
5312 "expirationSeconds"?: int64 & int
5313
5314 // path is the path relative to the mount point of the file to project the token into.
5315 "path"!: string
5316}
5317
5318// ServiceList holds a list of services.
5319#ServiceList: {
5320 // APIVersion defines the versioned schema of this representation of an object.
5321 // Servers should convert recognized schemas to the latest internal value, and
5322 // may reject unrecognized values. More info:
5323 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5324 "apiVersion": "v1"
5325
5326 // List of services
5327 "items"!: [...#Service]
5328
5329 // Kind is a string value representing the REST resource this object represents.
5330 // Servers may infer this from the endpoint the client submits requests to.
5331 // Cannot be updated. In CamelCase. More info:
5332 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5333 "kind": "ServiceList"
5334
5335 // Standard list metadata. More info:
5336 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5337 "metadata"?: v1.#ListMeta
5338}
5339
5340// ServicePort contains information on service's port.
5341#ServicePort: {
5342 // The application protocol for this port. This is used as a hint for
5343 // implementations to offer richer behavior for protocols that they understand.
5344 // This field follows standard Kubernetes label syntax. Valid values are
5345 // either:
5346 //
5347 // * Un-prefixed protocol names - reserved for IANA standard service names (as
5348 // per RFC-6335 and https://www.iana.org/assignments/service-names).
5349 //
5350 // * Kubernetes-defined prefixed names:
5351 // * 'kubernetes.io/h2c' - HTTP/2 prior knowledge over cleartext as described in
5352 // https://www.rfc-editor.org/rfc/rfc9113.html#name-starting-http-2-with-prior-
5353 // * 'kubernetes.io/ws' - WebSocket over cleartext as described in
5354 // https://www.rfc-editor.org/rfc/rfc6455
5355 // * 'kubernetes.io/wss' - WebSocket over TLS as described in https://www.rfc-editor.org/rfc/rfc6455
5356 //
5357 // * Other protocols should use implementation-defined prefixed names such as
5358 // mycompany.com/my-custom-protocol.
5359 "appProtocol"?: string
5360
5361 // The name of this port within the service. This must be a DNS_LABEL. All ports
5362 // within a ServiceSpec must have unique names. When considering the endpoints
5363 // for a Service, this must match the 'name' field in the EndpointPort.
5364 // Optional if only one ServicePort is defined on this service.
5365 "name"?: string
5366
5367 // The port on each node on which this service is exposed when type is NodePort
5368 // or LoadBalancer. Usually assigned by the system. If a value is specified,
5369 // in-range, and not in use it will be used, otherwise the operation will fail.
5370 // If not specified, a port will be allocated if this Service requires one. If
5371 // this field is specified when creating a Service which does not need it,
5372 // creation will fail. This field will be wiped when updating a Service to no
5373 // longer need it (e.g. changing type from NodePort to ClusterIP). More info:
5374 // https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
5375 "nodePort"?: int32 & int
5376
5377 // The port that will be exposed by this service.
5378 "port"!: int32 & int
5379
5380 // The IP protocol for this port. Supports "TCP", "UDP", and "SCTP". Default is TCP.
5381 "protocol"?: string
5382
5383 // Number or name of the port to access on the pods targeted by the service.
5384 // Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. If
5385 // this is a string, it will be looked up as a named port in the target Pod's
5386 // container ports. If this is not specified, the value of the 'port' field is
5387 // used (an identity map). This field is ignored for services with
5388 // clusterIP=None, and should be omitted or set equal to the 'port' field. More
5389 // info:
5390 // https://kubernetes.io/docs/concepts/services-networking/service/#defining-a-service
5391 "targetPort"?: intstr.#IntOrString
5392}
5393
5394// ServiceSpec describes the attributes that a user creates on a service.
5395#ServiceSpec: {
5396 // allocateLoadBalancerNodePorts defines if NodePorts will be automatically
5397 // allocated for services with type LoadBalancer. Default is "true". It may be
5398 // set to "false" if the cluster load-balancer does not rely on NodePorts. If
5399 // the caller requests specific NodePorts (by specifying a value), those
5400 // requests will be respected, regardless of this field. This field may only be
5401 // set for services with type LoadBalancer and will be cleared if the type is
5402 // changed to any other type.
5403 "allocateLoadBalancerNodePorts"?: bool
5404
5405 // clusterIP is the IP address of the service and is usually assigned randomly.
5406 // If an address is specified manually, is in-range (as per system
5407 // configuration), and is not in use, it will be allocated to the service;
5408 // otherwise creation of the service will fail. This field may not be changed
5409 // through updates unless the type field is also being changed to ExternalName
5410 // (which requires this field to be blank) or the type field is being changed
5411 // from ExternalName (in which case this field may optionally be specified, as
5412 // describe above). Valid values are "None", empty string (""), or a valid IP
5413 // address. Setting this to "None" makes a "headless service" (no virtual IP),
5414 // which is useful when direct endpoint connections are preferred and proxying
5415 // is not required. Only applies to types ClusterIP, NodePort, and
5416 // LoadBalancer. If this field is specified when creating a Service of type
5417 // ExternalName, creation will fail. This field will be wiped when updating a
5418 // Service to type ExternalName. More info:
5419 // https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5420 "clusterIP"?: string
5421
5422 // ClusterIPs is a list of IP addresses assigned to this service, and are
5423 // usually assigned randomly. If an address is specified manually, is in-range
5424 // (as per system configuration), and is not in use, it will be allocated to
5425 // the service; otherwise creation of the service will fail. This field may not
5426 // be changed through updates unless the type field is also being changed to
5427 // ExternalName (which requires this field to be empty) or the type field is
5428 // being changed from ExternalName (in which case this field may optionally be
5429 // specified, as describe above). Valid values are "None", empty string (""),
5430 // or a valid IP address. Setting this to "None" makes a "headless service" (no
5431 // virtual IP), which is useful when direct endpoint connections are preferred
5432 // and proxying is not required. Only applies to types ClusterIP, NodePort, and
5433 // LoadBalancer. If this field is specified when creating a Service of type
5434 // ExternalName, creation will fail. This field will be wiped when updating a
5435 // Service to type ExternalName. If this field is not specified, it will be
5436 // initialized from the clusterIP field. If this field is specified, clients
5437 // must ensure that clusterIPs[0] and clusterIP have the same value.
