cue.dev/x/k8s.io@v0.12.0

api/core/v1/schema.cue raw

   1package v1
   2
   3import (
   4	"cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
   5	"cue.dev/x/k8s.io/apimachinery/pkg/api/resource"
   6	"cue.dev/x/k8s.io/apimachinery/pkg/util/intstr"
   7)
   8
   9// Represents a Persistent Disk resource in AWS.
  10//
  11// An AWS EBS disk must exist before mounting to a container. The disk must also
  12// be in the same AWS zone as the kubelet. An AWS EBS disk can only be mounted
  13// as read/write once. AWS EBS volumes support ownership management and SELinux
  14// relabeling.
  15#AWSElasticBlockStoreVolumeSource: {
  16	// fsType is the filesystem type of the volume that you want to mount. Tip:
  17	// Ensure that the filesystem type is supported by the host operating system.
  18	// Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
  19	// unspecified. More info:
  20	// https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  21	"fsType"?: string
  22
  23	// partition is the partition in the volume that you want to mount. If omitted,
  24	// the default is to mount by volume name. Examples: For volume /dev/sda1, you
  25	// specify the partition as "1". Similarly, the volume partition for /dev/sda
  26	// is "0" (or you can leave the property empty).
  27	"partition"?: int32 & int
  28
  29	// readOnly value true will force the readOnly setting in VolumeMounts. More
  30	// info:
  31	// https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  32	"readOnly"?: bool
  33
  34	// volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS
  35	// volume). More info:
  36	// https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  37	"volumeID"!: string
  38}
  39
  40// Affinity is a group of affinity scheduling rules.
  41#Affinity: {
  42	// Describes node affinity scheduling rules for the pod.
  43	"nodeAffinity"?: #NodeAffinity
  44
  45	// Describes pod affinity scheduling rules (e.g. co-locate this pod in the same
  46	// node, zone, etc. as some other pod(s)).
  47	"podAffinity"?: #PodAffinity
  48
  49	// Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in
  50	// the same node, zone, etc. as some other pod(s)).
  51	"podAntiAffinity"?: #PodAntiAffinity
  52}
  53
  54// AppArmorProfile defines a pod or container's AppArmor settings.
  55#AppArmorProfile: {
  56	// localhostProfile indicates a profile loaded on the node that should be used.
  57	// The profile must be preconfigured on the node to work. Must match the loaded
  58	// name of the profile. Must be set if and only if type is "Localhost".
  59	"localhostProfile"?: string
  60
  61	// type indicates which kind of AppArmor profile will be applied. Valid options are:
  62	// Localhost - a profile pre-loaded on the node.
  63	// RuntimeDefault - the container runtime's default profile.
  64	// Unconfined - no AppArmor enforcement.
  65	"type"!: string
  66}
  67
  68// AttachedVolume describes a volume attached to a node
  69#AttachedVolume: {
  70	// DevicePath represents the device path where the volume should be available
  71	"devicePath"!: string
  72
  73	// Name of the attached volume
  74	"name"!: string
  75}
  76
  77// AzureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.
  78#AzureDiskVolumeSource: {
  79	// cachingMode is the Host Caching mode: None, Read Only, Read Write.
  80	"cachingMode"?: string
  81
  82	// diskName is the Name of the data disk in the blob storage
  83	"diskName"!: string
  84
  85	// diskURI is the URI of data disk in the blob storage
  86	"diskURI"!: string
  87
  88	// fsType is Filesystem type to mount. Must be a filesystem type supported by
  89	// the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to
  90	// be "ext4" if unspecified.
  91	"fsType"?: string
  92
  93	// kind expected values are Shared: multiple blob disks per storage account
  94	// Dedicated: single blob disk per storage account Managed: azure managed data
  95	// disk (only in managed availability set). defaults to shared
  96	"kind"?: string
  97
  98	// readOnly Defaults to false (read/write). ReadOnly here will force the
  99	// ReadOnly setting in VolumeMounts.
 100	"readOnly"?: bool
 101}
 102
 103// AzureFile represents an Azure File Service mount on the host and bind mount to the pod.
 104#AzureFilePersistentVolumeSource: {
 105	// readOnly defaults to false (read/write). ReadOnly here will force the
 106	// ReadOnly setting in VolumeMounts.
 107	"readOnly"?: bool
 108
 109	// secretName is the name of secret that contains Azure Storage Account Name and Key
 110	"secretName"!: string
 111
 112	// secretNamespace is the namespace of the secret that contains Azure Storage
 113	// Account Name and Key default is the same as the Pod
 114	"secretNamespace"?: string
 115
 116	// shareName is the azure Share Name
 117	"shareName"!: string
 118}
 119
 120// AzureFile represents an Azure File Service mount on the host and bind mount to the pod.
 121#AzureFileVolumeSource: {
 122	// readOnly defaults to false (read/write). ReadOnly here will force the
 123	// ReadOnly setting in VolumeMounts.
 124	"readOnly"?: bool
 125
 126	// secretName is the name of secret that contains Azure Storage Account Name and Key
 127	"secretName"!: string
 128
 129	// shareName is the azure share Name
 130	"shareName"!: string
 131}
 132
 133// Binding ties one object to another; for example, a pod is bound to a node by a scheduler.
 134#Binding: {
 135	// APIVersion defines the versioned schema of this representation of an object.
 136	// Servers should convert recognized schemas to the latest internal value, and
 137	// may reject unrecognized values. More info:
 138	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 139	"apiVersion": "v1"
 140
 141	// Kind is a string value representing the REST resource this object represents.
 142	// Servers may infer this from the endpoint the client submits requests to.
 143	// Cannot be updated. In CamelCase. More info:
 144	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 145	"kind": "Binding"
 146
 147	// Standard object's metadata. More info:
 148	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 149	"metadata"?: v1.#ObjectMeta
 150
 151	// The target object that you want to bind to the standard object.
 152	"target"!: #ObjectReference
 153}
 154
 155// Represents storage that is managed by an external CSI volume driver
 156#CSIPersistentVolumeSource: {
 157	// controllerExpandSecretRef is a reference to the secret object containing
 158	// sensitive information to pass to the CSI driver to complete the CSI
 159	// ControllerExpandVolume call. This field is optional, and may be empty if no
 160	// secret is required. If the secret object contains more than one secret, all
 161	// secrets are passed.
 162	"controllerExpandSecretRef"?: #SecretReference
 163
 164	// controllerPublishSecretRef is a reference to the secret object containing
 165	// sensitive information to pass to the CSI driver to complete the CSI
 166	// ControllerPublishVolume and ControllerUnpublishVolume calls. This field is
 167	// optional, and may be empty if no secret is required. If the secret object
 168	// contains more than one secret, all secrets are passed.
 169	"controllerPublishSecretRef"?: #SecretReference
 170
 171	// driver is the name of the driver to use for this volume. Required.
 172	"driver"!: string
 173
 174	// fsType to mount. Must be a filesystem type supported by the host operating
 175	// system. Ex. "ext4", "xfs", "ntfs".
 176	"fsType"?: string
 177
 178	// nodeExpandSecretRef is a reference to the secret object containing sensitive
 179	// information to pass to the CSI driver to complete the CSI NodeExpandVolume
 180	// call. This field is optional, may be omitted if no secret is required. If
 181	// the secret object contains more than one secret, all secrets are passed.
 182	"nodeExpandSecretRef"?: #SecretReference
 183
 184	// nodePublishSecretRef is a reference to the secret object containing sensitive
 185	// information to pass to the CSI driver to complete the CSI NodePublishVolume
 186	// and NodeUnpublishVolume calls. This field is optional, and may be empty if
 187	// no secret is required. If the secret object contains more than one secret,
 188	// all secrets are passed.
 189	"nodePublishSecretRef"?: #SecretReference
 190
 191	// nodeStageSecretRef is a reference to the secret object containing sensitive
 192	// information to pass to the CSI driver to complete the CSI NodeStageVolume
 193	// and NodeStageVolume and NodeUnstageVolume calls. This field is optional, and
 194	// may be empty if no secret is required. If the secret object contains more
 195	// than one secret, all secrets are passed.
 196	"nodeStageSecretRef"?: #SecretReference
 197
 198	// readOnly value to pass to ControllerPublishVolumeRequest. Defaults to false (read/write).
 199	"readOnly"?: bool
 200
 201	// volumeAttributes of the volume to publish.
 202	"volumeAttributes"?: [string]: string
 203
 204	// volumeHandle is the unique volume name returned by the CSI volume plugin’s
 205	// CreateVolume to refer to the volume on all subsequent calls. Required.
 206	"volumeHandle"!: string
 207}
 208
 209// Represents a source location of a volume to mount, managed by an external CSI driver
 210#CSIVolumeSource: {
 211	// driver is the name of the CSI driver that handles this volume. Consult with
 212	// your admin for the correct name as registered in the cluster.
 213	"driver"!: string
 214
 215	// fsType to mount. Ex. "ext4", "xfs", "ntfs". If not provided, the empty value
 216	// is passed to the associated CSI driver which will determine the default
 217	// filesystem to apply.
 218	"fsType"?: string
 219
 220	// nodePublishSecretRef is a reference to the secret object containing sensitive
 221	// information to pass to the CSI driver to complete the CSI NodePublishVolume
 222	// and NodeUnpublishVolume calls. This field is optional, and may be empty if
 223	// no secret is required. If the secret object contains more than one secret,
 224	// all secret references are passed.
 225	"nodePublishSecretRef"?: #LocalObjectReference
 226
 227	// readOnly specifies a read-only configuration for the volume. Defaults to false (read/write).
 228	"readOnly"?: bool
 229
 230	// volumeAttributes stores driver-specific properties that are passed to the CSI
 231	// driver. Consult your driver's documentation for supported values.
 232	"volumeAttributes"?: [string]: string
 233}
 234
 235// Adds and removes POSIX capabilities from running containers.
 236#Capabilities: {
 237	// Added capabilities
 238	"add"?: [...string]
 239
 240	// Removed capabilities
 241	"drop"?: [...string]
 242}
 243
 244// Represents a Ceph Filesystem mount that lasts the lifetime of a pod Cephfs
 245// volumes do not support ownership management or SELinux relabeling.
 246#CephFSPersistentVolumeSource: {
 247	// monitors is Required: Monitors is a collection of Ceph monitors More info:
 248	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 249	"monitors"!: [...string]
 250
 251	// path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /
 252	"path"?: string
 253
 254	// readOnly is Optional: Defaults to false (read/write). ReadOnly here will
 255	// force the ReadOnly setting in VolumeMounts. More info:
 256	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 257	"readOnly"?: bool
 258
 259	// secretFile is Optional: SecretFile is the path to key ring for User, default
 260	// is /etc/ceph/user.secret More info:
 261	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 262	"secretFile"?: string
 263
 264	// secretRef is Optional: SecretRef is reference to the authentication secret
 265	// for User, default is empty. More info:
 266	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 267	"secretRef"?: #SecretReference
 268
 269	// user is Optional: User is the rados user name, default is admin More info:
 270	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 271	"user"?: string
 272}
 273
 274// Represents a Ceph Filesystem mount that lasts the lifetime of a pod Cephfs
 275// volumes do not support ownership management or SELinux relabeling.
 276#CephFSVolumeSource: {
 277	// monitors is Required: Monitors is a collection of Ceph monitors More info:
 278	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 279	"monitors"!: [...string]
 280
 281	// path is Optional: Used as the mounted root, rather than the full Ceph tree, default is /
 282	"path"?: string
 283
 284	// readOnly is Optional: Defaults to false (read/write). ReadOnly here will
 285	// force the ReadOnly setting in VolumeMounts. More info:
 286	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 287	"readOnly"?: bool
 288
 289	// secretFile is Optional: SecretFile is the path to key ring for User, default
 290	// is /etc/ceph/user.secret More info:
 291	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 292	"secretFile"?: string
 293
 294	// secretRef is Optional: SecretRef is reference to the authentication secret
 295	// for User, default is empty. More info:
 296	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 297	"secretRef"?: #LocalObjectReference
 298
 299	// user is optional: User is the rados user name, default is admin More info:
 300	// https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
 301	"user"?: string
 302}
 303
 304// Represents a cinder volume resource in Openstack. A Cinder volume must exist
 305// before mounting to a container. The volume must also be in the same region
 306// as the kubelet. Cinder volumes support ownership management and SELinux
 307// relabeling.
 308#CinderPersistentVolumeSource: {
 309	// fsType Filesystem type to mount. Must be a filesystem type supported by the
 310	// host operating system. Examples: "ext4", "xfs", "ntfs". Implicitly inferred
 311	// to be "ext4" if unspecified. More info:
 312	// https://examples.k8s.io/mysql-cinder-pd/README.md
 313	"fsType"?: string
 314
 315	// readOnly is Optional: Defaults to false (read/write). ReadOnly here will
 316	// force the ReadOnly setting in VolumeMounts. More info:
 317	// https://examples.k8s.io/mysql-cinder-pd/README.md
 318	"readOnly"?: bool
 319
 320	// secretRef is Optional: points to a secret object containing parameters used
 321	// to connect to OpenStack.
 322	"secretRef"?: #SecretReference
 323
 324	// volumeID used to identify the volume in cinder. More info:
 325	// https://examples.k8s.io/mysql-cinder-pd/README.md
 326	"volumeID"!: string
 327}
 328
 329// Represents a cinder volume resource in Openstack. A Cinder volume must exist
 330// before mounting to a container. The volume must also be in the same region
 331// as the kubelet. Cinder volumes support ownership management and SELinux
 332// relabeling.
 333#CinderVolumeSource: {
 334	// fsType is the filesystem type to mount. Must be a filesystem type supported
 335	// by the host operating system. Examples: "ext4", "xfs", "ntfs". Implicitly
 336	// inferred to be "ext4" if unspecified. More info:
 337	// https://examples.k8s.io/mysql-cinder-pd/README.md
 338	"fsType"?: string
 339
 340	// readOnly defaults to false (read/write). ReadOnly here will force the
 341	// ReadOnly setting in VolumeMounts. More info:
 342	// https://examples.k8s.io/mysql-cinder-pd/README.md
 343	"readOnly"?: bool
 344
 345	// secretRef is optional: points to a secret object containing parameters used
 346	// to connect to OpenStack.
 347	"secretRef"?: #LocalObjectReference
 348
 349	// volumeID used to identify the volume in cinder. More info:
 350	// https://examples.k8s.io/mysql-cinder-pd/README.md
 351	"volumeID"!: string
 352}
 353
 354// ClientIPConfig represents the configurations of Client IP based session affinity.
 355#ClientIPConfig: {
 356	// timeoutSeconds specifies the seconds of ClientIP type session sticky time.
 357	// The value must be >0 && <=86400(for 1 day) if ServiceAffinity == "ClientIP".
 358	// Default value is 10800(for 3 hours).
 359	"timeoutSeconds"?: int32 & int
 360}
 361
 362// ClusterTrustBundleProjection describes how to select a set of
 363// ClusterTrustBundle objects and project their contents into the pod
 364// filesystem.
 365#ClusterTrustBundleProjection: {
 366	// Select all ClusterTrustBundles that match this label selector. Only has
 367	// effect if signerName is set. Mutually-exclusive with name. If unset,
 368	// interpreted as "match nothing". If set but empty, interpreted as "match
 369	// everything".
 370	"labelSelector"?: v1.#LabelSelector
 371
 372	// Select a single ClusterTrustBundle by object name. Mutually-exclusive with
 373	// signerName and labelSelector.
 374	"name"?: string
 375
 376	// If true, don't block pod startup if the referenced ClusterTrustBundle(s)
 377	// aren't available. If using name, then the named ClusterTrustBundle is
 378	// allowed not to exist. If using signerName, then the combination of
 379	// signerName and labelSelector is allowed to match zero ClusterTrustBundles.
 380	"optional"?: bool
 381
 382	// Relative path from the volume root to write the bundle.
 383	"path"!: string
 384
 385	// Select all ClusterTrustBundles that match this signer name.
 386	// Mutually-exclusive with name. The contents of all selected
 387	// ClusterTrustBundles will be unified and deduplicated.
 388	"signerName"?: string
 389}
 390
 391// Information about the condition of a component.
 392#ComponentCondition: {
 393	// Condition error code for a component. For example, a health check error code.
 394	"error"?: string
 395
 396	// Message about the condition for a component. For example, information about a health check.
 397	"message"?: string
 398
 399	// Status of the condition for a component. Valid values for "Healthy": "True",
 400	// "False", or "Unknown".
 401	"status"!: string
 402
 403	// Type of condition for a component. Valid value: "Healthy"
 404	"type"!: string
 405}
 406
 407// ComponentStatus (and ComponentStatusList) holds the cluster validation info.
 408// Deprecated: This API is deprecated in v1.19+
 409#ComponentStatus: {
 410	// APIVersion defines the versioned schema of this representation of an object.
 411	// Servers should convert recognized schemas to the latest internal value, and
 412	// may reject unrecognized values. More info:
 413	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 414	"apiVersion": "v1"
 415
 416	// List of component conditions observed
 417	"conditions"?: [...#ComponentCondition]
 418
 419	// Kind is a string value representing the REST resource this object represents.
 420	// Servers may infer this from the endpoint the client submits requests to.
 421	// Cannot be updated. In CamelCase. More info:
 422	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 423	"kind": "ComponentStatus"
 424
 425	// Standard object's metadata. More info:
 426	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 427	"metadata"?: v1.#ObjectMeta
 428}
 429
 430// Status of all the conditions for the component as a list of ComponentStatus
 431// objects. Deprecated: This API is deprecated in v1.19+
 432#ComponentStatusList: {
 433	// APIVersion defines the versioned schema of this representation of an object.