5438 //
5439 // This field may hold a maximum of two entries (dual-stack IPs, in either
5440 // order). These IPs must correspond to the values of the ipFamilies field.
5441 // Both clusterIPs and ipFamilies are governed by the ipFamilyPolicy field.
5442 // More info:
5443 // https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5444 "clusterIPs"?: [...string]
5445
5446 // externalIPs is a list of IP addresses for which nodes in the cluster will
5447 // also accept traffic for this service. These IPs are not managed by
5448 // Kubernetes. The user is responsible for ensuring that traffic arrives at a
5449 // node with this IP. A common example is external load-balancers that are not
5450 // part of the Kubernetes system.
5451 "externalIPs"?: [...string]
5452
5453 // externalName is the external reference that discovery mechanisms will return
5454 // as an alias for this service (e.g. a DNS CNAME record). No proxying will be
5455 // involved. Must be a lowercase RFC-1123 hostname
5456 // (https://tools.ietf.org/html/rfc1123) and requires `type` to be
5457 // "ExternalName".
5458 "externalName"?: string
5459
5460 // externalTrafficPolicy describes how nodes distribute service traffic they
5461 // receive on one of the Service's "externally-facing" addresses (NodePorts,
5462 // ExternalIPs, and LoadBalancer IPs). If set to "Local", the proxy will
5463 // configure the service in a way that assumes that external load balancers
5464 // will take care of balancing the service traffic between nodes, and so each
5465 // node will deliver traffic only to the node-local endpoints of the service,
5466 // without masquerading the client source IP. (Traffic mistakenly sent to a
5467 // node with no endpoints will be dropped.) The default value, "Cluster", uses
5468 // the standard behavior of routing to all endpoints evenly (possibly modified
5469 // by topology and other features). Note that traffic sent to an External IP or
5470 // LoadBalancer IP from within the cluster will always get "Cluster" semantics,
5471 // but clients sending to a NodePort from within the cluster may need to take
5472 // traffic policy into account when picking a node.
5473 "externalTrafficPolicy"?: string
5474
5475 // healthCheckNodePort specifies the healthcheck nodePort for the service. This
5476 // only applies when type is set to LoadBalancer and externalTrafficPolicy is
5477 // set to Local. If a value is specified, is in-range, and is not in use, it
5478 // will be used. If not specified, a value will be automatically allocated.
5479 // External systems (e.g. load-balancers) can use this port to determine if a
5480 // given node holds endpoints for this service or not. If this field is
5481 // specified when creating a Service which does not need it, creation will
5482 // fail. This field will be wiped when updating a Service to no longer need it
5483 // (e.g. changing type). This field cannot be updated once set.
5484 "healthCheckNodePort"?: int32 & int
5485
5486 // InternalTrafficPolicy describes how nodes distribute service traffic they
5487 // receive on the ClusterIP. If set to "Local", the proxy will assume that pods
5488 // only want to talk to endpoints of the service on the same node as the pod,
5489 // dropping the traffic if there are no local endpoints. The default value,
5490 // "Cluster", uses the standard behavior of routing to all endpoints evenly
5491 // (possibly modified by topology and other features).
5492 "internalTrafficPolicy"?: string
5493
5494 // IPFamilies is a list of IP families (e.g. IPv4, IPv6) assigned to this
5495 // service. This field is usually assigned automatically based on cluster
5496 // configuration and the ipFamilyPolicy field. If this field is specified
5497 // manually, the requested family is available in the cluster, and
5498 // ipFamilyPolicy allows it, it will be used; otherwise creation of the service
5499 // will fail. This field is conditionally mutable: it allows for adding or
5500 // removing a secondary IP family, but it does not allow changing the primary
5501 // IP family of the Service. Valid values are "IPv4" and "IPv6". This field
5502 // only applies to Services of types ClusterIP, NodePort, and LoadBalancer, and
5503 // does apply to "headless" services. This field will be wiped when updating a
5504 // Service to type ExternalName.
5505 //
5506 // This field may hold a maximum of two entries (dual-stack families, in either
5507 // order). These families must correspond to the values of the clusterIPs
5508 // field, if specified. Both clusterIPs and ipFamilies are governed by the
5509 // ipFamilyPolicy field.
5510 "ipFamilies"?: [...string]
5511
5512 // IPFamilyPolicy represents the dual-stack-ness requested or required by this
5513 // Service. If there is no value provided, then this field will be set to
5514 // SingleStack. Services can be "SingleStack" (a single IP family),
5515 // "PreferDualStack" (two IP families on dual-stack configured clusters or a
5516 // single IP family on single-stack clusters), or "RequireDualStack" (two IP
5517 // families on dual-stack configured clusters, otherwise fail). The ipFamilies
5518 // and clusterIPs fields depend on the value of this field. This field will be
5519 // wiped when updating a service to type ExternalName.
5520 "ipFamilyPolicy"?: string
5521
5522 // loadBalancerClass is the class of the load balancer implementation this
5523 // Service belongs to. If specified, the value of this field must be a
5524 // label-style identifier, with an optional prefix, e.g. "internal-vip" or
5525 // "example.com/internal-vip". Unprefixed names are reserved for end-users.
5526 // This field can only be set when the Service type is 'LoadBalancer'. If not
5527 // set, the default load balancer implementation is used, today this is
5528 // typically done through the cloud provider integration, but should apply for
5529 // any default implementation. If set, it is assumed that a load balancer
5530 // implementation is watching for Services with a matching class. Any default
5531 // load balancer implementation (e.g. cloud providers) should ignore Services
5532 // that set this field. This field can only be set when creating or updating a
5533 // Service to type 'LoadBalancer'. Once set, it can not be changed. This field
5534 // will be wiped when a service is updated to a non 'LoadBalancer' type.
5535 "loadBalancerClass"?: string
5536
5537 // Only applies to Service Type: LoadBalancer. This feature depends on whether
5538 // the underlying cloud-provider supports specifying the loadBalancerIP when a
5539 // load balancer is created. This field will be ignored if the cloud-provider
5540 // does not support the feature. Deprecated: This field was under-specified and
5541 // its meaning varies across implementations. Using it is non-portable and it
5542 // may not support dual-stack. Users are encouraged to use
5543 // implementation-specific annotations when available.