 434	// Servers should convert recognized schemas to the latest internal value, and
 435	// may reject unrecognized values. More info:
 436	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 437	"apiVersion": "v1"
 438
 439	// List of ComponentStatus objects.
 440	"items"!: [...#ComponentStatus]
 441
 442	// Kind is a string value representing the REST resource this object represents.
 443	// Servers may infer this from the endpoint the client submits requests to.
 444	// Cannot be updated. In CamelCase. More info:
 445	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 446	"kind": "ComponentStatusList"
 447
 448	// Standard list metadata. More info:
 449	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 450	"metadata"?: v1.#ListMeta
 451}
 452
 453// ConfigMap holds configuration data for pods to consume.
 454#ConfigMap: {
 455	// APIVersion defines the versioned schema of this representation of an object.
 456	// Servers should convert recognized schemas to the latest internal value, and
 457	// may reject unrecognized values. More info:
 458	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 459	"apiVersion": "v1"
 460
 461	// BinaryData contains the binary data. Each key must consist of alphanumeric
 462	// characters, '-', '_' or '.'. BinaryData can contain byte sequences that are
 463	// not in the UTF-8 range. The keys stored in BinaryData must not overlap with
 464	// the ones in the Data field, this is enforced during validation process.
 465	// Using this field will require 1.10+ apiserver and kubelet.
 466	"binaryData"?: [string]: string
 467
 468	// Data contains the configuration data. Each key must consist of alphanumeric
 469	// characters, '-', '_' or '.'. Values with non-UTF-8 byte sequences must use
 470	// the BinaryData field. The keys stored in Data must not overlap with the keys
 471	// in the BinaryData field, this is enforced during validation process.
 472	"data"?: [string]: string
 473
 474	// Immutable, if set to true, ensures that data stored in the ConfigMap cannot
 475	// be updated (only object metadata can be modified). If not set to true, the
 476	// field can be modified at any time. Defaulted to nil.
 477	"immutable"?: bool
 478
 479	// Kind is a string value representing the REST resource this object represents.
 480	// Servers may infer this from the endpoint the client submits requests to.
 481	// Cannot be updated. In CamelCase. More info:
 482	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 483	"kind": "ConfigMap"
 484
 485	// Standard object's metadata. More info:
 486	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 487	"metadata"?: v1.#ObjectMeta
 488}
 489
 490// ConfigMapEnvSource selects a ConfigMap to populate the environment variables with.
 491//
 492// The contents of the target ConfigMap's Data field will represent the
 493// key-value pairs as environment variables.
 494#ConfigMapEnvSource: {
 495	// Name of the referent. This field is effectively required, but due to
 496	// backwards compatibility is allowed to be empty. Instances of this type with
 497	// an empty value here are almost certainly wrong. More info:
 498	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
 499	"name"?: string
 500
 501	// Specify whether the ConfigMap must be defined
 502	"optional"?: bool
 503}
 504
 505// Selects a key from a ConfigMap.
 506#ConfigMapKeySelector: {
 507	// The key to select.
 508	"key"!: string
 509
 510	// Name of the referent. This field is effectively required, but due to
 511	// backwards compatibility is allowed to be empty. Instances of this type with
 512	// an empty value here are almost certainly wrong. More info:
 513	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
 514	"name"?: string
 515
 516	// Specify whether the ConfigMap or its key must be defined
 517	"optional"?: bool
 518}
 519
 520// ConfigMapList is a resource containing a list of ConfigMap objects.
 521#ConfigMapList: {
 522	// APIVersion defines the versioned schema of this representation of an object.
 523	// Servers should convert recognized schemas to the latest internal value, and
 524	// may reject unrecognized values. More info:
 525	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 526	"apiVersion": "v1"
 527
 528	// Items is the list of ConfigMaps.
 529	"items"!: [...#ConfigMap]
 530
 531	// Kind is a string value representing the REST resource this object represents.
 532	// Servers may infer this from the endpoint the client submits requests to.
 533	// Cannot be updated. In CamelCase. More info:
 534	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 535	"kind": "ConfigMapList"
 536
 537	// More info:
 538	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 539	"metadata"?: v1.#ListMeta
 540}
 541
 542// ConfigMapNodeConfigSource contains the information to reference a ConfigMap
 543// as a config source for the Node. This API is deprecated since 1.22:
 544// https://git.k8s.io/enhancements/keps/sig-node/281-dynamic-kubelet-configuration
 545#ConfigMapNodeConfigSource: {
 546	// KubeletConfigKey declares which key of the referenced ConfigMap corresponds
 547	// to the KubeletConfiguration structure This field is required in all cases.
 548	"kubeletConfigKey"!: string
 549
 550	// Name is the metadata.name of the referenced ConfigMap. This field is required in all cases.
 551	"name"!: string
 552
 553	// Namespace is the metadata.namespace of the referenced ConfigMap. This field
 554	// is required in all cases.
 555	"namespace"!: string
 556
 557	// ResourceVersion is the metadata.ResourceVersion of the referenced ConfigMap.
 558	// This field is forbidden in Node.Spec, and required in Node.Status.
 559	"resourceVersion"?: string
 560
 561	// UID is the metadata.UID of the referenced ConfigMap. This field is forbidden
 562	// in Node.Spec, and required in Node.Status.
 563	"uid"?: string
 564}
 565
 566// Adapts a ConfigMap into a projected volume.
 567//
 568// The contents of the target ConfigMap's Data field will be presented in a
 569// projected volume as files using the keys in the Data field as the file
 570// names, unless the items element is populated with specific mappings of keys
 571// to paths. Note that this is identical to a configmap volume source without
 572// the default mode.
 573#ConfigMapProjection: {
 574	// items if unspecified, each key-value pair in the Data field of the referenced
 575	// ConfigMap will be projected into the volume as a file whose name is the key
 576	// and content is the value. If specified, the listed keys will be projected
 577	// into the specified paths, and unlisted keys will not be present. If a key is
 578	// specified which is not present in the ConfigMap, the volume setup will error
 579	// unless it is marked optional. Paths must be relative and may not contain the
 580	// '..' path or start with '..'.
 581	"items"?: [...#KeyToPath]
 582
 583	// Name of the referent. This field is effectively required, but due to
 584	// backwards compatibility is allowed to be empty. Instances of this type with
 585	// an empty value here are almost certainly wrong. More info:
 586	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
 587	"name"?: string
 588
 589	// optional specify whether the ConfigMap or its keys must be defined
 590	"optional"?: bool
 591}
 592
 593// Adapts a ConfigMap into a volume.
 594//
 595// The contents of the target ConfigMap's Data field will be presented in a
 596// volume as files using the keys in the Data field as the file names, unless
 597// the items element is populated with specific mappings of keys to paths.
 598// ConfigMap volumes support ownership management and SELinux relabeling.
 599#ConfigMapVolumeSource: {
 600	// defaultMode is optional: mode bits used to set permissions on created files
 601	// by default. Must be an octal value between 0000 and 0777 or a decimal value
 602	// between 0 and 511. YAML accepts both octal and decimal values, JSON requires
 603	// decimal values for mode bits. Defaults to 0644. Directories within the path
 604	// are not affected by this setting. This might be in conflict with other
 605	// options that affect the file mode, like fsGroup, and the result can be other
 606	// mode bits set.
 607	"defaultMode"?: int32 & int
 608
 609	// items if unspecified, each key-value pair in the Data field of the referenced
 610	// ConfigMap will be projected into the volume as a file whose name is the key
 611	// and content is the value. If specified, the listed keys will be projected
 612	// into the specified paths, and unlisted keys will not be present. If a key is
 613	// specified which is not present in the ConfigMap, the volume setup will error
 614	// unless it is marked optional. Paths must be relative and may not contain the
 615	// '..' path or start with '..'.
 616	"items"?: [...#KeyToPath]
 617
 618	// Name of the referent. This field is effectively required, but due to
 619	// backwards compatibility is allowed to be empty. Instances of this type with
 620	// an empty value here are almost certainly wrong. More info:
 621	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
 622	"name"?: string
 623
 624	// optional specify whether the ConfigMap or its keys must be defined
 625	"optional"?: bool
 626}
 627
 628// A single application container that you want to run within a pod.
 629#Container: {
 630	// Arguments to the entrypoint. The container image's CMD is used if this is not
 631	// provided. Variable references $(VAR_NAME) are expanded using the container's
 632	// environment. If a variable cannot be resolved, the reference in the input
 633	// string will be unchanged. Double $$ are reduced to a single $, which allows
 634	// for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the
 635	// string literal "$(VAR_NAME)". Escaped references will never be expanded,
 636	// regardless of whether the variable exists or not. Cannot be updated. More
 637	// info:
 638	// https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
 639	"args"?: [...string]
 640
 641	// Entrypoint array. Not executed within a shell. The container image's
 642	// ENTRYPOINT is used if this is not provided. Variable references $(VAR_NAME)
 643	// are expanded using the container's environment. If a variable cannot be
 644	// resolved, the reference in the input string will be unchanged. Double $$ are
 645	// reduced to a single $, which allows for escaping the $(VAR_NAME) syntax:
 646	// i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
 647	// references will never be expanded, regardless of whether the variable exists
 648	// or not. Cannot be updated. More info:
 649	// https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
 650	"command"?: [...string]
 651
 652	// List of environment variables to set in the container. Cannot be updated.
 653	"env"?: [...#EnvVar]
 654
 655	// List of sources to populate environment variables in the container. The keys
 656	// defined within a source may consist of any printable ASCII characters except
 657	// '='. When a key exists in multiple sources, the value associated with the
 658	// last source will take precedence. Values defined by an Env with a duplicate
 659	// key will take precedence. Cannot be updated.
 660	"envFrom"?: [...#EnvFromSource]
 661
 662	// Container image name. More info:
 663	// https://kubernetes.io/docs/concepts/containers/images This field is optional
 664	// to allow higher level config management to default or override container
 665	// images in workload controllers like Deployments and StatefulSets.
 666	"image"?: string
 667
 668	// Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if
 669	// :latest tag is specified, or IfNotPresent otherwise. Cannot be updated. More
 670	// info: https://kubernetes.io/docs/concepts/containers/images#updating-images
 671	"imagePullPolicy"?: string
 672
 673	// Actions that the management system should take in response to container
 674	// lifecycle events. Cannot be updated.
 675	"lifecycle"?: #Lifecycle
 676
 677	// Periodic probe of container liveness. Container will be restarted if the
 678	// probe fails. Cannot be updated. More info:
 679	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
 680	"livenessProbe"?: #Probe
 681
 682	// Name of the container specified as a DNS_LABEL. Each container in a pod must
 683	// have a unique name (DNS_LABEL). Cannot be updated.
 684	"name"!: string
 685
 686	// List of ports to expose from the container. Not specifying a port here DOES
 687	// NOT prevent that port from being exposed. Any port which is listening on the
 688	// default "0.0.0.0" address inside a container will be accessible from the
 689	// network. Modifying this array with strategic merge patch may corrupt the
 690	// data. For more information See
 691	// https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
 692	"ports"?: [...#ContainerPort]
 693
 694	// Periodic probe of container service readiness. Container will be removed from
 695	// service endpoints if the probe fails. Cannot be updated. More info:
 696	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
 697	"readinessProbe"?: #Probe
 698
 699	// Resources resize policy for the container. This field cannot be set on ephemeral containers.
 700	"resizePolicy"?: [...#ContainerResizePolicy]
 701
 702	// Compute Resources required by this container. Cannot be updated. More info:
 703	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
 704	"resources"?: #ResourceRequirements
 705
 706	// RestartPolicy defines the restart behavior of individual containers in a pod.
 707	// This overrides the pod-level restart policy. When this field is not
 708	// specified, the restart behavior is defined by the Pod's restart policy and
 709	// the container type. Additionally, setting the RestartPolicy as "Always" for
 710	// the init container will have the following effect: this init container will
 711	// be continually restarted on exit until all regular containers have
 712	// terminated. Once all regular containers have completed, all init containers
 713	// with restartPolicy "Always" will be shut down. This lifecycle differs from
 714	// normal init containers and is often referred to as a "sidecar" container.
 715	// Although this init container still starts in the init container sequence, it
 716	// does not wait for the container to complete before proceeding to the next
 717	// init container. Instead, the next init container starts immediately after
 718	// this init container is started, or after any startupProbe has successfully
 719	// completed.
 720	"restartPolicy"?: string
 721
 722	// Represents a list of rules to be checked to determine if the container should
 723	// be restarted on exit. The rules are evaluated in order. Once a rule matches
 724	// a container exit condition, the remaining rules are ignored. If no rule
 725	// matches the container exit condition, the Container-level restart policy
 726	// determines the whether the container is restarted or not. Constraints on the
 727	// rules: - At most 20 rules are allowed. - Rules can have the same action. -
 728	// Identical rules are not forbidden in validations. When rules are specified,
 729	// container MUST set RestartPolicy explicitly even it if matches the Pod's
 730	// RestartPolicy.
 731	"restartPolicyRules"?: [...#ContainerRestartRule]
 732
 733	// SecurityContext defines the security options the container should be run
 734	// with. If set, the fields of SecurityContext override the equivalent fields
 735	// of PodSecurityContext. More info:
 736	// https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
 737	"securityContext"?: #SecurityContext
 738
 739	// StartupProbe indicates that the Pod has successfully initialized. If
 740	// specified, no other probes are executed until this completes successfully.
 741	// If this probe fails, the Pod will be restarted, just as if the livenessProbe
 742	// failed. This can be used to provide different probe parameters at the
 743	// beginning of a Pod's lifecycle, when it might take a long time to load data
 744	// or warm a cache, than during steady-state operation. This cannot be updated.
 745	// More info:
 746	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
 747	"startupProbe"?: #Probe
 748
 749	// Whether this container should allocate a buffer for stdin in the container
 750	// runtime. If this is not set, reads from stdin in the container will always
 751	// result in EOF. Default is false.
 752	"stdin"?: bool
 753
 754	// Whether the container runtime should close the stdin channel after it has
 755	// been opened by a single attach. When stdin is true the stdin stream will
 756	// remain open across multiple attach sessions. If stdinOnce is set to true,
 757	// stdin is opened on container start, is empty until the first client attaches
 758	// to stdin, and then remains open and accepts data until the client
 759	// disconnects, at which time stdin is closed and remains closed until the
 760	// container is restarted. If this flag is false, a container processes that
 761	// reads from stdin will never receive an EOF. Default is false
 762	"stdinOnce"?: bool
 763
 764	// Optional: Path at which the file to which the container's termination message
 765	// will be written is mounted into the container's filesystem. Message written
 766	// is intended to be brief final status, such as an assertion failure message.
 767	// Will be truncated by the node if greater than 4096 bytes. The total message
 768	// length across all containers will be limited to 12kb. Defaults to
 769	// /dev/termination-log. Cannot be updated.
 770	"terminationMessagePath"?: string
 771
 772	// Indicate how the termination message should be populated. File will use the
 773	// contents of terminationMessagePath to populate the container status message
 774	// on both success and failure. FallbackToLogsOnError will use the last chunk
 775	// of container log output if the termination message file is empty and the
 776	// container exited with an error. The log output is limited to 2048 bytes or
 777	// 80 lines, whichever is smaller. Defaults to File. Cannot be updated.
 778	"terminationMessagePolicy"?: string
 779
 780	// Whether this container should allocate a TTY for itself, also requires
 781	// 'stdin' to be true. Default is false.
 782	"tty"?: bool
 783
 784	// volumeDevices is the list of block devices to be used by the container.
 785	"volumeDevices"?: [...#VolumeDevice]
 786
 787	// Pod volumes to mount into the container's filesystem. Cannot be updated.
 788	"volumeMounts"?: [...#VolumeMount]
 789
 790	// Container's working directory. If not specified, the container runtime's
 791	// default will be used, which might be configured in the container image.
 792	// Cannot be updated.
 793	"workingDir"?: string
 794}
 795
 796// ContainerExtendedResourceRequest has the mapping of container name, extended
 797// resource name to the device request name.
 798#ContainerExtendedResourceRequest: {
 799	// The name of the container requesting resources.
 800	"containerName"!: string
 801
 802	// The name of the request in the special ResourceClaim which corresponds to the extended resource.
 803	"requestName"!: string
 804
 805	// The name of the extended resource in that container which gets backed by DRA.
 806	"resourceName"!: string
 807}
 808
 809// Describe a container image
 810#ContainerImage: {
 811	// Names by which this image is known. e.g.
 812	// ["kubernetes.example/hyperkube:v1.0.7",
 813	// "cloud-vendor.registry.example/cloud-vendor/hyperkube:v1.0.7"]
 814	"names"?: [...string]
 815
 816	// The size of the image in bytes.
 817	"sizeBytes"?: int64 & int
 818}
 819
 820// ContainerPort represents a network port in a single container.
 821#ContainerPort: {
 822	// Number of port to expose on the pod's IP address. This must be a valid port
 823	// number, 0 < x < 65536.
 824	"containerPort"!: int32 & int
 825
 826	// What host IP to bind the external port to.
 827	"hostIP"?: string
 828
 829	// Number of port to expose on the host. If specified, this must be a valid port
 830	// number, 0 < x < 65536. If HostNetwork is specified, this must match
 831	// ContainerPort. Most containers do not need this.
 832	"hostPort"?: int32 & int
 833
 834	// If specified, this must be an IANA_SVC_NAME and unique within the pod. Each
 835	// named port in a pod must have a unique name. Name for the port that can be
 836	// referred to by services.
 837	"name"?: string
 838
 839	// Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
 840	"protocol"?: string
 841}
 842
 843// ContainerResizePolicy represents resource resize policy for the container.
 844#ContainerResizePolicy: {
 845	// Name of the resource to which this resource resize policy applies. Supported values: cpu, memory.
 846	"resourceName"!: string
 847
 848	// Restart policy to apply when specified resource is resized. If not specified,
 849	// it defaults to NotRequired.
 850	"restartPolicy"!: string
 851}
 852
 853// ContainerRestartRule describes how a container exit is handled.
 854#ContainerRestartRule: {
 855	// Specifies the action taken on a container exit if the requirements are
 856	// satisfied. The only possible value is "Restart" to restart the container.
 857	"action"!: string
 858
 859	// Represents the exit codes to check on container exits.
 860	"exitCodes"?: #ContainerRestartRuleOnExitCodes
 861}
 862
 863// ContainerRestartRuleOnExitCodes describes the condition for handling an
 864// exited container based on its exit codes.
 865#ContainerRestartRuleOnExitCodes: {
 866	// Represents the relationship between the container exit code(s) and the
 867	// specified values. Possible values are: - In: the requirement is satisfied if
 868	// the container exit code is in the
 869	// set of specified values.
 870	// - NotIn: the requirement is satisfied if the container exit code is
 871	// not in the set of specified values.
 872	"operator"!: string
 873
 874	// Specifies the set of values to check for container exit codes. At most 255 elements are allowed.
 875	"values"?: [...int32 & int]
 876}
 877
 878// ContainerState holds a possible state of container. Only one of its members
 879// may be specified. If none of them is specified, the default one is
 880// ContainerStateWaiting.
 881#ContainerState: {
 882	// Details about a running container
 883	"running"?: #ContainerStateRunning
 884
 885	// Details about a terminated container
 886	"terminated"?: #ContainerStateTerminated
 887
 888	// Details about a waiting container
 889	"waiting"?: #ContainerStateWaiting
 890}
 891
 892// ContainerStateRunning is a running state of a container.
 893#ContainerStateRunning: {
 894	// Time at which the container was last (re-)started
 895	"startedAt"?: v1.#Time
 896}
 897
 898// ContainerStateTerminated is a terminated state of a container.
 899#ContainerStateTerminated: {
 900	// Container's ID in the format '<type>://<container_id>'
 901	"containerID"?: string
 902
 903	// Exit status from the last termination of the container
 904	"exitCode"!: int32 & int
 905
 906	// Time at which the container last terminated
 907	"finishedAt"?: v1.#Time
 908
 909	// Message regarding the last termination of the container
 910	"message"?: string
 911
 912	// (brief) reason from the last termination of the container
 913	"reason"?: string
 914
 915	// Signal from the last termination of the container
 916	"signal"?: int32 & int
 917
 918	// Time at which previous execution of the container started
 919	"startedAt"?: v1.#Time
 920}
 921
 922// ContainerStateWaiting is a waiting state of a container.
 923#ContainerStateWaiting: {
 924	// Message regarding why the container is not yet running.
 925	"message"?: string
 926
 927	// (brief) reason the container is not yet running.
 928	"reason"?: string
 929}
 930
 931// ContainerStatus contains details for the current status of this container.
 932#ContainerStatus: {
 933	// AllocatedResources represents the compute resources allocated for this
 934	// container by the node. Kubelet sets this value to
 935	// Container.Resources.Requests upon successful pod admission and after
 936	// successfully admitting desired pod resize.
 937	"allocatedResources"?: [string]: resource.#Quantity
 938
 939	// AllocatedResourcesStatus represents the status of various resources allocated for this Pod.
 940	"allocatedResourcesStatus"?: [...#ResourceStatus]
 941
 942	// ContainerID is the ID of the container in the format
 943	// '<type>://<container_id>'. Where type is a container runtime identifier,
 944	// returned from Version call of CRI API (for example "containerd").
 945	"containerID"?: string
 946
 947	// Image is the name of container image that the container is running. The
 948	// container image may not match the image used in the PodSpec, as it may have
 949	// been resolved by the runtime. More info:
 950	// https://kubernetes.io/docs/concepts/containers/images.
 951	"image"!: string
 952
 953	// ImageID is the image ID of the container's image. The image ID may not match
 954	// the image ID of the image used in the PodSpec, as it may have been resolved
 955	// by the runtime.
 956	"imageID"!: string
 957
 958	// LastTerminationState holds the last termination state of the container to
 959	// help debug container crashes and restarts. This field is not populated if
 960	// the container is still running and RestartCount is 0.
 961	"lastState"?: #ContainerState
 962
 963	// Name is a DNS_LABEL representing the unique name of the container. Each
 964	// container in a pod must have a unique name across all container types.
 965	// Cannot be updated.
 966	"name"!: string
 967
 968	// Ready specifies whether the container is currently passing its readiness
 969	// check. The value will change as readiness probes keep executing. If no
 970	// readiness probes are specified, this field defaults to true once the
 971	// container is fully started (see Started field).
 972	//
 973	// The value is typically used to determine whether a container is ready to accept traffic.
 974	"ready"!: bool
 975
 976	// Resources represents the compute resource requests and limits that have been
 977	// successfully enacted on the running container after it has been started or
 978	// has been successfully resized.
 979	"resources"?: #ResourceRequirements
 980
 981	// RestartCount holds the number of times the container has been restarted.
 982	// Kubelet makes an effort to always increment the value, but there are cases
 983	// when the state may be lost due to node restarts and then the value may be
 984	// reset to 0. The value is never negative.
 985	"restartCount"!: int32 & int
 986
 987	// Started indicates whether the container has finished its postStart lifecycle
 988	// hook and passed its startup probe. Initialized as false, becomes true after
 989	// startupProbe is considered successful. Resets to false when the container is
 990	// restarted, or if kubelet loses state temporarily. In both cases, startup
 991	// probes will run again. Is always true when no startupProbe is defined and
 992	// container is running and has passed the postStart lifecycle hook. The null
 993	// value must be treated the same as false.
 994	"started"?: bool
 995
 996	// State holds details about the container's current condition.
 997	"state"?: #ContainerState
 998
 999	// StopSignal reports the effective stop signal for this container
1000	"stopSignal"?: string
1001
1002	// User represents user identity information initially attached to the first
1003	// process of the container
1004	"user"?: #ContainerUser
1005
1006	// Status of volume mounts.
1007	"volumeMounts"?: [...#VolumeMountStatus]
1008}
1009
1010// ContainerUser represents user identity information
1011#ContainerUser: {
1012	// Linux holds user identity information initially attached to the first process
1013	// of the containers in Linux. Note that the actual running identity can be
1014	// changed if the process has enough privilege to do so.
1015	"linux"?: #LinuxContainerUser
1016}
1017
1018// DaemonEndpoint contains information about a single Daemon endpoint.
1019#DaemonEndpoint: {
1020	// Port number of the given endpoint.
1021	"Port"!: int32 & int
1022}
1023
1024// Represents downward API info for projecting into a projected volume. Note
1025// that this is identical to a downwardAPI volume source without the default
1026// mode.
1027#DownwardAPIProjection: {
1028	// Items is a list of DownwardAPIVolume file
1029	"items"?: [...#DownwardAPIVolumeFile]
1030}
1031
1032// DownwardAPIVolumeFile represents information to create the file containing the pod field
1033#DownwardAPIVolumeFile: {
1034	// Required: Selects a field of the pod: only annotations, labels, name,
1035	// namespace and uid are supported.
1036	"fieldRef"?: #ObjectFieldSelector
1037
1038	// Optional: mode bits used to set permissions on this file, must be an octal
1039	// value between 0000 and 0777 or a decimal value between 0 and 511. YAML
1040	// accepts both octal and decimal values, JSON requires decimal values for mode
1041	// bits. If not specified, the volume defaultMode will be used. This might be
1042	// in conflict with other options that affect the file mode, like fsGroup, and
1043	// the result can be other mode bits set.
1044	"mode"?: int32 & int
1045
1046	// Required: Path is the relative path name of the file to be created. Must not
1047	// be absolute or contain the '..' path. Must be utf-8 encoded. The first item
1048	// of the relative path must not start with '..'
1049	"path"!: string
1050
1051	// Selects a resource of the container: only resources limits and requests
1052	// (limits.cpu, limits.memory, requests.cpu and requests.memory) are currently
1053	// supported.
1054	"resourceFieldRef"?: #ResourceFieldSelector
1055}
1056
1057// DownwardAPIVolumeSource represents a volume containing downward API info.
1058// Downward API volumes support ownership management and SELinux relabeling.
1059#DownwardAPIVolumeSource: {
1060	// Optional: mode bits to use on created files by default. Must be a Optional:
1061	// mode bits used to set permissions on created files by default. Must be an
1062	// octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
1063	// accepts both octal and decimal values, JSON requires decimal values for mode
1064	// bits. Defaults to 0644. Directories within the path are not affected by this
1065	// setting. This might be in conflict with other options that affect the file
1066	// mode, like fsGroup, and the result can be other mode bits set.
1067	"defaultMode"?: int32 & int
1068
1069	// Items is a list of downward API volume file
1070	"items"?: [...#DownwardAPIVolumeFile]
1071}
1072
1073// Represents an empty directory for a pod. Empty directory volumes support
1074// ownership management and SELinux relabeling.
1075#EmptyDirVolumeSource: {
1076	// medium represents what type of storage medium should back this directory. The
1077	// default is "" which means to use the node's default medium. Must be an empty
1078	// string (default) or Memory. More info:
1079	// https://kubernetes.io/docs/concepts/storage/volumes#emptydir
1080	"medium"?: string
1081
1082	// sizeLimit is the total amount of local storage required for this EmptyDir
1083	// volume. The size limit is also applicable for memory medium. The maximum
1084	// usage on memory medium EmptyDir would be the minimum value between the
1085	// SizeLimit specified here and the sum of memory limits of all containers in a
1086	// pod. The default is nil which means that the limit is undefined. More info:
1087	// https://kubernetes.io/docs/concepts/storage/volumes#emptydir
1088	"sizeLimit"?: resource.#Quantity
1089}
1090
1091// EndpointAddress is a tuple that describes single IP address. Deprecated: This
1092// API is deprecated in v1.33+.
1093#EndpointAddress: {
1094	// The Hostname of this endpoint
1095	"hostname"?: string
1096
1097	// The IP of this endpoint. May not be loopback (127.0.0.0/8 or ::1), link-local
1098	// (169.254.0.0/16 or fe80::/10), or link-local multicast (224.0.0.0/24 or
1099	// ff02::/16).
1100	"ip"!: string
1101
1102	// Optional: Node hosting this endpoint. This can be used to determine endpoints local to a node.
1103	"nodeName"?: string
1104
1105	// Reference to object providing the endpoint.
1106	"targetRef"?: #ObjectReference
1107}
1108
1109// EndpointPort is a tuple that describes a single port. Deprecated: This API is
1110// deprecated in v1.33+.
1111#EndpointPort: {
1112	// The application protocol for this port. This is used as a hint for
1113	// implementations to offer richer behavior for protocols that they understand.
1114	// This field follows standard Kubernetes label syntax. Valid values are
1115	// either:
1116	//
1117	// * Un-prefixed protocol names - reserved for IANA standard service names (as
1118	// per RFC-6335 and https://www.iana.org/assignments/service-names).
1119	//
1120	// * Kubernetes-defined prefixed names:
1121	// * 'kubernetes.io/h2c' - HTTP/2 prior knowledge over cleartext as described in
1122	// https://www.rfc-editor.org/rfc/rfc9113.html#name-starting-http-2-with-prior-
1123	// * 'kubernetes.io/ws' - WebSocket over cleartext as described in
1124	// https://www.rfc-editor.org/rfc/rfc6455
1125	// * 'kubernetes.io/wss' - WebSocket over TLS as described in https://www.rfc-editor.org/rfc/rfc6455
1126	//
1127	// * Other protocols should use implementation-defined prefixed names such as
1128	// mycompany.com/my-custom-protocol.
1129	"appProtocol"?: string
1130
1131	// The name of this port. This must match the 'name' field in the corresponding
1132	// ServicePort. Must be a DNS_LABEL. Optional only if one port is defined.
1133	"name"?: string
1134
1135	// The port number of the endpoint.
1136	"port"!: int32 & int
1137
1138	// The IP protocol for this port. Must be UDP, TCP, or SCTP. Default is TCP.
1139	"protocol"?: string
1140}
1141
1142// EndpointSubset is a group of addresses with a common set of ports. The
1143// expanded set of endpoints is the Cartesian product of Addresses x Ports. For
1144// example, given:
1145//
1146// {
1147// Addresses: [{"ip": "10.10.1.1"}, {"ip": "10.10.2.2"}],
1148// Ports: [{"name": "a", "port": 8675}, {"name": "b", "port": 309}]
1149// }
1150//
1151// The resulting set of endpoints can be viewed as:
1152//
1153// a: [ 10.10.1.1:8675, 10.10.2.2:8675 ],
1154// b: [ 10.10.1.1:309, 10.10.2.2:309 ]
1155//
1156// Deprecated: This API is deprecated in v1.33+.
1157#EndpointSubset: {
1158	// IP addresses which offer the related ports that are marked as ready. These
1159	// endpoints should be considered safe for load balancers and clients to
1160	// utilize.
1161	"addresses"?: [...#EndpointAddress]
1162
1163	// IP addresses which offer the related ports but are not currently marked as
1164	// ready because they have not yet finished starting, have recently failed a
1165	// readiness check, or have recently failed a liveness check.
1166	"notReadyAddresses"?: [...#EndpointAddress]
1167
1168	// Port numbers available on the related IP addresses.
1169	"ports"?: [...#EndpointPort]
1170}
1171
1172// Endpoints is a collection of endpoints that implement the actual service. Example:
1173//
1174// Name: "mysvc",
1175// Subsets: [
1176// {
1177// Addresses: [{"ip": "10.10.1.1"}, {"ip": "10.10.2.2"}],
1178// Ports: [{"name": "a", "port": 8675}, {"name": "b", "port": 309}]
1179// },
1180// {
1181// Addresses: [{"ip": "10.10.3.3"}],
1182// Ports: [{"name": "a", "port": 93}, {"name": "b", "port": 76}]
1183// },
1184// ]
1185//
1186// Endpoints is a legacy API and does not contain information about all Service
1187// features. Use discoveryv1.EndpointSlice for complete information about
1188// Service endpoints.
1189//
1190// Deprecated: This API is deprecated in v1.33+. Use discoveryv1.EndpointSlice.
1191#Endpoints: {
1192	// APIVersion defines the versioned schema of this representation of an object.
1193	// Servers should convert recognized schemas to the latest internal value, and
1194	// may reject unrecognized values. More info:
1195	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1196	"apiVersion": "v1"
1197
1198	// Kind is a string value representing the REST resource this object represents.
1199	// Servers may infer this from the endpoint the client submits requests to.
1200	// Cannot be updated. In CamelCase. More info:
1201	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1202	"kind": "Endpoints"
1203
1204	// Standard object's metadata. More info:
1205	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
1206	"metadata"?: v1.#ObjectMeta
1207
1208	// The set of all endpoints is the union of all subsets. Addresses are placed
1209	// into subsets according to the IPs they share. A single address with multiple
1210	// ports, some of which are ready and some of which are not (because they come
1211	// from different containers) will result in the address being displayed in
1212	// different subsets for the different ports. No address will appear in both
1213	// Addresses and NotReadyAddresses in the same subset. Sets of addresses and
1214	// ports that comprise a service.
1215	"subsets"?: [...#EndpointSubset]
1216}
1217
1218// EndpointsList is a list of endpoints. Deprecated: This API is deprecated in v1.33+.
1219#EndpointsList: {
1220	// APIVersion defines the versioned schema of this representation of an object.
1221	// Servers should convert recognized schemas to the latest internal value, and
1222	// may reject unrecognized values. More info:
1223	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1224	"apiVersion": "v1"
1225
1226	// List of endpoints.
1227	"items"!: [...#Endpoints]
1228
1229	// Kind is a string value representing the REST resource this object represents.
1230	// Servers may infer this from the endpoint the client submits requests to.
1231	// Cannot be updated. In CamelCase. More info:
1232	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1233	"kind": "EndpointsList"
1234
1235	// Standard list metadata. More info:
1236	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1237	"metadata"?: v1.#ListMeta
1238}
1239
1240// EnvFromSource represents the source of a set of ConfigMaps or Secrets
1241#EnvFromSource: {
1242	// The ConfigMap to select from
1243	"configMapRef"?: #ConfigMapEnvSource
1244
1245	// Optional text to prepend to the name of each environment variable. May
1246	// consist of any printable ASCII characters except '='.
1247	"prefix"?: string
1248
1249	// The Secret to select from
1250	"secretRef"?: #SecretEnvSource
1251}
1252
1253// EnvVar represents an environment variable present in a Container.
1254#EnvVar: {
1255	// Name of the environment variable. May consist of any printable ASCII characters except '='.
1256	"name"!: string
1257
1258	// Variable references $(VAR_NAME) are expanded using the previously defined
1259	// environment variables in the container and any service environment
1260	// variables. If a variable cannot be resolved, the reference in the input
1261	// string will be unchanged. Double $$ are reduced to a single $, which allows
1262	// for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the
1263	// string literal "$(VAR_NAME)". Escaped references will never be expanded,
1264	// regardless of whether the variable exists or not. Defaults to "".
1265	"value"?: string
1266
1267	// Source for the environment variable's value. Cannot be used if value is not empty.
1268	"valueFrom"?: #EnvVarSource
1269}
1270
1271// EnvVarSource represents a source for the value of an EnvVar.
1272#EnvVarSource: {
1273	// Selects a key of a ConfigMap.
1274	"configMapKeyRef"?: #ConfigMapKeySelector
1275
1276	// Selects a field of the pod: supports metadata.name, metadata.namespace,
1277	// `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
1278	// spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
1279	"fieldRef"?: #ObjectFieldSelector
1280
1281	// FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be enabled.
1282	"fileKeyRef"?: #FileKeySelector
1283
1284	// Selects a resource of the container: only resources limits and requests
1285	// (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
1286	// requests.memory and requests.ephemeral-storage) are currently supported.