5544 "loadBalancerIP"?: string
5545
5546 // If specified and supported by the platform, this will restrict traffic
5547 // through the cloud-provider load-balancer will be restricted to the specified
5548 // client IPs. This field will be ignored if the cloud-provider does not
5549 // support the feature." More info:
5550 // https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/
5551 "loadBalancerSourceRanges"?: [...string]
5552
5553 // The list of ports that are exposed by this service. More info:
5554 // https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5555 "ports"?: [...#ServicePort]
5556
5557 // publishNotReadyAddresses indicates that any agent which deals with endpoints
5558 // for this Service should disregard any indications of ready/not-ready. The
5559 // primary use case for setting this field is for a StatefulSet's Headless
5560 // Service to propagate SRV DNS records for its Pods for the purpose of peer
5561 // discovery. The Kubernetes controllers that generate Endpoints and
5562 // EndpointSlice resources for Services interpret this to mean that all
5563 // endpoints are considered "ready" even if the Pods themselves are not. Agents
5564 // which consume only Kubernetes generated endpoints through the Endpoints or
5565 // EndpointSlice resources can safely assume this behavior.
5566 "publishNotReadyAddresses"?: bool
5567
5568 // Route service traffic to pods with label keys and values matching this
5569 // selector. If empty or not present, the service is assumed to have an
5570 // external process managing its endpoints, which Kubernetes will not modify.
5571 // Only applies to types ClusterIP, NodePort, and LoadBalancer. Ignored if type
5572 // is ExternalName. More info:
5573 // https://kubernetes.io/docs/concepts/services-networking/service/
5574 "selector"?: [string]: string
5575
5576 // Supports "ClientIP" and "None". Used to maintain session affinity. Enable
5577 // client IP based session affinity. Must be ClientIP or None. Defaults to
5578 // None. More info:
5579 // https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5580 "sessionAffinity"?: string
5581
5582 // sessionAffinityConfig contains the configurations of session affinity.
5583 "sessionAffinityConfig"?: #SessionAffinityConfig
5584
5585 // TrafficDistribution offers a way to express preferences for how traffic is
5586 // distributed to Service endpoints. Implementations can use this field as a
5587 // hint, but are not required to guarantee strict adherence. If the field is
5588 // not set, the implementation will apply its default routing strategy. If set
5589 // to "PreferClose", implementations should prioritize endpoints that are in
5590 // the same zone.
5591 "trafficDistribution"?: string
5592
5593 // type determines how the Service is exposed. Defaults to ClusterIP. Valid
5594 // options are ExternalName, ClusterIP, NodePort, and LoadBalancer. "ClusterIP"
5595 // allocates a cluster-internal IP address for load-balancing to endpoints.
5596 // Endpoints are determined by the selector or if that is not specified, by
5597 // manual construction of an Endpoints object or EndpointSlice objects. If
5598 // clusterIP is "None", no virtual IP is allocated and the endpoints are
5599 // published as a set of endpoints rather than a virtual IP. "NodePort" builds
5600 // on ClusterIP and allocates a port on every node which routes to the same
5601 // endpoints as the clusterIP. "LoadBalancer" builds on NodePort and creates an
5602 // external load-balancer (if supported in the current cloud) which routes to
5603 // the same endpoints as the clusterIP. "ExternalName" aliases this service to
5604 // the specified externalName. Several other fields do not apply to
5605 // ExternalName services. More info:
5606 // https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types
5607 "type"?: string
5608}
5609
5610// ServiceStatus represents the current status of a service.
5611#ServiceStatus: {
5612 // Current service state
5613 "conditions"?: [...v1.#Condition]
5614
5615 // LoadBalancer contains the current status of the load-balancer, if one is present.
5616 "loadBalancer"?: #LoadBalancerStatus
5617}
5618
5619// SessionAffinityConfig represents the configurations of session affinity.
5620#SessionAffinityConfig: {
5621 // clientIP contains the configurations of Client IP based session affinity.
5622 "clientIP"?: #ClientIPConfig
5623}
5624
5625// SleepAction describes a "sleep" action.
5626#SleepAction: {
5627 // Seconds is the number of seconds to sleep.
5628 "seconds"!: int64 & int
5629}
5630
5631// Represents a StorageOS persistent volume resource.
5632#StorageOSPersistentVolumeSource: {
5633 // fsType is the filesystem type to mount. Must be a filesystem type supported
5634 // by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
5635 // to be "ext4" if unspecified.
5636 "fsType"?: string
5637
5638 // readOnly defaults to false (read/write). ReadOnly here will force the
5639 // ReadOnly setting in VolumeMounts.
5640 "readOnly"?: bool
5641
5642 // secretRef specifies the secret to use for obtaining the StorageOS API
5643 // credentials. If not specified, default values will be attempted.
5644 "secretRef"?: #ObjectReference
5645
5646 // volumeName is the human-readable name of the StorageOS volume. Volume names
5647 // are only unique within a namespace.
5648 "volumeName"?: string
5649
5650 // volumeNamespace specifies the scope of the volume within StorageOS. If no
5651 // namespace is specified then the Pod's namespace will be used. This allows
5652 // the Kubernetes name scoping to be mirrored within StorageOS for tighter
5653 // integration. Set VolumeName to any name to override the default behaviour.
5654 // Set to "default" if you are not using namespaces within StorageOS.
5655 // Namespaces that do not pre-exist within StorageOS will be created.
5656 "volumeNamespace"?: string
5657}
5658
5659// Represents a StorageOS persistent volume resource.
5660#StorageOSVolumeSource: {
5661 // fsType is the filesystem type to mount. Must be a filesystem type supported
5662 // by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
5663 // to be "ext4" if unspecified.
5664 "fsType"?: string
5665
5666 // readOnly defaults to false (read/write). ReadOnly here will force the
5667 // ReadOnly setting in VolumeMounts.
5668 "readOnly"?: bool
5669
5670 // secretRef specifies the secret to use for obtaining the StorageOS API
5671 // credentials. If not specified, default values will be attempted.
5672 "secretRef"?: #LocalObjectReference
5673
5674 // volumeName is the human-readable name of the StorageOS volume. Volume names
5675 // are only unique within a namespace.