1287	"resourceFieldRef"?: #ResourceFieldSelector
1288
1289	// Selects a key of a secret in the pod's namespace
1290	"secretKeyRef"?: #SecretKeySelector
1291}
1292
1293// An EphemeralContainer is a temporary container that you may add to an
1294// existing Pod for user-initiated activities such as debugging. Ephemeral
1295// containers have no resource or scheduling guarantees, and they will not be
1296// restarted when they exit or when a Pod is removed or restarted. The kubelet
1297// may evict a Pod if an ephemeral container causes the Pod to exceed its
1298// resource allocation.
1299//
1300// To add an ephemeral container, use the ephemeralcontainers subresource of an
1301// existing Pod. Ephemeral containers may not be removed or restarted.
1302#EphemeralContainer: {
1303	// Arguments to the entrypoint. The image's CMD is used if this is not provided.
1304	// Variable references $(VAR_NAME) are expanded using the container's
1305	// environment. If a variable cannot be resolved, the reference in the input
1306	// string will be unchanged. Double $$ are reduced to a single $, which allows
1307	// for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the
1308	// string literal "$(VAR_NAME)". Escaped references will never be expanded,
1309	// regardless of whether the variable exists or not. Cannot be updated. More
1310	// info:
1311	// https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
1312	"args"?: [...string]
1313
1314	// Entrypoint array. Not executed within a shell. The image's ENTRYPOINT is used
1315	// if this is not provided. Variable references $(VAR_NAME) are expanded using
1316	// the container's environment. If a variable cannot be resolved, the reference
1317	// in the input string will be unchanged. Double $$ are reduced to a single $,
1318	// which allows for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will
1319	// produce the string literal "$(VAR_NAME)". Escaped references will never be
1320	// expanded, regardless of whether the variable exists or not. Cannot be
1321	// updated. More info:
1322	// https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
1323	"command"?: [...string]
1324
1325	// List of environment variables to set in the container. Cannot be updated.
1326	"env"?: [...#EnvVar]
1327
1328	// List of sources to populate environment variables in the container. The keys
1329	// defined within a source may consist of any printable ASCII characters except
1330	// '='. When a key exists in multiple sources, the value associated with the
1331	// last source will take precedence. Values defined by an Env with a duplicate
1332	// key will take precedence. Cannot be updated.
1333	"envFrom"?: [...#EnvFromSource]
1334
1335	// Container image name. More info: https://kubernetes.io/docs/concepts/containers/images
1336	"image"?: string
1337
1338	// Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if
1339	// :latest tag is specified, or IfNotPresent otherwise. Cannot be updated. More
1340	// info: https://kubernetes.io/docs/concepts/containers/images#updating-images
1341	"imagePullPolicy"?: string
1342
1343	// Lifecycle is not allowed for ephemeral containers.
1344	"lifecycle"?: #Lifecycle
1345
1346	// Probes are not allowed for ephemeral containers.
1347	"livenessProbe"?: #Probe
1348
1349	// Name of the ephemeral container specified as a DNS_LABEL. This name must be
1350	// unique among all containers, init containers and ephemeral containers.
1351	"name"!: string
1352
1353	// Ports are not allowed for ephemeral containers.
1354	"ports"?: [...#ContainerPort]
1355
1356	// Probes are not allowed for ephemeral containers.
1357	"readinessProbe"?: #Probe
1358
1359	// Resources resize policy for the container.
1360	"resizePolicy"?: [...#ContainerResizePolicy]
1361
1362	// Resources are not allowed for ephemeral containers. Ephemeral containers use
1363	// spare resources already allocated to the pod.
1364	"resources"?: #ResourceRequirements
1365
1366	// Restart policy for the container to manage the restart behavior of each
1367	// container within a pod. You cannot set this field on ephemeral containers.
1368	"restartPolicy"?: string
1369
1370	// Represents a list of rules to be checked to determine if the container should
1371	// be restarted on exit. You cannot set this field on ephemeral containers.
1372	"restartPolicyRules"?: [...#ContainerRestartRule]
1373
1374	// Optional: SecurityContext defines the security options the ephemeral
1375	// container should be run with. If set, the fields of SecurityContext override
1376	// the equivalent fields of PodSecurityContext.
1377	"securityContext"?: #SecurityContext
1378
1379	// Probes are not allowed for ephemeral containers.
1380	"startupProbe"?: #Probe
1381
1382	// Whether this container should allocate a buffer for stdin in the container
1383	// runtime. If this is not set, reads from stdin in the container will always
1384	// result in EOF. Default is false.
1385	"stdin"?: bool
1386
1387	// Whether the container runtime should close the stdin channel after it has
1388	// been opened by a single attach. When stdin is true the stdin stream will
1389	// remain open across multiple attach sessions. If stdinOnce is set to true,
1390	// stdin is opened on container start, is empty until the first client attaches
1391	// to stdin, and then remains open and accepts data until the client
1392	// disconnects, at which time stdin is closed and remains closed until the
1393	// container is restarted. If this flag is false, a container processes that
1394	// reads from stdin will never receive an EOF. Default is false
1395	"stdinOnce"?: bool
1396
1397	// If set, the name of the container from PodSpec that this ephemeral container
1398	// targets. The ephemeral container will be run in the namespaces (IPC, PID,
1399	// etc) of this container. If not set then the ephemeral container uses the
1400	// namespaces configured in the Pod spec.
1401	//
1402	// The container runtime must implement support for this feature. If the runtime
1403	// does not support namespace targeting then the result of setting this field
1404	// is undefined.
1405	"targetContainerName"?: string
1406
1407	// Optional: Path at which the file to which the container's termination message
1408	// will be written is mounted into the container's filesystem. Message written
1409	// is intended to be brief final status, such as an assertion failure message.
1410	// Will be truncated by the node if greater than 4096 bytes. The total message
1411	// length across all containers will be limited to 12kb. Defaults to
1412	// /dev/termination-log. Cannot be updated.
1413	"terminationMessagePath"?: string
1414
1415	// Indicate how the termination message should be populated. File will use the
1416	// contents of terminationMessagePath to populate the container status message
1417	// on both success and failure. FallbackToLogsOnError will use the last chunk
1418	// of container log output if the termination message file is empty and the
1419	// container exited with an error. The log output is limited to 2048 bytes or
1420	// 80 lines, whichever is smaller. Defaults to File. Cannot be updated.
1421	"terminationMessagePolicy"?: string
1422
1423	// Whether this container should allocate a TTY for itself, also requires
1424	// 'stdin' to be true. Default is false.
1425	"tty"?: bool
1426
1427	// volumeDevices is the list of block devices to be used by the container.
1428	"volumeDevices"?: [...#VolumeDevice]
1429
1430	// Pod volumes to mount into the container's filesystem. Subpath mounts are not
1431	// allowed for ephemeral containers. Cannot be updated.
1432	"volumeMounts"?: [...#VolumeMount]
1433
1434	// Container's working directory. If not specified, the container runtime's
1435	// default will be used, which might be configured in the container image.
1436	// Cannot be updated.
1437	"workingDir"?: string
1438}
1439
1440// Represents an ephemeral volume that is handled by a normal storage driver.
1441#EphemeralVolumeSource: {
1442	// Will be used to create a stand-alone PVC to provision the volume. The pod in
1443	// which this EphemeralVolumeSource is embedded will be the owner of the PVC,
1444	// i.e. the PVC will be deleted together with the pod. The name of the PVC will
1445	// be `<pod name>-<volume name>` where `<volume name>` is the name from the
1446	// `PodSpec.Volumes` array entry. Pod validation will reject the pod if the
1447	// concatenated name is not valid for a PVC (for example, too long).
1448	//
1449	// An existing PVC with that name that is not owned by the pod will *not* be
1450	// used for the pod to avoid using an unrelated volume by mistake. Starting the
1451	// pod is then blocked until the unrelated PVC is removed. If such a
1452	// pre-created PVC is meant to be used by the pod, the PVC has to updated with
1453	// an owner reference to the pod once the pod exists. Normally this should not
1454	// be necessary, but it may be useful when manually reconstructing a broken
1455	// cluster.
1456	//
1457	// This field is read-only and no changes will be made by Kubernetes to the PVC
1458	// after it has been created.
1459	//
1460	// Required, must not be nil.
1461	"volumeClaimTemplate"?: #PersistentVolumeClaimTemplate
1462}
1463
1464// Event is a report of an event somewhere in the cluster. Events have a limited
1465// retention time and triggers and messages may evolve with time. Event
1466// consumers should not rely on the timing of an event with a given Reason
1467// reflecting a consistent underlying trigger, or the continued existence of
1468// events with that Reason. Events should be treated as informative,
1469// best-effort, supplemental data.
1470#Event: {
1471	// What action was taken/failed regarding to the Regarding object.
1472	"action"?: string
1473
1474	// APIVersion defines the versioned schema of this representation of an object.
1475	// Servers should convert recognized schemas to the latest internal value, and
1476	// may reject unrecognized values. More info:
1477	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1478	"apiVersion": "v1"
1479
1480	// The number of times this event has occurred.
1481	"count"?: int32 & int
1482
1483	// Time when this Event was first observed.
1484	"eventTime"?: v1.#MicroTime
1485
1486	// The time at which the event was first recorded. (Time of server receipt is in TypeMeta.)
1487	"firstTimestamp"?: v1.#Time
1488
1489	// The object that this event is about.
1490	"involvedObject"!: #ObjectReference
1491
1492	// Kind is a string value representing the REST resource this object represents.
1493	// Servers may infer this from the endpoint the client submits requests to.
1494	// Cannot be updated. In CamelCase. More info:
1495	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1496	"kind": "Event"
1497
1498	// The time at which the most recent occurrence of this event was recorded.
1499	"lastTimestamp"?: v1.#Time
1500
1501	// A human-readable description of the status of this operation.
1502	"message"?: string
1503
1504	// Standard object's metadata. More info:
1505	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
1506	"metadata"!: v1.#ObjectMeta
1507
1508	// This should be a short, machine understandable string that gives the reason
1509	// for the transition into the object's current status.
1510	"reason"?: string
1511
1512	// Optional secondary object for more complex actions.
1513	"related"?: #ObjectReference
1514
1515	// Name of the controller that emitted this Event, e.g. `kubernetes.io/kubelet`.
1516	"reportingComponent"?: string
1517
1518	// ID of the controller instance, e.g. `kubelet-xyzf`.
1519	"reportingInstance"?: string
1520
1521	// Data about the Event series this event represents or nil if it's a singleton Event.
1522	"series"?: #EventSeries
1523
1524	// The component reporting this event. Should be a short machine understandable string.
1525	"source"?: #EventSource
1526
1527	// Type of this event (Normal, Warning), new types could be added in the future
1528	"type"?: string
1529}
1530
1531// EventList is a list of events.
1532#EventList: {
1533	// APIVersion defines the versioned schema of this representation of an object.
1534	// Servers should convert recognized schemas to the latest internal value, and
1535	// may reject unrecognized values. More info:
1536	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
1537	"apiVersion": "v1"
1538
1539	// List of events
1540	"items"!: [...#Event]
1541
1542	// Kind is a string value representing the REST resource this object represents.
1543	// Servers may infer this from the endpoint the client submits requests to.
1544	// Cannot be updated. In CamelCase. More info:
1545	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1546	"kind": "EventList"
1547
1548	// Standard list metadata. More info:
1549	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
1550	"metadata"?: v1.#ListMeta
1551}
1552
1553// EventSeries contain information on series of events, i.e. thing that was/is
1554// happening continuously for some time.
1555#EventSeries: {
1556	// Number of occurrences in this series up to the last heartbeat time
1557	"count"?: int32 & int
1558
1559	// Time of the last occurrence observed
1560	"lastObservedTime"?: v1.#MicroTime
1561}
1562
1563// EventSource contains information for an event.
1564#EventSource: {
1565	// Component from which the event is generated.
1566	"component"?: string
1567
1568	// Node name on which the event is generated.
1569	"host"?: string
1570}
1571
1572// ExecAction describes a "run in container" action.
1573#ExecAction: {
1574	// Command is the command line to execute inside the container, the working
1575	// directory for the command is root ('/') in the container's filesystem. The
1576	// command is simply exec'd, it is not run inside a shell, so traditional shell
1577	// instructions ('|', etc) won't work. To use a shell, you need to explicitly
1578	// call out to that shell. Exit status of 0 is treated as live/healthy and
1579	// non-zero is unhealthy.
1580	"command"?: [...string]
1581}
1582
1583// Represents a Fibre Channel volume. Fibre Channel volumes can only be mounted
1584// as read/write once. Fibre Channel volumes support ownership management and
1585// SELinux relabeling.
1586#FCVolumeSource: {
1587	// fsType is the filesystem type to mount. Must be a filesystem type supported
1588	// by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
1589	// to be "ext4" if unspecified.
1590	"fsType"?: string
1591
1592	// lun is Optional: FC target lun number
1593	"lun"?: int32 & int
1594
1595	// readOnly is Optional: Defaults to false (read/write). ReadOnly here will
1596	// force the ReadOnly setting in VolumeMounts.
1597	"readOnly"?: bool
1598
1599	// targetWWNs is Optional: FC target worldwide names (WWNs)
1600	"targetWWNs"?: [...string]
1601
1602	// wwids Optional: FC volume world wide identifiers (wwids) Either wwids or
1603	// combination of targetWWNs and lun must be set, but not both simultaneously.
1604	"wwids"?: [...string]
1605}
1606
1607// FileKeySelector selects a key of the env file.
1608#FileKeySelector: {
1609	// The key within the env file. An invalid key will prevent the pod from
1610	// starting. The keys defined within a source may consist of any printable
1611	// ASCII characters except '='. During Alpha stage of the EnvFiles feature
1612	// gate, the key size is limited to 128 characters.
1613	"key"!: string
1614
1615	// Specify whether the file or its key must be defined. If the file or key does
1616	// not exist, then the env var is not published. If optional is set to true and
1617	// the specified key does not exist, the environment variable will not be set
1618	// in the Pod's containers.
1619	//
1620	// If optional is set to false and the specified key does not exist, an error
1621	// will be returned during Pod creation.
1622	"optional"?: bool
1623
1624	// The path within the volume from which to select the file. Must be relative
1625	// and may not contain the '..' path or start with '..'.
1626	"path"!: string
1627
1628	// The name of the volume mount containing the env file.
1629	"volumeName"!: string
1630}
1631
1632// FlexPersistentVolumeSource represents a generic persistent volume resource
1633// that is provisioned/attached using an exec based plugin.
1634#FlexPersistentVolumeSource: {
1635	// driver is the name of the driver to use for this volume.
1636	"driver"!: string
1637
1638	// fsType is the Filesystem type to mount. Must be a filesystem type supported
1639	// by the host operating system. Ex. "ext4", "xfs", "ntfs". The default
1640	// filesystem depends on FlexVolume script.
1641	"fsType"?: string
1642
1643	// options is Optional: this field holds extra command options if any.
1644	"options"?: [string]: string
1645
1646	// readOnly is Optional: defaults to false (read/write). ReadOnly here will
1647	// force the ReadOnly setting in VolumeMounts.
1648	"readOnly"?: bool
1649
1650	// secretRef is Optional: SecretRef is reference to the secret object containing
1651	// sensitive information to pass to the plugin scripts. This may be empty if no
1652	// secret object is specified. If the secret object contains more than one
1653	// secret, all secrets are passed to the plugin scripts.
1654	"secretRef"?: #SecretReference
1655}
1656
1657// FlexVolume represents a generic volume resource that is provisioned/attached
1658// using an exec based plugin.
1659#FlexVolumeSource: {
1660	// driver is the name of the driver to use for this volume.
1661	"driver"!: string
1662
1663	// fsType is the filesystem type to mount. Must be a filesystem type supported
1664	// by the host operating system. Ex. "ext4", "xfs", "ntfs". The default
1665	// filesystem depends on FlexVolume script.
1666	"fsType"?: string
1667
1668	// options is Optional: this field holds extra command options if any.
1669	"options"?: [string]: string
1670
1671	// readOnly is Optional: defaults to false (read/write). ReadOnly here will
1672	// force the ReadOnly setting in VolumeMounts.
1673	"readOnly"?: bool
1674
1675	// secretRef is Optional: secretRef is reference to the secret object containing
1676	// sensitive information to pass to the plugin scripts. This may be empty if no
1677	// secret object is specified. If the secret object contains more than one
1678	// secret, all secrets are passed to the plugin scripts.
1679	"secretRef"?: #LocalObjectReference
1680}
1681
1682// Represents a Flocker volume mounted by the Flocker agent. One and only one of
1683// datasetName and datasetUUID should be set. Flocker volumes do not support
1684// ownership management or SELinux relabeling.
1685#FlockerVolumeSource: {
1686	// datasetName is Name of the dataset stored as metadata -> name on the dataset
1687	// for Flocker should be considered as deprecated
1688	"datasetName"?: string
1689
1690	// datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker dataset
1691	"datasetUUID"?: string
1692}
1693
1694// Represents a Persistent Disk resource in Google Compute Engine.
1695//
1696// A GCE PD must exist before mounting to a container. The disk must also be in
1697// the same GCE project and zone as the kubelet. A GCE PD can only be mounted
1698// as read/write once or read-only many times. GCE PDs support ownership
1699// management and SELinux relabeling.
1700#GCEPersistentDiskVolumeSource: {
1701	// fsType is filesystem type of the volume that you want to mount. Tip: Ensure
1702	// that the filesystem type is supported by the host operating system.
1703	// Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
1704	// unspecified. More info:
1705	// https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1706	"fsType"?: string
1707
1708	// partition is the partition in the volume that you want to mount. If omitted,
1709	// the default is to mount by volume name. Examples: For volume /dev/sda1, you
1710	// specify the partition as "1". Similarly, the volume partition for /dev/sda
1711	// is "0" (or you can leave the property empty). More info:
1712	// https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1713	"partition"?: int32 & int
1714
1715	// pdName is unique name of the PD resource in GCE. Used to identify the disk in
1716	// GCE. More info:
1717	// https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1718	"pdName"!: string
1719
1720	// readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to
1721	// false. More info:
1722	// https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
1723	"readOnly"?: bool
1724}
1725
1726// GRPCAction specifies an action involving a GRPC service.
1727#GRPCAction: {
1728	// Port number of the gRPC service. Number must be in the range 1 to 65535.
1729	"port"!: int32 & int
1730
1731	// Service is the name of the service to place in the gRPC HealthCheckRequest
1732	// (see https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
1733	//
1734	// If this is not specified, the default behavior is defined by gRPC.
1735	"service"?: string
1736}
1737
1738// Represents a volume that is populated with the contents of a git repository.
1739// Git repo volumes do not support ownership management. Git repo volumes
1740// support SELinux relabeling.
1741//
1742// DEPRECATED: GitRepo is deprecated. To provision a container with a git repo,
1743// mount an EmptyDir into an InitContainer that clones the repo using git, then
1744// mount the EmptyDir into the Pod's container.
1745#GitRepoVolumeSource: {
1746	// directory is the target directory name. Must not contain or start with '..'.
1747	// If '.' is supplied, the volume directory will be the git repository.
1748	// Otherwise, if specified, the volume will contain the git repository in the
1749	// subdirectory with the given name.
1750	"directory"?: string
1751
1752	// repository is the URL
1753	"repository"!: string
1754
1755	// revision is the commit hash for the specified revision.
1756	"revision"?: string
1757}
1758
1759// Represents a Glusterfs mount that lasts the lifetime of a pod. Glusterfs
1760// volumes do not support ownership management or SELinux relabeling.
1761#GlusterfsPersistentVolumeSource: {
1762	// endpoints is the endpoint name that details Glusterfs topology. More info:
1763	// https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1764	"endpoints"!: string
1765
1766	// endpointsNamespace is the namespace that contains Glusterfs endpoint. If this
1767	// field is empty, the EndpointNamespace defaults to the same namespace as the
1768	// bound PVC. More info:
1769	// https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1770	"endpointsNamespace"?: string
1771
1772	// path is the Glusterfs volume path. More info:
1773	// https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1774	"path"!: string
1775
1776	// readOnly here will force the Glusterfs volume to be mounted with read-only
1777	// permissions. Defaults to false. More info:
1778	// https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1779	"readOnly"?: bool
1780}
1781
1782// Represents a Glusterfs mount that lasts the lifetime of a pod. Glusterfs
1783// volumes do not support ownership management or SELinux relabeling.
1784#GlusterfsVolumeSource: {
1785	// endpoints is the endpoint name that details Glusterfs topology.
1786	"endpoints"!: string
1787
1788	// path is the Glusterfs volume path. More info:
1789	// https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1790	"path"!: string
1791
1792	// readOnly here will force the Glusterfs volume to be mounted with read-only
1793	// permissions. Defaults to false. More info:
1794	// https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
1795	"readOnly"?: bool
1796}
1797
1798// HTTPGetAction describes an action based on HTTP Get requests.
1799#HTTPGetAction: {
1800	// Host name to connect to, defaults to the pod IP. You probably want to set
1801	// "Host" in httpHeaders instead.
1802	"host"?: string
1803
1804	// Custom headers to set in the request. HTTP allows repeated headers.
1805	"httpHeaders"?: [...#HTTPHeader]
1806
1807	// Path to access on the HTTP server.
1808	"path"?: string
1809
1810	// Name or number of the port to access on the container. Number must be in the
1811	// range 1 to 65535. Name must be an IANA_SVC_NAME.
1812	"port"!: intstr.#IntOrString
1813
1814	// Scheme to use for connecting to the host. Defaults to HTTP.
1815	"scheme"?: string
1816}
1817
1818// HTTPHeader describes a custom header to be used in HTTP probes
1819#HTTPHeader: {
1820	// The header field name. This will be canonicalized upon output, so
1821	// case-variant names will be understood as the same header.
1822	"name"!: string
1823
1824	// The header field value
1825	"value"!: string
1826}
1827
1828// HostAlias holds the mapping between IP and hostnames that will be injected as
1829// an entry in the pod's hosts file.
1830#HostAlias: {
1831	// Hostnames for the above IP address.
1832	"hostnames"?: [...string]
1833
1834	// IP address of the host file entry.
1835	"ip"!: string
1836}
1837
1838// HostIP represents a single IP address allocated to the host.
1839#HostIP: {
1840	// IP is the IP address assigned to the host
1841	"ip"!: string
1842}
1843
1844// Represents a host path mapped into a pod. Host path volumes do not support
1845// ownership management or SELinux relabeling.
1846#HostPathVolumeSource: {
1847	// path of the directory on the host. If the path is a symlink, it will follow
1848	// the link to the real path. More info:
1849	// https://kubernetes.io/docs/concepts/storage/volumes#hostpath
1850	"path"!: string
1851
1852	// type for HostPath Volume Defaults to "" More info:
1853	// https://kubernetes.io/docs/concepts/storage/volumes#hostpath
1854	"type"?: string
1855}
1856
1857// ISCSIPersistentVolumeSource represents an ISCSI disk. ISCSI volumes can only
1858// be mounted as read/write once. ISCSI volumes support ownership management
1859// and SELinux relabeling.
1860#ISCSIPersistentVolumeSource: {
1861	// chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication
1862	"chapAuthDiscovery"?: bool
1863
1864	// chapAuthSession defines whether support iSCSI Session CHAP authentication
1865	"chapAuthSession"?: bool
1866
1867	// fsType is the filesystem type of the volume that you want to mount. Tip:
1868	// Ensure that the filesystem type is supported by the host operating system.
1869	// Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
1870	// unspecified. More info:
1871	// https://kubernetes.io/docs/concepts/storage/volumes#iscsi
1872	"fsType"?: string
1873
1874	// initiatorName is the custom iSCSI Initiator Name. If initiatorName is
1875	// specified with iscsiInterface simultaneously, new iSCSI interface <target
1876	// portal>:<volume name> will be created for the connection.
1877	"initiatorName"?: string
1878
1879	// iqn is Target iSCSI Qualified Name.
1880	"iqn"!: string
1881
1882	// iscsiInterface is the interface Name that uses an iSCSI transport. Defaults to 'default' (tcp).
1883	"iscsiInterface"?: string
1884
1885	// lun is iSCSI Target Lun number.
1886	"lun"!: int32 & int
1887
1888	// portals is the iSCSI Target Portal List. The Portal is either an IP or
1889	// ip_addr:port if the port is other than default (typically TCP ports 860 and
1890	// 3260).
1891	"portals"?: [...string]
1892
1893	// readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
1894	"readOnly"?: bool
1895
1896	// secretRef is the CHAP Secret for iSCSI target and initiator authentication
1897	"secretRef"?: #SecretReference
1898
1899	// targetPortal is iSCSI Target Portal. The Portal is either an IP or
1900	// ip_addr:port if the port is other than default (typically TCP ports 860 and
1901	// 3260).
1902	"targetPortal"!: string
1903}
1904
1905// Represents an ISCSI disk. ISCSI volumes can only be mounted as read/write
1906// once. ISCSI volumes support ownership management and SELinux relabeling.
1907#ISCSIVolumeSource: {
1908	// chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication
1909	"chapAuthDiscovery"?: bool
1910
1911	// chapAuthSession defines whether support iSCSI Session CHAP authentication
1912	"chapAuthSession"?: bool
1913
1914	// fsType is the filesystem type of the volume that you want to mount. Tip:
1915	// Ensure that the filesystem type is supported by the host operating system.
1916	// Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
1917	// unspecified. More info:
1918	// https://kubernetes.io/docs/concepts/storage/volumes#iscsi
1919	"fsType"?: string
1920
1921	// initiatorName is the custom iSCSI Initiator Name. If initiatorName is
1922	// specified with iscsiInterface simultaneously, new iSCSI interface <target
1923	// portal>:<volume name> will be created for the connection.
1924	"initiatorName"?: string
1925
1926	// iqn is the target iSCSI Qualified Name.
1927	"iqn"!: string
1928
1929	// iscsiInterface is the interface Name that uses an iSCSI transport. Defaults to 'default' (tcp).
1930	"iscsiInterface"?: string
1931
1932	// lun represents iSCSI Target Lun number.
1933	"lun"!: int32 & int
1934
1935	// portals is the iSCSI Target Portal List. The portal is either an IP or
1936	// ip_addr:port if the port is other than default (typically TCP ports 860 and
1937	// 3260).
1938	"portals"?: [...string]
1939
1940	// readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
1941	"readOnly"?: bool
1942
1943	// secretRef is the CHAP Secret for iSCSI target and initiator authentication
1944	"secretRef"?: #LocalObjectReference
1945
1946	// targetPortal is iSCSI Target Portal. The Portal is either an IP or
1947	// ip_addr:port if the port is other than default (typically TCP ports 860 and
1948	// 3260).
1949	"targetPortal"!: string
1950}
1951
1952// ImageVolumeSource represents a image volume resource.
1953#ImageVolumeSource: {
1954	// Policy for pulling OCI objects. Possible values are: Always: the kubelet
1955	// always attempts to pull the reference. Container creation will fail If the
1956	// pull fails. Never: the kubelet never pulls the reference and only uses a
1957	// local image or artifact. Container creation will fail if the reference isn't
1958	// present. IfNotPresent: the kubelet pulls if the reference isn't already
1959	// present on disk. Container creation will fail if the reference isn't present
1960	// and the pull fails. Defaults to Always if :latest tag is specified, or
1961	// IfNotPresent otherwise.
1962	"pullPolicy"?: string
1963
1964	// Required: Image or artifact reference to be used. Behaves in the same way as
1965	// pod.spec.containers[*].image. Pull secrets will be assembled in the same way
1966	// as for the container image by looking up node credentials, SA image pull
1967	// secrets, and pod spec image pull secrets. More info:
1968	// https://kubernetes.io/docs/concepts/containers/images This field is optional
1969	// to allow higher level config management to default or override container
1970	// images in workload controllers like Deployments and StatefulSets.
1971	"reference"?: string
1972}
1973
1974// ImageVolumeStatus represents the image-based volume status.
1975#ImageVolumeStatus: {
1976	// ImageRef is the digest of the image used for this volume. It should have a
1977	// value that's similar to the pod's status.containerStatuses[i].imageID. The
1978	// ImageRef length should not exceed 256 characters.
1979	"imageRef"!: string
1980}
1981
1982// Maps a string key to a path within a volume.
1983#KeyToPath: {
1984	// key is the key to project.
1985	"key"!: string
1986
1987	// mode is Optional: mode bits used to set permissions on this file. Must be an
1988	// octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
1989	// accepts both octal and decimal values, JSON requires decimal values for mode
1990	// bits. If not specified, the volume defaultMode will be used. This might be
1991	// in conflict with other options that affect the file mode, like fsGroup, and
1992	// the result can be other mode bits set.
1993	"mode"?: int32 & int
1994
1995	// path is the relative path of the file to map the key to. May not be an
1996	// absolute path. May not contain the path element '..'. May not start with the
1997	// string '..'.
1998	"path"!: string
1999}
2000
2001// Lifecycle describes actions that the management system should take in
2002// response to container lifecycle events. For the PostStart and PreStop
2003// lifecycle handlers, management of the container blocks until the action is
2004// complete, unless the container process fails, in which case the handler is
2005// aborted.
2006#Lifecycle: {
2007	// PostStart is called immediately after a container is created. If the handler
2008	// fails, the container is terminated and restarted according to its restart
2009	// policy. Other management of the container blocks until the hook completes.
2010	// More info:
2011	// https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
2012	"postStart"?: #LifecycleHandler
2013
2014	// PreStop is called immediately before a container is terminated due to an API
2015	// request or management event such as liveness/startup probe failure,
2016	// preemption, resource contention, etc. The handler is not called if the
2017	// container crashes or exits. The Pod's termination grace period countdown
2018	// begins before the PreStop hook is executed. Regardless of the outcome of the
2019	// handler, the container will eventually terminate within the Pod's
2020	// termination grace period (unless delayed by finalizers). Other management of
2021	// the container blocks until the hook completes or until the termination grace
2022	// period is reached. More info:
2023	// https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
2024	"preStop"?: #LifecycleHandler
2025
2026	// StopSignal defines which signal will be sent to a container when it is being
2027	// stopped. If not specified, the default is defined by the container runtime
2028	// in use. StopSignal can only be set for Pods with a non-empty .spec.os.name
2029	"stopSignal"?: string
2030}
2031
2032// LifecycleHandler defines a specific action that should be taken in a
2033// lifecycle hook. One and only one of the fields, except TCPSocket must be
2034// specified.
2035#LifecycleHandler: {
2036	// Exec specifies a command to execute in the container.
2037	"exec"?: #ExecAction
2038
2039	// HTTPGet specifies an HTTP GET request to perform.
2040	"httpGet"?: #HTTPGetAction
2041
2042	// Sleep represents a duration that the container should sleep.
2043	"sleep"?: #SleepAction
2044
2045	// Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
2046	// backward compatibility. There is no validation of this field and lifecycle
2047	// hooks will fail at runtime when it is specified.
2048	"tcpSocket"?: #TCPSocketAction
2049}
2050
2051// LimitRange sets resource usage limits for each kind of resource in a Namespace.
2052#LimitRange: {
2053	// APIVersion defines the versioned schema of this representation of an object.
2054	// Servers should convert recognized schemas to the latest internal value, and
2055	// may reject unrecognized values. More info:
2056	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2057	"apiVersion": "v1"
2058
2059	// Kind is a string value representing the REST resource this object represents.
2060	// Servers may infer this from the endpoint the client submits requests to.
2061	// Cannot be updated. In CamelCase. More info:
2062	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2063	"kind": "LimitRange"
2064
2065	// Standard object's metadata. More info:
2066	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2067	"metadata"?: v1.#ObjectMeta
2068
2069	// Spec defines the limits enforced. More info:
2070	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2071	"spec"?: #LimitRangeSpec
2072}
2073
2074// LimitRangeItem defines a min/max usage limit for any resource that matches on kind.
2075#LimitRangeItem: {
2076	// Default resource requirement limit value by resource name if resource limit is omitted.
2077	"default"?: [string]: resource.#Quantity
2078
2079	// DefaultRequest is the default resource requirement request value by resource
2080	// name if resource request is omitted.
2081	"defaultRequest"?: [string]: resource.#Quantity
2082
2083	// Max usage constraints on this kind by resource name.
2084	"max"?: [string]: resource.#Quantity
2085
2086	// MaxLimitRequestRatio if specified, the named resource must have a request and
2087	// limit that are both non-zero where limit divided by request is less than or
2088	// equal to the enumerated value; this represents the max burst for the named
2089	// resource.
2090	"maxLimitRequestRatio"?: [string]: resource.#Quantity
2091
2092	// Min usage constraints on this kind by resource name.
2093	"min"?: [string]: resource.#Quantity
2094
2095	// Type of resource that this limit applies to.
2096	"type"!: string
2097}
2098
2099// LimitRangeList is a list of LimitRange items.
2100#LimitRangeList: {
2101	// APIVersion defines the versioned schema of this representation of an object.
2102	// Servers should convert recognized schemas to the latest internal value, and
2103	// may reject unrecognized values. More info:
2104	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2105	"apiVersion": "v1"
2106
2107	// Items is a list of LimitRange objects. More info:
2108	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
2109	"items"!: [...#LimitRange]
2110
2111	// Kind is a string value representing the REST resource this object represents.
2112	// Servers may infer this from the endpoint the client submits requests to.
2113	// Cannot be updated. In CamelCase. More info:
2114	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2115	"kind": "LimitRangeList"
2116
2117	// Standard list metadata. More info:
2118	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2119	"metadata"?: v1.#ListMeta
2120}
2121
2122// LimitRangeSpec defines a min/max usage limit for resources that match on kind.
2123#LimitRangeSpec: {
2124	// Limits is the list of LimitRangeItem objects that are enforced.
2125	"limits"!: [...#LimitRangeItem]
2126}
2127
2128// LinuxContainerUser represents user identity information in Linux containers
2129#LinuxContainerUser: {
2130	// GID is the primary gid initially attached to the first process in the container
2131	"gid"!: int64 & int
2132
2133	// SupplementalGroups are the supplemental groups initially attached to the
2134	// first process in the container
2135	"supplementalGroups"?: [...int64 & int]
2136
2137	// UID is the primary uid initially attached to the first process in the container
2138	"uid"!: int64 & int
2139}
2140
2141// LoadBalancerIngress represents the status of a load-balancer ingress point:
2142// traffic intended for the service should be sent to an ingress point.
2143#LoadBalancerIngress: {
2144	// Hostname is set for load-balancer ingress points that are DNS based
2145	// (typically AWS load-balancers)
2146	"hostname"?: string
2147
2148	// IP is set for load-balancer ingress points that are IP based (typically GCE
2149	// or OpenStack load-balancers)
2150	"ip"?: string
2151
2152	// IPMode specifies how the load-balancer IP behaves, and may only be specified
2153	// when the ip field is specified. Setting this to "VIP" indicates that traffic
2154	// is delivered to the node with the destination set to the load-balancer's IP
2155	// and port. Setting this to "Proxy" indicates that traffic is delivered to the
2156	// node or pod with the destination set to the node's IP and node port or the
2157	// pod's IP and port. Service implementations may use this information to
2158	// adjust traffic routing.