5676 "volumeName"?: string
5677
5678 // volumeNamespace specifies the scope of the volume within StorageOS. If no
5679 // namespace is specified then the Pod's namespace will be used. This allows
5680 // the Kubernetes name scoping to be mirrored within StorageOS for tighter
5681 // integration. Set VolumeName to any name to override the default behaviour.
5682 // Set to "default" if you are not using namespaces within StorageOS.
5683 // Namespaces that do not pre-exist within StorageOS will be created.
5684 "volumeNamespace"?: string
5685}
5686
5687// Sysctl defines a kernel parameter to be set
5688#Sysctl: {
5689 // Name of a property to set
5690 "name"!: string
5691
5692 // Value of a property to set
5693 "value"!: string
5694}
5695
5696// TCPSocketAction describes an action based on opening a socket
5697#TCPSocketAction: {
5698 // Optional: Host name to connect to, defaults to the pod IP.
5699 "host"?: string
5700
5701 // Number or name of the port to access on the container. Number must be in the
5702 // range 1 to 65535. Name must be an IANA_SVC_NAME.
5703 "port"!: intstr.#IntOrString
5704}
5705
5706// The node this Taint is attached to has the "effect" on any pod that does not tolerate the Taint.
5707#Taint: {
5708 // Required. The effect of the taint on pods that do not tolerate the taint.
5709 // Valid effects are NoSchedule, PreferNoSchedule and NoExecute.
5710 "effect"!: string
5711
5712 // Required. The taint key to be applied to a node.
5713 "key"!: string
5714
5715 // TimeAdded represents the time at which the taint was added.
5716 "timeAdded"?: v1.#Time
5717
5718 // The taint value corresponding to the taint key.
5719 "value"?: string
5720}
5721
5722// The pod this Toleration is attached to tolerates any taint that matches the
5723// triple <key,value,effect> using the matching operator <operator>.
5724#Toleration: {
5725 // Effect indicates the taint effect to match. Empty means match all taint
5726 // effects. When specified, allowed values are NoSchedule, PreferNoSchedule and
5727 // NoExecute.
5728 "effect"?: string
5729
5730 // Key is the taint key that the toleration applies to. Empty means match all
5731 // taint keys. If the key is empty, operator must be Exists; this combination
5732 // means to match all values and all keys.
5733 "key"?: string
5734
5735 // Operator represents a key's relationship to the value. Valid operators are
5736 // Exists, Equal, Lt, and Gt. Defaults to Equal. Exists is equivalent to
5737 // wildcard for value, so that a pod can tolerate all taints of a particular
5738 // category. Lt and Gt perform numeric comparisons (requires feature gate
5739 // TaintTolerationComparisonOperators).
5740 "operator"?: string
5741
5742 // TolerationSeconds represents the period of time the toleration (which must be
5743 // of effect NoExecute, otherwise this field is ignored) tolerates the taint.
5744 // By default, it is not set, which means tolerate the taint forever (do not
5745 // evict). Zero and negative values will be treated as 0 (evict immediately) by
5746 // the system.
5747 "tolerationSeconds"?: int64 & int
5748
5749 // Value is the taint value the toleration matches to. If the operator is
5750 // Exists, the value should be empty, otherwise just a regular string.
5751 "value"?: string
5752}
5753
5754// A topology selector requirement is a selector that matches given label. This
5755// is an alpha feature and may change in the future.
5756#TopologySelectorLabelRequirement: {
5757 // The label key that the selector applies to.
5758 "key"!: string
5759
5760 // An array of string values. One value must match the label to be selected.
5761 // Each entry in Values is ORed.
5762 "values"!: [...string]
5763}
5764
5765// A topology selector term represents the result of label queries. A null or
5766// empty topology selector term matches no objects. The requirements of them
5767// are ANDed. It provides a subset of functionality as NodeSelectorTerm. This
5768// is an alpha feature and may change in the future.
5769#TopologySelectorTerm: {
5770 // A list of topology selector requirements by labels.
5771 "matchLabelExpressions"?: [...#TopologySelectorLabelRequirement]
5772}
5773
5774// TopologySpreadConstraint specifies how to spread matching pods among the given topology.
5775#TopologySpreadConstraint: {
5776 // LabelSelector is used to find matching pods. Pods that match this label
5777 // selector are counted to determine the number of pods in their corresponding
5778 // topology domain.
5779 "labelSelector"?: v1.#LabelSelector
5780
5781 // MatchLabelKeys is a set of pod label keys to select the pods over which
5782 // spreading will be calculated. The keys are used to lookup values from the
5783 // incoming pod labels, those key-value labels are ANDed with labelSelector to
5784 // select the group of existing pods over which spreading will be calculated
5785 // for the incoming pod. The same key is forbidden to exist in both
5786 // MatchLabelKeys and LabelSelector. MatchLabelKeys cannot be set when
5787 // LabelSelector isn't set. Keys that don't exist in the incoming pod labels
5788 // will be ignored. A null or empty list means only match against
5789 // labelSelector.
5790 //
5791 // This is a beta field and requires the MatchLabelKeysInPodTopologySpread
5792 // feature gate to be enabled (enabled by default).
5793 "matchLabelKeys"?: [...string]
5794
5795 // MaxSkew describes the degree to which pods may be unevenly distributed. When
5796 // `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference
5797 // between the number of matching pods in the target topology and the global
5798 // minimum. The global minimum is the minimum number of matching pods in an
5799 // eligible domain or zero if the number of eligible domains is less than
5800 // MinDomains. For example, in a 3-zone cluster, MaxSkew is set to 1, and pods
5801 // with the same labelSelector spread as 2/2/1: In this case, the global
5802 // minimum is 1. | zone1 | zone2 | zone3 | | P P | P P | P | - if MaxSkew is 1,
5803 // incoming pod can only be scheduled to zone3 to become 2/2/2; scheduling it
5804 // onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2) violate
5805 // MaxSkew(1). - if MaxSkew is 2, incoming pod can be scheduled onto any zone.
5806 // When `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher
5807 // precedence to topologies that satisfy it. It's a required field. Default
5808 // value is 1 and 0 is not allowed.