2159	"ipMode"?: string
2160
2161	// Ports is a list of records of service ports If used, every port defined in
2162	// the service should have an entry in it
2163	"ports"?: [...#PortStatus]
2164}
2165
2166// LoadBalancerStatus represents the status of a load-balancer.
2167#LoadBalancerStatus: {
2168	// Ingress is a list containing ingress points for the load-balancer. Traffic
2169	// intended for the service should be sent to these ingress points.
2170	"ingress"?: [...#LoadBalancerIngress]
2171}
2172
2173// LocalObjectReference contains enough information to let you locate the
2174// referenced object inside the same namespace.
2175#LocalObjectReference: {
2176	// Name of the referent. This field is effectively required, but due to
2177	// backwards compatibility is allowed to be empty. Instances of this type with
2178	// an empty value here are almost certainly wrong. More info:
2179	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
2180	"name"?: string
2181}
2182
2183// Local represents directly-attached storage with node affinity
2184#LocalVolumeSource: {
2185	// fsType is the filesystem type to mount. It applies only when the Path is a
2186	// block device. Must be a filesystem type supported by the host operating
2187	// system. Ex. "ext4", "xfs", "ntfs". The default value is to auto-select a
2188	// filesystem if unspecified.
2189	"fsType"?: string
2190
2191	// path of the full path to the volume on the node. It can be either a directory
2192	// or block device (disk, partition, ...).
2193	"path"!: string
2194}
2195
2196// ModifyVolumeStatus represents the status object of ControllerModifyVolume operation
2197#ModifyVolumeStatus: {
2198	// status is the status of the ControllerModifyVolume operation. It can be in
2199	// any of following states:
2200	// - Pending
2201	// Pending indicates that the PersistentVolumeClaim cannot be modified due to
2202	// unmet requirements, such as
2203	// the specified VolumeAttributesClass not existing.
2204	// - InProgress
2205	// InProgress indicates that the volume is being modified.
2206	// - Infeasible
2207	// Infeasible indicates that the request has been rejected as invalid by the CSI driver. To
2208	// resolve the error, a valid VolumeAttributesClass needs to be specified.
2209	// Note: New statuses can be added in the future. Consumers should check for
2210	// unknown statuses and fail appropriately.
2211	"status"!: string
2212
2213	// targetVolumeAttributesClassName is the name of the VolumeAttributesClass the
2214	// PVC currently being reconciled
2215	"targetVolumeAttributesClassName"?: string
2216}
2217
2218// Represents an NFS mount that lasts the lifetime of a pod. NFS volumes do not
2219// support ownership management or SELinux relabeling.
2220#NFSVolumeSource: {
2221	// path that is exported by the NFS server. More info:
2222	// https://kubernetes.io/docs/concepts/storage/volumes#nfs
2223	"path"!: string
2224
2225	// readOnly here will force the NFS export to be mounted with read-only
2226	// permissions. Defaults to false. More info:
2227	// https://kubernetes.io/docs/concepts/storage/volumes#nfs
2228	"readOnly"?: bool
2229
2230	// server is the hostname or IP address of the NFS server. More info:
2231	// https://kubernetes.io/docs/concepts/storage/volumes#nfs
2232	"server"!: string
2233}
2234
2235// Namespace provides a scope for Names. Use of multiple namespaces is optional.
2236#Namespace: {
2237	// APIVersion defines the versioned schema of this representation of an object.
2238	// Servers should convert recognized schemas to the latest internal value, and
2239	// may reject unrecognized values. More info:
2240	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2241	"apiVersion": "v1"
2242
2243	// Kind is a string value representing the REST resource this object represents.
2244	// Servers may infer this from the endpoint the client submits requests to.
2245	// Cannot be updated. In CamelCase. More info:
2246	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2247	"kind": "Namespace"
2248
2249	// Standard object's metadata. More info:
2250	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2251	"metadata"?: v1.#ObjectMeta
2252
2253	// Spec defines the behavior of the Namespace. More info:
2254	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2255	"spec"?: #NamespaceSpec
2256
2257	// Status describes the current status of a Namespace. More info:
2258	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2259	"status"?: #NamespaceStatus
2260}
2261
2262// NamespaceCondition contains details about state of namespace.
2263#NamespaceCondition: {
2264	// Last time the condition transitioned from one status to another.
2265	"lastTransitionTime"?: v1.#Time
2266
2267	// Human-readable message indicating details about last transition.
2268	"message"?: string
2269
2270	// Unique, one-word, CamelCase reason for the condition's last transition.
2271	"reason"?: string
2272
2273	// Status of the condition, one of True, False, Unknown.
2274	"status"!: string
2275
2276	// Type of namespace controller condition.
2277	"type"!: string
2278}
2279
2280// NamespaceList is a list of Namespaces.
2281#NamespaceList: {
2282	// APIVersion defines the versioned schema of this representation of an object.
2283	// Servers should convert recognized schemas to the latest internal value, and
2284	// may reject unrecognized values. More info:
2285	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2286	"apiVersion": "v1"
2287
2288	// Items is the list of Namespace objects in the list. More info:
2289	// https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
2290	"items"!: [...#Namespace]
2291
2292	// Kind is a string value representing the REST resource this object represents.
2293	// Servers may infer this from the endpoint the client submits requests to.
2294	// Cannot be updated. In CamelCase. More info:
2295	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2296	"kind": "NamespaceList"
2297
2298	// Standard list metadata. More info:
2299	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2300	"metadata"?: v1.#ListMeta
2301}
2302
2303// NamespaceSpec describes the attributes on a Namespace.
2304#NamespaceSpec: {
2305	// Finalizers is an opaque list of values that must be empty to permanently
2306	// remove object from storage. More info:
2307	// https://kubernetes.io/docs/tasks/administer-cluster/namespaces/
2308	"finalizers"?: [...string]
2309}
2310
2311// NamespaceStatus is information about the current status of a Namespace.
2312#NamespaceStatus: {
2313	// Represents the latest available observations of a namespace's current state.
2314	"conditions"?: [...#NamespaceCondition]
2315
2316	// Phase is the current lifecycle phase of the namespace. More info:
2317	// https://kubernetes.io/docs/tasks/administer-cluster/namespaces/
2318	"phase"?: string
2319}
2320
2321// Node is a worker node in Kubernetes. Each node will have a unique identifier
2322// in the cache (i.e. in etcd).
2323#Node: {
2324	// APIVersion defines the versioned schema of this representation of an object.
2325	// Servers should convert recognized schemas to the latest internal value, and
2326	// may reject unrecognized values. More info:
2327	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2328	"apiVersion": "v1"
2329
2330	// Kind is a string value representing the REST resource this object represents.
2331	// Servers may infer this from the endpoint the client submits requests to.
2332	// Cannot be updated. In CamelCase. More info:
2333	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2334	"kind": "Node"
2335
2336	// Standard object's metadata. More info:
2337	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2338	"metadata"?: v1.#ObjectMeta
2339
2340	// Spec defines the behavior of a node.
2341	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2342	"spec"?: #NodeSpec
2343
2344	// Most recently observed status of the node. Populated by the system.
2345	// Read-only. More info:
2346	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
2347	"status"?: #NodeStatus
2348}
2349
2350// NodeAddress contains information for the node's address.
2351#NodeAddress: {
2352	// The node address.
2353	"address"!: string
2354
2355	// Node address type, one of Hostname, ExternalIP or InternalIP.
2356	"type"!: string
2357}
2358
2359// Node affinity is a group of node affinity scheduling rules.
2360#NodeAffinity: {
2361	// The scheduler will prefer to schedule pods to nodes that satisfy the affinity
2362	// expressions specified by this field, but it may choose a node that violates
2363	// one or more of the expressions. The node that is most preferred is the one
2364	// with the greatest sum of weights, i.e. for each node that meets all of the
2365	// scheduling requirements (resource request, requiredDuringScheduling affinity
2366	// expressions, etc.), compute a sum by iterating through the elements of this
2367	// field and adding "weight" to the sum if the node matches the corresponding
2368	// matchExpressions; the node(s) with the highest sum are the most preferred.
2369	"preferredDuringSchedulingIgnoredDuringExecution"?: [...#PreferredSchedulingTerm]
2370
2371	// If the affinity requirements specified by this field are not met at
2372	// scheduling time, the pod will not be scheduled onto the node. If the
2373	// affinity requirements specified by this field cease to be met at some point
2374	// during pod execution (e.g. due to an update), the system may or may not try
2375	// to eventually evict the pod from its node.
2376	"requiredDuringSchedulingIgnoredDuringExecution"?: #NodeSelector
2377}
2378
2379// NodeAllocatableResourceClaimStatus describes the status of node allocatable
2380// resources allocated via DRA.
2381#NodeAllocatableResourceClaimStatus: {
2382	// Containers lists the names of all containers in this pod that reference the claim.
2383	"containers"?: [...string]
2384
2385	// ResourceClaimName is the resource claim referenced by the pod that resulted
2386	// in this node allocatable resource allocation.
2387	"resourceClaimName"!: string
2388
2389	// Resources is a map of the node-allocatable resource name to the aggregate
2390	// quantity allocated to the claim.
2391	"resources"!: [string]: resource.#Quantity
2392}
2393
2394// NodeCondition contains condition information for a node.
2395#NodeCondition: {
2396	// Last time we got an update on a given condition.
2397	"lastHeartbeatTime"?: v1.#Time
2398
2399	// Last time the condition transit from one status to another.
2400	"lastTransitionTime"?: v1.#Time
2401
2402	// Human readable message indicating details about last transition.
2403	"message"?: string
2404
2405	// (brief) reason for the condition's last transition.
2406	"reason"?: string
2407
2408	// Status of the condition, one of True, False, Unknown.
2409	"status"!: string
2410
2411	// Type of node condition.
2412	"type"!: string
2413}
2414
2415// NodeConfigSource specifies a source of node configuration. Exactly one
2416// subfield (excluding metadata) must be non-nil. This API is deprecated since
2417// 1.22
2418#NodeConfigSource: {
2419	// ConfigMap is a reference to a Node's ConfigMap
2420	"configMap"?: #ConfigMapNodeConfigSource
2421}
2422
2423// NodeConfigStatus describes the status of the config assigned by Node.Spec.ConfigSource.
2424#NodeConfigStatus: {
2425	// Active reports the checkpointed config the node is actively using. Active
2426	// will represent either the current version of the Assigned config, or the
2427	// current LastKnownGood config, depending on whether attempting to use the
2428	// Assigned config results in an error.
2429	"active"?: #NodeConfigSource
2430
2431	// Assigned reports the checkpointed config the node will try to use. When
2432	// Node.Spec.ConfigSource is updated, the node checkpoints the associated
2433	// config payload to local disk, along with a record indicating intended
2434	// config. The node refers to this record to choose its config checkpoint, and
2435	// reports this record in Assigned. Assigned only updates in the status after
2436	// the record has been checkpointed to disk. When the Kubelet is restarted, it
2437	// tries to make the Assigned config the Active config by loading and
2438	// validating the checkpointed payload identified by Assigned.
2439	"assigned"?: #NodeConfigSource
2440
2441	// Error describes any problems reconciling the Spec.ConfigSource to the Active
2442	// config. Errors may occur, for example, attempting to checkpoint
2443	// Spec.ConfigSource to the local Assigned record, attempting to checkpoint the
2444	// payload associated with Spec.ConfigSource, attempting to load or validate
2445	// the Assigned config, etc. Errors may occur at different points while syncing
2446	// config. Earlier errors (e.g. download or checkpointing errors) will not
2447	// result in a rollback to LastKnownGood, and may resolve across Kubelet
2448	// retries. Later errors (e.g. loading or validating a checkpointed config)
2449	// will result in a rollback to LastKnownGood. In the latter case, it is
2450	// usually possible to resolve the error by fixing the config assigned in
2451	// Spec.ConfigSource. You can find additional information for debugging by
2452	// searching the error message in the Kubelet log. Error is a human-readable
2453	// description of the error state; machines can check whether or not Error is
2454	// empty, but should not rely on the stability of the Error text across Kubelet
2455	// versions.
2456	"error"?: string
2457
2458	// LastKnownGood reports the checkpointed config the node will fall back to when
2459	// it encounters an error attempting to use the Assigned config. The Assigned
2460	// config becomes the LastKnownGood config when the node determines that the
2461	// Assigned config is stable and correct. This is currently implemented as a
2462	// 10-minute soak period starting when the local record of Assigned config is
2463	// updated. If the Assigned config is Active at the end of this period, it
2464	// becomes the LastKnownGood. Note that if Spec.ConfigSource is reset to nil
2465	// (use local defaults), the LastKnownGood is also immediately reset to nil,
2466	// because the local default config is always assumed good. You should not make
2467	// assumptions about the node's method of determining config stability and
2468	// correctness, as this may change or become configurable in the future.
2469	"lastKnownGood"?: #NodeConfigSource
2470}
2471
2472// NodeDaemonEndpoints lists ports opened by daemons running on the Node.
2473#NodeDaemonEndpoints: {
2474	// Endpoint on which Kubelet is listening.
2475	"kubeletEndpoint"?: #DaemonEndpoint
2476}
2477
2478// NodeFeatures describes the set of features implemented by the CRI
2479// implementation. The features contained in the NodeFeatures should depend
2480// only on the cri implementation independent of runtime handlers.
2481#NodeFeatures: {
2482	// SupplementalGroupsPolicy is set to true if the runtime supports
2483	// SupplementalGroupsPolicy and ContainerUser.
2484	"supplementalGroupsPolicy"?: bool
2485}
2486
2487// NodeList is the whole list of all Nodes which have been registered with master.
2488#NodeList: {
2489	// APIVersion defines the versioned schema of this representation of an object.
2490	// Servers should convert recognized schemas to the latest internal value, and
2491	// may reject unrecognized values. More info:
2492	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2493	"apiVersion": "v1"
2494
2495	// List of nodes
2496	"items"!: [...#Node]
2497
2498	// Kind is a string value representing the REST resource this object represents.
2499	// Servers may infer this from the endpoint the client submits requests to.
2500	// Cannot be updated. In CamelCase. More info:
2501	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2502	"kind": "NodeList"
2503
2504	// Standard list metadata. More info:
2505	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2506	"metadata"?: v1.#ListMeta
2507}
2508
2509// NodeRuntimeHandler is a set of runtime handler information.
2510#NodeRuntimeHandler: {
2511	// Supported features.
2512	"features"?: #NodeRuntimeHandlerFeatures
2513
2514	// Runtime handler name. Empty for the default runtime handler.
2515	"name"?: string
2516}
2517
2518// NodeRuntimeHandlerFeatures is a set of features implemented by the runtime handler.
2519#NodeRuntimeHandlerFeatures: {
2520	// RecursiveReadOnlyMounts is set to true if the runtime handler supports RecursiveReadOnlyMounts.
2521	"recursiveReadOnlyMounts"?: bool
2522
2523	// UserNamespaces is set to true if the runtime handler supports UserNamespaces,
2524	// including for volumes.
2525	"userNamespaces"?: bool
2526}
2527
2528// A node selector represents the union of the results of one or more label
2529// queries over a set of nodes; that is, it represents the OR of the selectors
2530// represented by the node selector terms.
2531#NodeSelector: {
2532	// Required. A list of node selector terms. The terms are ORed.
2533	"nodeSelectorTerms"!: [...#NodeSelectorTerm]
2534}
2535
2536// A node selector requirement is a selector that contains values, a key, and an
2537// operator that relates the key and values.
2538#NodeSelectorRequirement: {
2539	// The label key that the selector applies to.
2540	"key"!: string
2541
2542	// Represents a key's relationship to a set of values. Valid operators are In,
2543	// NotIn, Exists, DoesNotExist. Gt, and Lt.
2544	"operator"!: string
2545
2546	// An array of string values. If the operator is In or NotIn, the values array
2547	// must be non-empty. If the operator is Exists or DoesNotExist, the values
2548	// array must be empty. If the operator is Gt or Lt, the values array must have
2549	// a single element, which will be interpreted as an integer. This array is
2550	// replaced during a strategic merge patch.
2551	"values"?: [...string]
2552}
2553
2554// A null or empty node selector term matches no objects. The requirements of
2555// them are ANDed. The TopologySelectorTerm type implements a subset of the
2556// NodeSelectorTerm.
2557#NodeSelectorTerm: {
2558	// A list of node selector requirements by node's labels.
2559	"matchExpressions"?: [...#NodeSelectorRequirement]
2560
2561	// A list of node selector requirements by node's fields.
2562	"matchFields"?: [...#NodeSelectorRequirement]
2563}
2564
2565// NodeSpec describes the attributes that a node is created with.
2566#NodeSpec: {
2567	// Deprecated: Previously used to specify the source of the node's configuration
2568	// for the DynamicKubeletConfig feature. This feature is removed.
2569	"configSource"?: #NodeConfigSource
2570
2571	// Deprecated. Not all kubelets will set this field. Remove field after 1.13.
2572	// see: https://issues.k8s.io/61966
2573	"externalID"?: string
2574
2575	// PodCIDR represents the pod IP range assigned to the node.
2576	"podCIDR"?: string
2577
2578	// podCIDRs represents the IP ranges assigned to the node for usage by Pods on
2579	// that node. If this field is specified, the 0th entry must match the podCIDR
2580	// field. It may contain at most 1 value for each of IPv4 and IPv6.
2581	"podCIDRs"?: [...string]
2582
2583	// ID of the node assigned by the cloud provider in the format:
2584	// <ProviderName>://<ProviderSpecificNodeID>
2585	"providerID"?: string
2586
2587	// If specified, the node's taints.
2588	"taints"?: [...#Taint]
2589
2590	// Unschedulable controls node schedulability of new pods. By default, node is
2591	// schedulable. More info:
2592	// https://kubernetes.io/docs/concepts/nodes/node/#manual-node-administration
2593	"unschedulable"?: bool
2594}
2595
2596// NodeStatus is information about the current status of a node.