5809 "maxSkew"!: int32 & int
5810
5811 // MinDomains indicates a minimum number of eligible domains. When the number of
5812 // eligible domains with matching topology keys is less than minDomains, Pod
5813 // Topology Spread treats "global minimum" as 0, and then the calculation of
5814 // Skew is performed. And when the number of eligible domains with matching
5815 // topology keys equals or greater than minDomains, this value has no effect on
5816 // scheduling. As a result, when the number of eligible domains is less than
5817 // minDomains, scheduler won't schedule more than maxSkew Pods to those
5818 // domains. If value is nil, the constraint behaves as if MinDomains is equal
5819 // to 1. Valid values are integers greater than 0. When value is not nil,
5820 // WhenUnsatisfiable must be DoNotSchedule.
5821 //
5822 // For example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5
5823 // and pods with the same labelSelector spread as 2/2/2: | zone1 | zone2 |
5824 // zone3 | | P P | P P | P P | The number of domains is less than
5825 // 5(MinDomains), so "global minimum" is treated as 0. In this situation, new
5826 // pod with the same labelSelector cannot be scheduled, because computed skew
5827 // will be 3(3 - 0) if new Pod is scheduled to any of the three zones, it will
5828 // violate MaxSkew.
5829 "minDomains"?: int32 & int
5830
5831 // NodeAffinityPolicy indicates how we will treat Pod's
5832 // nodeAffinity/nodeSelector when calculating pod topology spread skew. Options
5833 // are: - Honor: only nodes matching nodeAffinity/nodeSelector are included in
5834 // the calculations. - Ignore: nodeAffinity/nodeSelector are ignored. All nodes
5835 // are included in the calculations.
5836 //
5837 // If this value is nil, the behavior is equivalent to the Honor policy.
5838 "nodeAffinityPolicy"?: string
5839
5840 // NodeTaintsPolicy indicates how we will treat node taints when calculating pod
5841 // topology spread skew. Options are: - Honor: nodes without taints, along with
5842 // tainted nodes for which the incoming pod has a toleration, are included. -
5843 // Ignore: node taints are ignored. All nodes are included.
5844 //
5845 // If this value is nil, the behavior is equivalent to the Ignore policy.
5846 "nodeTaintsPolicy"?: string
5847
5848 // TopologyKey is the key of node labels. Nodes that have a label with this key
5849 // and identical values are considered to be in the same topology. We consider
5850 // each <key, value> as a "bucket", and try to put balanced number of pods into
5851 // each bucket. We define a domain as a particular instance of a topology.
5852 // Also, we define an eligible domain as a domain whose nodes meet the
5853 // requirements of nodeAffinityPolicy and nodeTaintsPolicy. e.g. If TopologyKey
5854 // is "kubernetes.io/hostname", each Node is a domain of that topology. And, if
5855 // TopologyKey is "topology.kubernetes.io/zone", each zone is a domain of that
5856 // topology. It's a required field.
5857 "topologyKey"!: string
5858
5859 // WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy the
5860 // spread constraint. - DoNotSchedule (default) tells the scheduler not to
5861 // schedule it. - ScheduleAnyway tells the scheduler to schedule the pod in any
5862 // location,
5863 // but giving higher precedence to topologies that would help reduce the
5864 // skew.
5865 // A constraint is considered "Unsatisfiable" for an incoming pod if and only if
5866 // every possible node assignment for that pod would violate "MaxSkew" on some
5867 // topology. For example, in a 3-zone cluster, MaxSkew is set to 1, and pods
5868 // with the same labelSelector spread as 3/1/1: | zone1 | zone2 | zone3 | | P P
5869 // P | P | P | If WhenUnsatisfiable is set to DoNotSchedule, incoming pod can
5870 // only be scheduled to zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1)
5871 // on zone2(zone3) satisfies MaxSkew(1). In other words, the cluster can still
5872 // be imbalanced, but scheduler won't make it *more* imbalanced. It's a
5873 // required field.
5874 "whenUnsatisfiable"!: string
5875}
5876
5877// TypedLocalObjectReference contains enough information to let you locate the
5878// typed referenced object inside the same namespace.
5879#TypedLocalObjectReference: {
5880 // APIGroup is the group for the resource being referenced. If APIGroup is not
5881 // specified, the specified Kind must be in the core API group. For any other
5882 // third-party types, APIGroup is required.
5883 "apiGroup"?: string
5884
5885 // Kind is the type of resource being referenced
5886 "kind"!: string
5887
5888 // Name is the name of resource being referenced
5889 "name"!: string
5890}
5891
5892// TypedObjectReference contains enough information to let you locate the typed referenced object
5893#TypedObjectReference: {
5894 // APIGroup is the group for the resource being referenced. If APIGroup is not
5895 // specified, the specified Kind must be in the core API group. For any other
5896 // third-party types, APIGroup is required.
5897 "apiGroup"?: string
5898
5899 // Kind is the type of resource being referenced
5900 "kind"!: string
5901
5902 // Name is the name of resource being referenced
5903 "name"!: string
5904
5905 // Namespace is the namespace of resource being referenced Note that when a
5906 // namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is
5907 // required in the referent namespace to allow that namespace's owner to accept
5908 // the reference. See the ReferenceGrant documentation for details. (Alpha)
5909 // This field requires the CrossNamespaceVolumeDataSource feature gate to be
5910 // enabled.
5911 "namespace"?: string
5912}
5913
5914// Volume represents a named volume in a pod that may be accessed by any container in the pod.
5915#Volume: {
5916 // awsElasticBlockStore represents an AWS Disk resource that is attached to a
5917 // kubelet's host machine and then exposed to the pod. Deprecated:
5918 // AWSElasticBlockStore is deprecated. All operations for the in-tree
5919 // awsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.
5920 // More info:
5921 // https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
5922 "awsElasticBlockStore"?: #AWSElasticBlockStoreVolumeSource
5923
5924 // azureDisk represents an Azure Data Disk mount on the host and bind mount to
5925 // the pod. Deprecated: AzureDisk is deprecated. All operations for the in-tree
5926 // azureDisk type are redirected to the disk.csi.azure.com CSI driver.
5927 "azureDisk"?: #AzureDiskVolumeSource
5928
5929 // azureFile represents an Azure File Service mount on the host and bind mount
5930 // to the pod. Deprecated: AzureFile is deprecated. All operations for the
5931 // in-tree azureFile type are redirected to the file.csi.azure.com CSI driver.
5932 "azureFile"?: #AzureFileVolumeSource
5933
5934 // cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
5935 // Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer
5936 // supported.
5937 "cephfs"?: #CephFSVolumeSource
5938
5939 // cinder represents a cinder volume attached and mounted on kubelets host
5940 // machine. Deprecated: Cinder is deprecated. All operations for the in-tree
5941 // cinder type are redirected to the cinder.csi.openstack.org CSI driver. More
5942 // info: https://examples.k8s.io/mysql-cinder-pd/README.md
5943 "cinder"?: #CinderVolumeSource
5944
5945 // configMap represents a configMap that should populate this volume
5946 "configMap"?: #ConfigMapVolumeSource
5947
5948 // csi (Container Storage Interface) represents ephemeral storage that is
5949 // handled by certain external CSI drivers.
5950 "csi"?: #CSIVolumeSource
5951
5952 // downwardAPI represents downward API about the pod that should populate this volume
5953 "downwardAPI"?: #DownwardAPIVolumeSource
5954
5955 // emptyDir represents a temporary directory that shares a pod's lifetime. More
5956 // info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir
5957 "emptyDir"?: #EmptyDirVolumeSource
5958
5959 // ephemeral represents a volume that is handled by a cluster storage driver.
5960 // The volume's lifecycle is tied to the pod that defines it - it will be
5961 // created before the pod starts, and deleted when the pod is removed.
5962 //
5963 // Use this if: a) the volume is only needed while the pod runs, b) features of
5964 // normal volumes like restoring from snapshot or capacity
5965 // tracking are needed,
5966 // c) the storage driver is specified through a storage class, and d) the
5967 // storage driver supports dynamic volume provisioning through
5968 // a PersistentVolumeClaim (see EphemeralVolumeSource for more
5969 // information on the connection between this volume type
5970 // and PersistentVolumeClaim).
5971 //
5972 // Use PersistentVolumeClaim or one of the vendor-specific APIs for volumes that
5973 // persist for longer than the lifecycle of an individual pod.
5974 //
5975 // Use CSI for light-weight local ephemeral volumes if the CSI driver is meant
5976 // to be used that way - see the documentation of the driver for more
5977 // information.
5978 //
5979 // A pod can use both types of ephemeral volumes and persistent volumes at the same time.
5980 "ephemeral"?: #EphemeralVolumeSource
5981
5982 // fc represents a Fibre Channel resource that is attached to a kubelet's host
5983 // machine and then exposed to the pod.
5984 "fc"?: #FCVolumeSource
5985
5986 // flexVolume represents a generic volume resource that is provisioned/attached
5987 // using an exec based plugin. Deprecated: FlexVolume is deprecated. Consider
5988 // using a CSIDriver instead.
5989 "flexVolume"?: #FlexVolumeSource
5990
5991 // flocker represents a Flocker volume attached to a kubelet's host machine.
5992 // This depends on the Flocker control service being running. Deprecated:
5993 // Flocker is deprecated and the in-tree flocker type is no longer supported.
5994 "flocker"?: #FlockerVolumeSource
5995
5996 // gcePersistentDisk represents a GCE Disk resource that is attached to a
5997 // kubelet's host machine and then exposed to the pod. Deprecated:
5998 // GCEPersistentDisk is deprecated. All operations for the in-tree
5999 // gcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI
6000 // driver. More info:
6001 // https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
6002 "gcePersistentDisk"?: #GCEPersistentDiskVolumeSource
6003
6004 // gitRepo represents a git repository at a particular revision. Deprecated:
6005 // GitRepo is deprecated. To provision a container with a git repo, mount an
6006 // EmptyDir into an InitContainer that clones the repo using git, then mount
6007 // the EmptyDir into the Pod's container.
6008 "gitRepo"?: #GitRepoVolumeSource
6009
6010 // glusterfs represents a Glusterfs mount on the host that shares a pod's
6011 // lifetime. Deprecated: Glusterfs is deprecated and the in-tree glusterfs type
6012 // is no longer supported.
6013 "glusterfs"?: #GlusterfsVolumeSource
6014
6015 // hostPath represents a pre-existing file or directory on the host machine that
6016 // is directly exposed to the container. This is generally used for system
6017 // agents or other privileged things that are allowed to see the host machine.
6018 // Most containers will NOT need this. More info:
6019 // https://kubernetes.io/docs/concepts/storage/volumes#hostpath
6020 "hostPath"?: #HostPathVolumeSource
6021
6022 // image represents an OCI object (a container image or artifact) pulled and
6023 // mounted on the kubelet's host machine. The volume is resolved at pod startup
6024 // depending on which PullPolicy value is provided:
6025 //
6026 // - Always: the kubelet always attempts to pull the reference. Container
6027 // creation will fail If the pull fails. - Never: the kubelet never pulls the
6028 // reference and only uses a local image or artifact. Container creation will
6029 // fail if the reference isn't present. - IfNotPresent: the kubelet pulls if
6030 // the reference isn't already present on disk. Container creation will fail if
6031 // the reference isn't present and the pull fails.
6032 //
6033 // The volume gets re-resolved if the pod gets deleted and recreated, which
6034 // means that new remote content will become available on pod recreation. A
6035 // failure to resolve or pull the image during pod startup will block
6036 // containers from starting and may add significant latency. Failures will be
6037 // retried using normal volume backoff and will be reported on the pod reason
6038 // and message. The types of objects that may be mounted by this volume are
6039 // defined by the container runtime implementation on a host machine and at
6040 // minimum must include all valid types supported by the container image field.
6041 // The OCI object gets mounted in a single directory
6042 // (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers
6043 // in the same way as for container images. The volume will be mounted
6044 // read-only (ro). Sub path mounts for containers are not supported
6045 // (spec.containers[*].volumeMounts.subpath) before 1.33. The field
6046 // spec.securityContext.fsGroupChangePolicy has no effect on this volume type.