2597#NodeStatus: {
2598	// List of addresses reachable to the node. Queried from cloud provider, if
2599	// available. More info:
2600	// https://kubernetes.io/docs/reference/node/node-status/#addresses Note: This
2601	// field is declared as mergeable, but the merge key is not sufficiently
2602	// unique, which can cause data corruption when it is merged. Callers should
2603	// instead use a full-replacement patch. See https://pr.k8s.io/79391 for an
2604	// example. Consumers should assume that addresses can change during the
2605	// lifetime of a Node. However, there are some exceptions where this may not be
2606	// possible, such as Pods that inherit a Node's address in its own status or
2607	// consumers of the downward API (status.hostIP).
2608	"addresses"?: [...#NodeAddress]
2609
2610	// Allocatable represents the resources of a node that are available for
2611	// scheduling. Defaults to Capacity.
2612	"allocatable"?: [string]: resource.#Quantity
2613
2614	// Capacity represents the total resources of a node. More info:
2615	// https://kubernetes.io/docs/reference/node/node-status/#capacity
2616	"capacity"?: [string]: resource.#Quantity
2617
2618	// Conditions is an array of current observed node conditions. More info:
2619	// https://kubernetes.io/docs/reference/node/node-status/#condition
2620	"conditions"?: [...#NodeCondition]
2621
2622	// Status of the config assigned to the node via the dynamic Kubelet config feature.
2623	"config"?: #NodeConfigStatus
2624
2625	// Endpoints of daemons running on the Node.
2626	"daemonEndpoints"?: #NodeDaemonEndpoints
2627
2628	// DeclaredFeatures represents the features related to feature gates that are declared by the node.
2629	"declaredFeatures"?: [...string]
2630
2631	// Features describes the set of features implemented by the CRI implementation.
2632	"features"?: #NodeFeatures
2633
2634	// List of container images on this node
2635	"images"?: [...#ContainerImage]
2636
2637	// Set of ids/uuids to uniquely identify the node. More info:
2638	// https://kubernetes.io/docs/reference/node/node-status/#info
2639	"nodeInfo"?: #NodeSystemInfo
2640
2641	// NodePhase is the recently observed lifecycle phase of the node. More info:
2642	// https://kubernetes.io/docs/concepts/nodes/node/#phase The field is never
2643	// populated, and now is deprecated.
2644	"phase"?: string
2645
2646	// The available runtime handlers.
2647	"runtimeHandlers"?: [...#NodeRuntimeHandler]
2648
2649	// List of volumes that are attached to the node.
2650	"volumesAttached"?: [...#AttachedVolume]
2651
2652	// List of attachable volumes in use (mounted) by the node.
2653	"volumesInUse"?: [...string]
2654}
2655
2656// NodeSwapStatus represents swap memory information.
2657#NodeSwapStatus: {
2658	// Total amount of swap memory in bytes.
2659	"capacity"?: int64 & int
2660}
2661
2662// NodeSystemInfo is a set of ids/uuids to uniquely identify the node.
2663#NodeSystemInfo: {
2664	// The Architecture reported by the node
2665	"architecture"!: string
2666
2667	// Boot ID reported by the node.
2668	"bootID"!: string
2669
2670	// ContainerRuntime Version reported by the node through runtime remote API
2671	// (e.g. containerd://1.4.2).
2672	"containerRuntimeVersion"!: string
2673
2674	// Kernel Version reported by the node from 'uname -r' (e.g. 3.16.0-0.bpo.4-amd64).
2675	"kernelVersion"!: string
2676
2677	// Deprecated: KubeProxy Version reported by the node.
2678	"kubeProxyVersion"!: string
2679
2680	// Kubelet Version reported by the node.
2681	"kubeletVersion"!: string
2682
2683	// MachineID reported by the node. For unique machine identification in the
2684	// cluster this field is preferred. Learn more from man(5) machine-id:
2685	// http://man7.org/linux/man-pages/man5/machine-id.5.html
2686	"machineID"!: string
2687
2688	// The Operating System reported by the node
2689	"operatingSystem"!: string
2690
2691	// OS Image reported by the node from /etc/os-release (e.g. Debian GNU/Linux 7 (wheezy)).
2692	"osImage"!: string
2693
2694	// Swap Info reported by the node.
2695	"swap"?: #NodeSwapStatus
2696
2697	// SystemUUID reported by the node. For unique machine identification MachineID
2698	// is preferred. This field is specific to Red Hat hosts
2699	// https://access.redhat.com/documentation/en-us/red_hat_subscription_management/1/html/rhsm/uuid
2700	"systemUUID"!: string
2701}
2702
2703// ObjectFieldSelector selects an APIVersioned field of an object.
2704#ObjectFieldSelector: {
2705	// Version of the schema the FieldPath is written in terms of, defaults to "v1".
2706	"apiVersion"?: string
2707
2708	// Path of the field to select in the specified API version.
2709	"fieldPath"!: string
2710}
2711
2712// ObjectReference contains enough information to let you inspect or modify the referred object.
2713#ObjectReference: {
2714	// API version of the referent.
2715	"apiVersion"?: string
2716
2717	// If referring to a piece of an object instead of an entire object, this string
2718	// should contain a valid JSON/Go field access statement, such as
2719	// desiredState.manifest.containers[2]. For example, if the object reference is
2720	// to a container within a pod, this would take on a value like:
2721	// "spec.containers{name}" (where "name" refers to the name of the container
2722	// that triggered the event) or if no container name is specified
2723	// "spec.containers[2]" (container with index 2 in this pod). This syntax is
2724	// chosen only to have some well-defined way of referencing a part of an
2725	// object.
2726	"fieldPath"?: string
2727
2728	// Kind of the referent. More info:
2729	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2730	"kind"?: string
2731
2732	// Name of the referent. More info:
2733	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
2734	"name"?: string
2735
2736	// Namespace of the referent. More info:
2737	// https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
2738	"namespace"?: string
2739
2740	// Specific resourceVersion to which this reference is made, if any. More info:
2741	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
2742	"resourceVersion"?: string
2743
2744	// UID of the referent. More info:
2745	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
2746	"uid"?: string
2747}
2748
2749// PersistentVolume (PV) is a storage resource provisioned by an administrator.
2750// It is analogous to a node. More info:
2751// https://kubernetes.io/docs/concepts/storage/persistent-volumes
2752#PersistentVolume: {
2753	// APIVersion defines the versioned schema of this representation of an object.
2754	// Servers should convert recognized schemas to the latest internal value, and
2755	// may reject unrecognized values. More info:
2756	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2757	"apiVersion": "v1"
2758
2759	// Kind is a string value representing the REST resource this object represents.
2760	// Servers may infer this from the endpoint the client submits requests to.
2761	// Cannot be updated. In CamelCase. More info:
2762	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2763	"kind": "PersistentVolume"
2764
2765	// Standard object's metadata. More info:
2766	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2767	"metadata"?: v1.#ObjectMeta
2768
2769	// spec defines a specification of a persistent volume owned by the cluster.
2770	// Provisioned by an administrator. More info:
2771	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistent-volumes
2772	"spec"?: #PersistentVolumeSpec
2773
2774	// status represents the current information/status for the persistent volume.
2775	// Populated by the system. Read-only. More info:
2776	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistent-volumes
2777	"status"?: #PersistentVolumeStatus
2778}
2779
2780// PersistentVolumeClaim is a user's request for and claim to a persistent volume
2781#PersistentVolumeClaim: {
2782	// APIVersion defines the versioned schema of this representation of an object.
2783	// Servers should convert recognized schemas to the latest internal value, and
2784	// may reject unrecognized values. More info:
2785	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2786	"apiVersion": "v1"
2787
2788	// Kind is a string value representing the REST resource this object represents.
2789	// Servers may infer this from the endpoint the client submits requests to.
2790	// Cannot be updated. In CamelCase. More info:
2791	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2792	"kind": "PersistentVolumeClaim"
2793
2794	// Standard object's metadata. More info:
2795	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
2796	"metadata"?: v1.#ObjectMeta
2797
2798	// spec defines the desired characteristics of a volume requested by a pod
2799	// author. More info:
2800	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
2801	"spec"?: #PersistentVolumeClaimSpec
2802
2803	// status represents the current information/status of a persistent volume
2804	// claim. Read-only. More info:
2805	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
2806	"status"?: #PersistentVolumeClaimStatus
2807}
2808
2809// PersistentVolumeClaimCondition contains details about state of pvc
2810#PersistentVolumeClaimCondition: {
2811	// lastProbeTime is the time we probed the condition.
2812	"lastProbeTime"?: v1.#Time
2813
2814	// lastTransitionTime is the time the condition transitioned from one status to another.
2815	"lastTransitionTime"?: v1.#Time
2816
2817	// message is the human-readable message indicating details about last transition.
2818	"message"?: string
2819
2820	// reason is a unique, this should be a short, machine understandable string
2821	// that gives the reason for condition's last transition. If it reports
2822	// "Resizing" that means the underlying persistent volume is being resized.
2823	"reason"?: string
2824
2825	// Status is the status of the condition. Can be True, False, Unknown. More
2826	// info:
2827	// https://kubernetes.io/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-claim-v1/#:~:text=state%20of%20pvc-,conditions.status,-(string)%2C%20required
2828	"status"!: string
2829
2830	// Type is the type of the condition. More info:
2831	// https://kubernetes.io/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-claim-v1/#:~:text=set%20to%20%27ResizeStarted%27.-,PersistentVolumeClaimCondition,-contains%20details%20about
2832	"type"!: string
2833}
2834
2835// PersistentVolumeClaimList is a list of PersistentVolumeClaim items.
2836#PersistentVolumeClaimList: {
2837	// APIVersion defines the versioned schema of this representation of an object.
2838	// Servers should convert recognized schemas to the latest internal value, and
2839	// may reject unrecognized values. More info:
2840	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
2841	"apiVersion": "v1"
2842
2843	// items is a list of persistent volume claims. More info:
2844	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
2845	"items"!: [...#PersistentVolumeClaim]
2846
2847	// Kind is a string value representing the REST resource this object represents.
2848	// Servers may infer this from the endpoint the client submits requests to.
2849	// Cannot be updated. In CamelCase. More info:
2850	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2851	"kind": "PersistentVolumeClaimList"
2852
2853	// Standard list metadata. More info:
2854	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
2855	"metadata"?: v1.#ListMeta
2856}
2857
2858// PersistentVolumeClaimSpec describes the common attributes of storage devices
2859// and allows a Source for provider-specific attributes
2860#PersistentVolumeClaimSpec: {
2861	// accessModes contains the desired access modes the volume should have. More
2862	// info:
2863	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
2864	"accessModes"?: [...string]
2865
2866	// dataSource field can be used to specify either: * An existing VolumeSnapshot
2867	// object (snapshot.storage.k8s.io/VolumeSnapshot) * An existing PVC
2868	// (PersistentVolumeClaim) If the provisioner or an external controller can
2869	// support the specified data source, it will create a new volume based on the
2870	// contents of the specified data source. When the AnyVolumeDataSource feature
2871	// gate is enabled, dataSource contents will be copied to dataSourceRef, and
2872	// dataSourceRef contents will be copied to dataSource when
2873	// dataSourceRef.namespace is not specified. If the namespace is specified,
2874	// then dataSourceRef will not be copied to dataSource.
2875	"dataSource"?: #TypedLocalObjectReference
2876
2877	// dataSourceRef specifies the object from which to populate the volume with
2878	// data, if a non-empty volume is desired. This may be any object from a
2879	// non-empty API group (non core object) or a PersistentVolumeClaim object.
2880	// When this field is specified, volume binding will only succeed if the type
2881	// of the specified object matches some installed volume populator or dynamic
2882	// provisioner. This field will replace the functionality of the dataSource
2883	// field and as such if both fields are non-empty, they must have the same
2884	// value. For backwards compatibility, when namespace isn't specified in
2885	// dataSourceRef, both fields (dataSource and dataSourceRef) will be set to the
2886	// same value automatically if one of them is empty and the other is non-empty.
2887	// When namespace is specified in dataSourceRef, dataSource isn't set to the
2888	// same value and must be empty. There are three important differences between
2889	// dataSource and dataSourceRef: * While dataSource only allows two specific
2890	// types of objects, dataSourceRef
2891	// allows any non-core object, as well as PersistentVolumeClaim objects.
2892	// * While dataSource ignores disallowed values (dropping them), dataSourceRef
2893	// preserves all values, and generates an error if a disallowed value is
2894	// specified.
2895	// * While dataSource only allows local objects, dataSourceRef allows objects
2896	// in any namespaces.
2897	// (Beta) Using this field requires the AnyVolumeDataSource feature gate to be
2898	// enabled. (Alpha) Using the namespace field of dataSourceRef requires the
2899	// CrossNamespaceVolumeDataSource feature gate to be enabled.
2900	"dataSourceRef"?: #TypedObjectReference
2901
2902	// resources represents the minimum resources the volume should have. Users are
2903	// allowed to specify resource requirements that are lower than previous value
2904	// but must still be higher than capacity recorded in the status field of the
2905	// claim. More info:
2906	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources
2907	"resources"?: #VolumeResourceRequirements
2908
2909	// selector is a label query over volumes to consider for binding.
2910	"selector"?: v1.#LabelSelector
2911
2912	// storageClassName is the name of the StorageClass required by the claim. More
2913	// info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1
2914	"storageClassName"?: string
2915
2916	// volumeAttributesClassName may be used to set the VolumeAttributesClass used
2917	// by this claim. If specified, the CSI driver will create or update the volume
2918	// with the attributes defined in the corresponding VolumeAttributesClass. This
2919	// has a different purpose than storageClassName, it can be changed after the
2920	// claim is created. An empty string or nil value indicates that no
2921	// VolumeAttributesClass will be applied to the claim. If the claim enters an
2922	// Infeasible error state, this field can be reset to its previous value
2923	// (including nil) to cancel the modification. If the resource referred to by
2924	// volumeAttributesClass does not exist, this PersistentVolumeClaim will be set
2925	// to a Pending state, as reflected by the modifyVolumeStatus field, until such
2926	// as a resource exists. More info:
2927	// https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/
2928	"volumeAttributesClassName"?: string
2929
2930	// volumeMode defines what type of volume is required by the claim. Value of
2931	// Filesystem is implied when not included in claim spec.
2932	"volumeMode"?: string
2933
2934	// volumeName is the binding reference to the PersistentVolume backing this claim.
2935	"volumeName"?: string
2936}
2937
2938// PersistentVolumeClaimStatus is the current status of a persistent volume claim.
2939#PersistentVolumeClaimStatus: {
2940	// accessModes contains the actual access modes the volume backing the PVC has.
2941	// More info:
2942	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
2943	"accessModes"?: [...string]
2944
2945	// allocatedResourceStatuses stores status of resource being resized for the
2946	// given PVC. Key names follow standard Kubernetes label syntax. Valid values
2947	// are either:
2948	// * Un-prefixed keys:
2949	// - storage - the capacity of the volume.
2950	// * Custom resources must use implementation-defined prefixed names such as
2951	// "example.com/my-custom-resource"
2952	// Apart from above values - keys that are unprefixed or have kubernetes.io
2953	// prefix are considered reserved and hence may not be used.
2954	//
2955	// ClaimResourceStatus can be in any of following states:
2956	// - ControllerResizeInProgress:
2957	// State set when resize controller starts resizing the volume in control-plane.
2958	// - ControllerResizeFailed:
2959	// State set when resize has failed in resize controller with a terminal error.
2960	// - NodeResizePending:
2961	// State set when resize controller has finished resizing the volume but further resizing of
2962	// volume is needed on the node.
2963	// - NodeResizeInProgress:
2964	// State set when kubelet starts resizing the volume.
2965	// - NodeResizeFailed:
2966	// State set when resizing has failed in kubelet with a terminal error. Transient errors don't set
2967	// NodeResizeFailed.
2968	// For example: if expanding a PVC for more capacity - this field can be one of
2969	// the following states:
2970	// - pvc.status.allocatedResourceStatus['storage'] = "ControllerResizeInProgress"
2971	// - pvc.status.allocatedResourceStatus['storage'] = "ControllerResizeFailed"
2972	// - pvc.status.allocatedResourceStatus['storage'] = "NodeResizePending"
2973	// - pvc.status.allocatedResourceStatus['storage'] = "NodeResizeInProgress"
2974	// - pvc.status.allocatedResourceStatus['storage'] = "NodeResizeFailed"
2975	// When this field is not set, it means that no resize operation is in progress for the given PVC.
2976	//
2977	// A controller that receives PVC update with previously unknown resourceName or
2978	// ClaimResourceStatus should ignore the update for the purpose it was
2979	// designed. For example - a controller that only is responsible for resizing
2980	// capacity of the volume, should ignore PVC updates that change other valid
2981	// resources associated with PVC.
2982	"allocatedResourceStatuses"?: [string]: string
2983
2984	// allocatedResources tracks the resources allocated to a PVC including its
2985	// capacity. Key names follow standard Kubernetes label syntax. Valid values
2986	// are either:
2987	// * Un-prefixed keys:
2988	// - storage - the capacity of the volume.
2989	// * Custom resources must use implementation-defined prefixed names such as
2990	// "example.com/my-custom-resource"
2991	// Apart from above values - keys that are unprefixed or have kubernetes.io
2992	// prefix are considered reserved and hence may not be used.
2993	//
2994	// Capacity reported here may be larger than the actual capacity when a volume
2995	// expansion operation is requested. For storage quota, the larger value from
2996	// allocatedResources and PVC.spec.resources is used. If allocatedResources is
2997	// not set, PVC.spec.resources alone is used for quota calculation. If a volume
2998	// expansion capacity request is lowered, allocatedResources is only lowered if
2999	// there are no expansion operations in progress and if the actual volume
3000	// capacity is equal or lower than the requested capacity.