6047 "image"?: #ImageVolumeSource
6048
6049 // iscsi represents an ISCSI Disk resource that is attached to a kubelet's host
6050 // machine and then exposed to the pod. More info:
6051 // https://kubernetes.io/docs/concepts/storage/volumes/#iscsi
6052 "iscsi"?: #ISCSIVolumeSource
6053
6054 // name of the volume. Must be a DNS_LABEL and unique within the pod. More info:
6055 // https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
6056 "name"!: string
6057
6058 // nfs represents an NFS mount on the host that shares a pod's lifetime More
6059 // info: https://kubernetes.io/docs/concepts/storage/volumes#nfs
6060 "nfs"?: #NFSVolumeSource
6061
6062 // persistentVolumeClaimVolumeSource represents a reference to a
6063 // PersistentVolumeClaim in the same namespace. More info:
6064 // https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
6065 "persistentVolumeClaim"?: #PersistentVolumeClaimVolumeSource
6066
6067 // photonPersistentDisk represents a PhotonController persistent disk attached
6068 // and mounted on kubelets host machine. Deprecated: PhotonPersistentDisk is
6069 // deprecated and the in-tree photonPersistentDisk type is no longer supported.
6070 "photonPersistentDisk"?: #PhotonPersistentDiskVolumeSource
6071
6072 // portworxVolume represents a portworx volume attached and mounted on kubelets
6073 // host machine. Deprecated: PortworxVolume is deprecated. All operations for
6074 // the in-tree portworxVolume type are redirected to the pxd.portworx.com CSI
6075 // driver.
6076 "portworxVolume"?: #PortworxVolumeSource
6077
6078 // projected items for all in one resources secrets, configmaps, and downward API
6079 "projected"?: #ProjectedVolumeSource
6080
6081 // quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
6082 // Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer
6083 // supported.
6084 "quobyte"?: #QuobyteVolumeSource
6085
6086 // rbd represents a Rados Block Device mount on the host that shares a pod's
6087 // lifetime. Deprecated: RBD is deprecated and the in-tree rbd type is no
6088 // longer supported.
6089 "rbd"?: #RBDVolumeSource
6090
6091 // scaleIO represents a ScaleIO persistent volume attached and mounted on
6092 // Kubernetes nodes. Deprecated: ScaleIO is deprecated and the in-tree scaleIO
6093 // type is no longer supported.
6094 "scaleIO"?: #ScaleIOVolumeSource
6095
6096 // secret represents a secret that should populate this volume. More info:
6097 // https://kubernetes.io/docs/concepts/storage/volumes#secret
6098 "secret"?: #SecretVolumeSource
6099
6100 // storageOS represents a StorageOS volume attached and mounted on Kubernetes
6101 // nodes. Deprecated: StorageOS is deprecated and the in-tree storageos type is
6102 // no longer supported.
6103 "storageos"?: #StorageOSVolumeSource
6104
6105 // vsphereVolume represents a vSphere volume attached and mounted on kubelets
6106 // host machine. Deprecated: VsphereVolume is deprecated. All operations for
6107 // the in-tree vsphereVolume type are redirected to the csi.vsphere.vmware.com
6108 // CSI driver.
6109 "vsphereVolume"?: #VsphereVirtualDiskVolumeSource
6110}
6111
6112// volumeDevice describes a mapping of a raw block device within a container.
6113#VolumeDevice: {
6114 // devicePath is the path inside of the container that the device will be mapped to.
6115 "devicePath"!: string
6116
6117 // name must match the name of a persistentVolumeClaim in the pod
6118 "name"!: string
6119}
6120
6121// VolumeMount describes a mounting of a Volume within a container.
6122#VolumeMount: {
6123 // Path within the container at which the volume should be mounted. Must not contain ':'.
6124 "mountPath"!: string
6125
6126 // mountPropagation determines how mounts are propagated from the host to
6127 // container and the other way around. When not set, MountPropagationNone is
6128 // used. This field is beta in 1.10. When RecursiveReadOnly is set to
6129 // IfPossible or to Enabled, MountPropagation must be None or unspecified
6130 // (which defaults to None).
6131 "mountPropagation"?: string
6132
6133 // This must match the Name of a Volume.
6134 "name"!: string
6135
6136 // Mounted read-only if true, read-write otherwise (false or unspecified). Defaults to false.
6137 "readOnly"?: bool
6138
6139 // RecursiveReadOnly specifies whether read-only mounts should be handled recursively.
6140 //
6141 // If ReadOnly is false, this field has no meaning and must be unspecified.
6142 //
6143 // If ReadOnly is true, and this field is set to Disabled, the mount is not made
6144 // recursively read-only. If this field is set to IfPossible, the mount is made
6145 // recursively read-only, if it is supported by the container runtime. If this
6146 // field is set to Enabled, the mount is made recursively read-only if it is
6147 // supported by the container runtime, otherwise the pod will not be started
6148 // and an error will be generated to indicate the reason.
6149 //
6150 // If this field is set to IfPossible or Enabled, MountPropagation must be set
6151 // to None (or be unspecified, which defaults to None).
6152 //
6153 // If this field is not specified, it is treated as an equivalent of Disabled.
6154 "recursiveReadOnly"?: string
6155
6156 // Path within the volume from which the container's volume should be mounted.
6157 // Defaults to "" (volume's root).
6158 "subPath"?: string
6159
6160 // Expanded path within the volume from which the container's volume should be
6161 // mounted. Behaves similarly to SubPath but environment variable references
6162 // $(VAR_NAME) are expanded using the container's environment. Defaults to ""
6163 // (volume's root). SubPathExpr and SubPath are mutually exclusive.
6164 "subPathExpr"?: string
6165}
6166
6167// VolumeMountStatus shows status of volume mounts.
6168#VolumeMountStatus: {
6169 // MountPath corresponds to the original VolumeMount.
6170 "mountPath"!: string
6171
6172 // Name corresponds to the name of the original VolumeMount.
6173 "name"!: string
6174
6175 // ReadOnly corresponds to the original VolumeMount.
6176 "readOnly"?: bool
6177
6178 // RecursiveReadOnly must be set to Disabled, Enabled, or unspecified (for
6179 // non-readonly mounts). An IfPossible value in the original VolumeMount must
6180 // be translated to Disabled or Enabled, depending on the mount result.
6181 "recursiveReadOnly"?: string
6182
6183 // volumeStatus represents volume-type-specific status about the mounted volume.
6184 "volumeStatus"?: #VolumeStatus
6185}
6186
6187// VolumeNodeAffinity defines constraints that limit what nodes this volume can be accessed from.
6188#VolumeNodeAffinity: {
6189 // required specifies hard node constraints that must be met.
6190 "required"?: #NodeSelector
6191}
6192
6193// Projection that may be projected along with other supported volume types.
6194// Exactly one of these fields must be set.
6195#VolumeProjection: {
6196 // ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field of
6197 // ClusterTrustBundle objects in an auto-updating file.
6198 //
6199 // Alpha, gated by the ClusterTrustBundleProjection feature gate.
6200 //
6201 // ClusterTrustBundle objects can either be selected by name, or by the
6202 // combination of signer name and a label selector.
6203 //
6204 // Kubelet performs aggressive normalization of the PEM contents written into
6205 // the pod filesystem. Esoteric PEM features such as inter-block comments and
6206 // block headers are stripped. Certificates are deduplicated. The ordering of
6207 // certificates within the file is arbitrary, and Kubelet may change the order
6208 // over time.
6209 "clusterTrustBundle"?: #ClusterTrustBundleProjection
6210
6211 // configMap information about the configMap data to project
6212 "configMap"?: #ConfigMapProjection
6213
6214 // downwardAPI information about the downwardAPI data to project
6215 "downwardAPI"?: #DownwardAPIProjection
6216
6217 // Projects an auto-rotating credential bundle (private key and certificate
6218 // chain) that the pod can use either as a TLS client or server.
6219 //
6220 // Kubelet generates a private key and uses it to send a PodCertificateRequest
6221 // to the named signer. Once the signer approves the request and issues a
6222 // certificate chain, Kubelet writes the key and certificate chain to the pod
6223 // filesystem. The pod does not start until certificates have been issued for
6224 // each podCertificate projected volume source in its spec.
6225 //
6226 // Kubelet will begin trying to rotate the certificate at the time indicated by
6227 // the signer using the PodCertificateRequest.Status.BeginRefreshAt timestamp.
6228 //
6229 // Kubelet can write a single file, indicated by the credentialBundlePath field,
6230 // or separate files, indicated by the keyPath and certificateChainPath fields.
6231 //
6232 // The credential bundle is a single file in PEM format. The first PEM entry is
6233 // the private key (in PKCS#8 format), and the remaining PEM entries are the
6234 // certificate chain issued by the signer (typically, signers will return their
6235 // certificate chain in leaf-to-root order).
6236 //
6237 // Prefer using the credential bundle format, since your application code can
6238 // read it atomically. If you use keyPath and certificateChainPath, your
6239 // application must make two separate file reads. If these coincide with a
6240 // certificate rotation, it is possible that the private key and leaf
6241 // certificate you read may not correspond to each other. Your application will
6242 // need to check for this condition, and re-read until they are consistent.
6243 //
6244 // The named signer controls chooses the format of the certificate it issues;
6245 // consult the signer implementation's documentation to learn how to use the
6246 // certificates it issues.
6247 "podCertificate"?: #PodCertificateProjection
6248
6249 // secret information about the secret data to project
6250 "secret"?: #SecretProjection
6251
6252 // serviceAccountToken is information about the serviceAccountToken data to project
6253 "serviceAccountToken"?: #ServiceAccountTokenProjection
6254}
6255
6256// VolumeResourceRequirements describes the storage resource requirements for a volume.
6257#VolumeResourceRequirements: {
6258 // Limits describes the maximum amount of compute resources allowed. More info:
6259 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
6260 "limits"?: [string]: resource.#Quantity
6261
6262 // Requests describes the minimum amount of compute resources required. If
6263 // Requests is omitted for a container, it defaults to Limits if that is
6264 // explicitly specified, otherwise to an implementation-defined value. Requests
6265 // cannot exceed Limits. More info:
6266 // https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
6267 "requests"?: [string]: resource.#Quantity
6268}
6269
6270// VolumeStatus represents the status of a mounted volume. At most one of its
6271// members must be specified.
6272#VolumeStatus: {
6273 // image represents an OCI object (a container image or artifact) pulled and
6274 // mounted on the kubelet's host machine.
6275 "image"?: #ImageVolumeStatus
6276}
6277
6278// Represents a vSphere volume resource.
6279#VsphereVirtualDiskVolumeSource: {
6280 // fsType is filesystem type to mount. Must be a filesystem type supported by
6281 // the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to
6282 // be "ext4" if unspecified.
6283 "fsType"?: string
6284
6285 // storagePolicyID is the storage Policy Based Management (SPBM) profile ID
6286 // associated with the StoragePolicyName.
6287 "storagePolicyID"?: string
6288
6289 // storagePolicyName is the storage Policy Based Management (SPBM) profile name.
6290 "storagePolicyName"?: string
6291
6292 // volumePath is the path that identifies vSphere volume vmdk
6293 "volumePath"!: string
6294}
6295
6296// The weights of all of the matched WeightedPodAffinityTerm fields are added
6297// per-node to find the most preferred node(s)
6298#WeightedPodAffinityTerm: {
6299 // Required. A pod affinity term, associated with the corresponding weight.
6300 "podAffinityTerm"!: #PodAffinityTerm
6301
6302 // weight associated with matching the corresponding podAffinityTerm, in the range 1-100.
6303 "weight"!: int32 & int
6304}
6305
6306// WindowsSecurityContextOptions contain Windows-specific options and credentials.
6307#WindowsSecurityContextOptions: {
6308 // GMSACredentialSpec is where the GMSA admission webhook
6309 // (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of
6310 // the GMSA credential spec named by the GMSACredentialSpecName field.
6311 "gmsaCredentialSpec"?: string
6312
6313 // GMSACredentialSpecName is the name of the GMSA credential spec to use.
6314 "gmsaCredentialSpecName"?: string
6315
6316 // HostProcess determines if a container should be run as a 'Host Process'
6317 // container. All of a Pod's containers must have the same effective
6318 // HostProcess value (it is not allowed to have a mix of HostProcess containers
6319 // and non-HostProcess containers). In addition, if HostProcess is true then
6320 // HostNetwork must also be set to true.
6321 "hostProcess"?: bool
6322
6323 // The UserName in Windows to run the entrypoint of the container process.
6324 // Defaults to the user specified in image metadata if unspecified. May also be
6325 // set in PodSecurityContext. If set in both SecurityContext and
6326 // PodSecurityContext, the value specified in SecurityContext takes precedence.
6327 "runAsUserName"?: string
6328}