3001	//
3002	// A controller that receives PVC update with previously unknown resourceName
3003	// should ignore the update for the purpose it was designed. For example - a
3004	// controller that only is responsible for resizing capacity of the volume,
3005	// should ignore PVC updates that change other valid resources associated with
3006	// PVC.
3007	"allocatedResources"?: [string]: resource.#Quantity
3008
3009	// capacity represents the actual resources of the underlying volume.
3010	"capacity"?: [string]: resource.#Quantity
3011
3012	// conditions is the current Condition of persistent volume claim. If underlying
3013	// persistent volume is being resized then the Condition will be set to
3014	// 'Resizing'.
3015	"conditions"?: [...#PersistentVolumeClaimCondition]
3016
3017	// currentVolumeAttributesClassName is the current name of the
3018	// VolumeAttributesClass the PVC is using. When unset, there is no
3019	// VolumeAttributeClass applied to this PersistentVolumeClaim
3020	"currentVolumeAttributesClassName"?: string
3021
3022	// ModifyVolumeStatus represents the status object of ControllerModifyVolume
3023	// operation. When this is unset, there is no ModifyVolume operation being
3024	// attempted.
3025	"modifyVolumeStatus"?: #ModifyVolumeStatus
3026
3027	// phase represents the current phase of PersistentVolumeClaim.
3028	"phase"?: string
3029}
3030
3031// PersistentVolumeClaimTemplate is used to produce PersistentVolumeClaim
3032// objects as part of an EphemeralVolumeSource.
3033#PersistentVolumeClaimTemplate: {
3034	// May contain labels and annotations that will be copied into the PVC when
3035	// creating it. No other fields are allowed and will be rejected during
3036	// validation.
3037	"metadata"?: v1.#ObjectMeta
3038
3039	// The specification for the PersistentVolumeClaim. The entire content is copied
3040	// unchanged into the PVC that gets created from this template. The same fields
3041	// as in a PersistentVolumeClaim are also valid here.
3042	"spec"!: #PersistentVolumeClaimSpec
3043}
3044
3045// PersistentVolumeClaimVolumeSource references the user's PVC in the same
3046// namespace. This volume finds the bound PV and mounts that volume for the
3047// pod. A PersistentVolumeClaimVolumeSource is, essentially, a wrapper around
3048// another type of volume that is owned by someone else (the system).
3049#PersistentVolumeClaimVolumeSource: {
3050	// claimName is the name of a PersistentVolumeClaim in the same namespace as the
3051	// pod using this volume. More info:
3052	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
3053	"claimName"!: string
3054
3055	// readOnly Will force the ReadOnly setting in VolumeMounts. Default false.
3056	"readOnly"?: bool
3057}
3058
3059// PersistentVolumeList is a list of PersistentVolume items.
3060#PersistentVolumeList: {
3061	// APIVersion defines the versioned schema of this representation of an object.
3062	// Servers should convert recognized schemas to the latest internal value, and
3063	// may reject unrecognized values. More info:
3064	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
3065	"apiVersion": "v1"
3066
3067	// items is a list of persistent volumes. More info:
3068	// https://kubernetes.io/docs/concepts/storage/persistent-volumes
3069	"items"!: [...#PersistentVolume]
3070
3071	// Kind is a string value representing the REST resource this object represents.
3072	// Servers may infer this from the endpoint the client submits requests to.
3073	// Cannot be updated. In CamelCase. More info:
3074	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3075	"kind": "PersistentVolumeList"
3076
3077	// Standard list metadata. More info:
3078	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3079	"metadata"?: v1.#ListMeta
3080}
3081
3082// PersistentVolumeSpec is the specification of a persistent volume.
3083#PersistentVolumeSpec: {
3084	// accessModes contains all ways the volume can be mounted. More info:
3085	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes
3086	"accessModes"?: [...string]
3087
3088	// awsElasticBlockStore represents an AWS Disk resource that is attached to a
3089	// kubelet's host machine and then exposed to the pod. Deprecated:
3090	// AWSElasticBlockStore is deprecated. All operations for the in-tree
3091	// awsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.
3092	// More info:
3093	// https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
3094	"awsElasticBlockStore"?: #AWSElasticBlockStoreVolumeSource
3095
3096	// azureDisk represents an Azure Data Disk mount on the host and bind mount to
3097	// the pod. Deprecated: AzureDisk is deprecated. All operations for the in-tree
3098	// azureDisk type are redirected to the disk.csi.azure.com CSI driver.
3099	"azureDisk"?: #AzureDiskVolumeSource
3100
3101	// azureFile represents an Azure File Service mount on the host and bind mount
3102	// to the pod. Deprecated: AzureFile is deprecated. All operations for the
3103	// in-tree azureFile type are redirected to the file.csi.azure.com CSI driver.
3104	"azureFile"?: #AzureFilePersistentVolumeSource
3105
3106	// capacity is the description of the persistent volume's resources and
3107	// capacity. More info:
3108	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#capacity
3109	"capacity"?: [string]: resource.#Quantity
3110
3111	// cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
3112	// Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer
3113	// supported.
3114	"cephfs"?: #CephFSPersistentVolumeSource
3115
3116	// cinder represents a cinder volume attached and mounted on kubelets host
3117	// machine. Deprecated: Cinder is deprecated. All operations for the in-tree
3118	// cinder type are redirected to the cinder.csi.openstack.org CSI driver. More
3119	// info: https://examples.k8s.io/mysql-cinder-pd/README.md
3120	"cinder"?: #CinderPersistentVolumeSource
3121
3122	// claimRef is part of a bi-directional binding between PersistentVolume and
3123	// PersistentVolumeClaim. Expected to be non-nil when bound. claim.VolumeName
3124	// is the authoritative bind between PV and PVC. More info:
3125	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#binding
3126	"claimRef"?: #ObjectReference
3127
3128	// csi represents storage that is handled by an external CSI driver.
3129	"csi"?: #CSIPersistentVolumeSource
3130
3131	// fc represents a Fibre Channel resource that is attached to a kubelet's host
3132	// machine and then exposed to the pod.
3133	"fc"?: #FCVolumeSource
3134
3135	// flexVolume represents a generic volume resource that is provisioned/attached
3136	// using an exec based plugin. Deprecated: FlexVolume is deprecated. Consider
3137	// using a CSIDriver instead.
3138	"flexVolume"?: #FlexPersistentVolumeSource
3139
3140	// flocker represents a Flocker volume attached to a kubelet's host machine and
3141	// exposed to the pod for its usage. This depends on the Flocker control
3142	// service being running. Deprecated: Flocker is deprecated and the in-tree
3143	// flocker type is no longer supported.
3144	"flocker"?: #FlockerVolumeSource
3145
3146	// gcePersistentDisk represents a GCE Disk resource that is attached to a
3147	// kubelet's host machine and then exposed to the pod. Provisioned by an admin.
3148	// Deprecated: GCEPersistentDisk is deprecated. All operations for the in-tree
3149	// gcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI
3150	// driver. More info:
3151	// https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
3152	"gcePersistentDisk"?: #GCEPersistentDiskVolumeSource
3153
3154	// glusterfs represents a Glusterfs volume that is attached to a host and
3155	// exposed to the pod. Provisioned by an admin. Deprecated: Glusterfs is
3156	// deprecated and the in-tree glusterfs type is no longer supported. More info:
3157	// https://examples.k8s.io/volumes/glusterfs/README.md
3158	"glusterfs"?: #GlusterfsPersistentVolumeSource
3159
3160	// hostPath represents a directory on the host. Provisioned by a developer or
3161	// tester. This is useful for single-node development and testing only! On-host
3162	// storage is not supported in any way and WILL NOT WORK in a multi-node
3163	// cluster. More info:
3164	// https://kubernetes.io/docs/concepts/storage/volumes#hostpath
3165	"hostPath"?: #HostPathVolumeSource
3166
3167	// iscsi represents an ISCSI Disk resource that is attached to a kubelet's host
3168	// machine and then exposed to the pod. Provisioned by an admin.
3169	"iscsi"?: #ISCSIPersistentVolumeSource
3170
3171	// local represents directly-attached storage with node affinity
3172	"local"?: #LocalVolumeSource
3173
3174	// mountOptions is the list of mount options, e.g. ["ro", "soft"]. Not validated
3175	// - mount will simply fail if one is invalid. More info:
3176	// https://kubernetes.io/docs/concepts/storage/persistent-volumes/#mount-options
3177	"mountOptions"?: [...string]
3178
3179	// nfs represents an NFS mount on the host. Provisioned by an admin. More info:
3180	// https://kubernetes.io/docs/concepts/storage/volumes#nfs
3181	"nfs"?: #NFSVolumeSource
3182
3183	// nodeAffinity defines constraints that limit what nodes this volume can be
3184	// accessed from. This field influences the scheduling of pods that use this
3185	// volume. This field is mutable if MutablePVNodeAffinity feature gate is
3186	// enabled.
3187	"nodeAffinity"?: #VolumeNodeAffinity
3188
3189	// persistentVolumeReclaimPolicy defines what happens to a persistent volume
3190	// when released from its claim. Valid options are Retain (default for manually
3191	// created PersistentVolumes), Delete (default for dynamically provisioned
3192	// PersistentVolumes), and Recycle (deprecated). Recycle must be supported by
3193	// the volume plugin underlying this PersistentVolume. More info:
3194	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#reclaiming
3195	"persistentVolumeReclaimPolicy"?: string
3196
3197	// photonPersistentDisk represents a PhotonController persistent disk attached
3198	// and mounted on kubelets host machine. Deprecated: PhotonPersistentDisk is
3199	// deprecated and the in-tree photonPersistentDisk type is no longer supported.
3200	"photonPersistentDisk"?: #PhotonPersistentDiskVolumeSource
3201
3202	// portworxVolume represents a portworx volume attached and mounted on kubelets
3203	// host machine. Deprecated: PortworxVolume is deprecated. All operations for
3204	// the in-tree portworxVolume type are redirected to the pxd.portworx.com CSI
3205	// driver.
3206	"portworxVolume"?: #PortworxVolumeSource
3207
3208	// quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
3209	// Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer
3210	// supported.
3211	"quobyte"?: #QuobyteVolumeSource
3212
3213	// rbd represents a Rados Block Device mount on the host that shares a pod's
3214	// lifetime. Deprecated: RBD is deprecated and the in-tree rbd type is no
3215	// longer supported. More info: https://examples.k8s.io/volumes/rbd/README.md
3216	"rbd"?: #RBDPersistentVolumeSource
3217
3218	// scaleIO represents a ScaleIO persistent volume attached and mounted on
3219	// Kubernetes nodes. Deprecated: ScaleIO is deprecated and the in-tree scaleIO
3220	// type is no longer supported.
3221	"scaleIO"?: #ScaleIOPersistentVolumeSource
3222
3223	// storageClassName is the name of StorageClass to which this persistent volume
3224	// belongs. Empty value means that this volume does not belong to any
3225	// StorageClass.
3226	"storageClassName"?: string
3227
3228	// storageOS represents a StorageOS volume that is attached to the kubelet's
3229	// host machine and mounted into the pod. Deprecated: StorageOS is deprecated
3230	// and the in-tree storageos type is no longer supported. More info:
3231	// https://examples.k8s.io/volumes/storageos/README.md
3232	"storageos"?: #StorageOSPersistentVolumeSource
3233
3234	// Name of VolumeAttributesClass to which this persistent volume belongs. Empty
3235	// value is not allowed. When this field is not set, it indicates that this
3236	// volume does not belong to any VolumeAttributesClass. This field is mutable
3237	// and can be changed by the CSI driver after a volume has been updated
3238	// successfully to a new class. For an unbound PersistentVolume, the
3239	// volumeAttributesClassName will be matched with unbound
3240	// PersistentVolumeClaims during the binding process.
3241	"volumeAttributesClassName"?: string
3242
3243	// volumeMode defines if a volume is intended to be used with a formatted
3244	// filesystem or to remain in raw block state. Value of Filesystem is implied
3245	// when not included in spec.
3246	"volumeMode"?: string
3247
3248	// vsphereVolume represents a vSphere volume attached and mounted on kubelets
3249	// host machine. Deprecated: VsphereVolume is deprecated. All operations for
3250	// the in-tree vsphereVolume type are redirected to the csi.vsphere.vmware.com
3251	// CSI driver.
3252	"vsphereVolume"?: #VsphereVirtualDiskVolumeSource
3253}
3254
3255// PersistentVolumeStatus is the current status of a persistent volume.
3256#PersistentVolumeStatus: {
3257	// lastPhaseTransitionTime is the time the phase transitioned from one to
3258	// another and automatically resets to current time everytime a volume phase
3259	// transitions.
3260	"lastPhaseTransitionTime"?: v1.#Time
3261
3262	// message is a human-readable message indicating details about why the volume is in this state.
3263	"message"?: string
3264
3265	// phase indicates if a volume is available, bound to a claim, or released by a
3266	// claim. More info:
3267	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#phase
3268	"phase"?: string
3269
3270	// reason is a brief CamelCase string that describes any failure and is meant
3271	// for machine parsing and tidy display in the CLI.
3272	"reason"?: string
3273}
3274
3275// Represents a Photon Controller persistent disk resource.
3276#PhotonPersistentDiskVolumeSource: {
3277	// fsType is the filesystem type to mount. Must be a filesystem type supported
3278	// by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
3279	// to be "ext4" if unspecified.
3280	"fsType"?: string
3281
3282	// pdID is the ID that identifies Photon Controller persistent disk
3283	"pdID"!: string
3284}
3285
3286// Pod is a collection of containers that can run on a host. This resource is
3287// created by clients and scheduled onto hosts.
3288#Pod: {
3289	// APIVersion defines the versioned schema of this representation of an object.
3290	// Servers should convert recognized schemas to the latest internal value, and
3291	// may reject unrecognized values. More info:
3292	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
3293	"apiVersion": "v1"
3294
3295	// Kind is a string value representing the REST resource this object represents.
3296	// Servers may infer this from the endpoint the client submits requests to.
3297	// Cannot be updated. In CamelCase. More info:
3298	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3299	"kind": "Pod"
3300
3301	// Standard object's metadata. More info:
3302	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
3303	"metadata"?: v1.#ObjectMeta
3304
3305	// Specification of the desired behavior of the pod. More info:
3306	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
3307	"spec"?: #PodSpec
3308
3309	// Most recently observed status of the pod. This data may not be up to date.
3310	// Populated by the system. Read-only. More info:
3311	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
3312	"status"?: #PodStatus
3313}
3314
3315// Pod affinity is a group of inter pod affinity scheduling rules.
3316#PodAffinity: {
3317	// The scheduler will prefer to schedule pods to nodes that satisfy the affinity
3318	// expressions specified by this field, but it may choose a node that violates
3319	// one or more of the expressions. The node that is most preferred is the one
3320	// with the greatest sum of weights, i.e. for each node that meets all of the
3321	// scheduling requirements (resource request, requiredDuringScheduling affinity
3322	// expressions, etc.), compute a sum by iterating through the elements of this
3323	// field and adding "weight" to the sum if the node has pods which matches the
3324	// corresponding podAffinityTerm; the node(s) with the highest sum are the most
3325	// preferred.
3326	"preferredDuringSchedulingIgnoredDuringExecution"?: [...#WeightedPodAffinityTerm]
3327
3328	// If the affinity requirements specified by this field are not met at
3329	// scheduling time, the pod will not be scheduled onto the node. If the
3330	// affinity requirements specified by this field cease to be met at some point
3331	// during pod execution (e.g. due to a pod label update), the system may or may
3332	// not try to eventually evict the pod from its node. When there are multiple
3333	// elements, the lists of nodes corresponding to each podAffinityTerm are
3334	// intersected, i.e. all terms must be satisfied.
3335	"requiredDuringSchedulingIgnoredDuringExecution"?: [...#PodAffinityTerm]
3336}
3337
3338// Defines a set of pods (namely those matching the labelSelector relative to
3339// the given namespace(s)) that this pod should be co-located (affinity) or not
3340// co-located (anti-affinity) with, where co-located is defined as running on a
3341// node whose value of the label with key <topologyKey> matches that of any
3342// node on which a pod of the set of pods is running
3343#PodAffinityTerm: {
3344	// A label query over a set of resources, in this case pods. If it's null, this
3345	// PodAffinityTerm matches with no Pods.
3346	"labelSelector"?: v1.#LabelSelector
3347
3348	// MatchLabelKeys is a set of pod label keys to select which pods will be taken
3349	// into consideration. The keys are used to lookup values from the incoming pod
3350	// labels, those key-value labels are merged with `labelSelector` as `key in
3351	// (value)` to select the group of existing pods which pods will be taken into
3352	// consideration for the incoming pod's pod (anti) affinity. Keys that don't
3353	// exist in the incoming pod labels will be ignored. The default value is
3354	// empty. The same key is forbidden to exist in both matchLabelKeys and
3355	// labelSelector. Also, matchLabelKeys cannot be set when labelSelector isn't
3356	// set.
3357	"matchLabelKeys"?: [...string]
3358
3359	// MismatchLabelKeys is a set of pod label keys to select which pods will be
3360	// taken into consideration. The keys are used to lookup values from the
3361	// incoming pod labels, those key-value labels are merged with `labelSelector`
3362	// as `key notin (value)` to select the group of existing pods which pods will
3363	// be taken into consideration for the incoming pod's pod (anti) affinity. Keys
3364	// that don't exist in the incoming pod labels will be ignored. The default
3365	// value is empty. The same key is forbidden to exist in both mismatchLabelKeys
3366	// and labelSelector. Also, mismatchLabelKeys cannot be set when labelSelector
3367	// isn't set.
3368	"mismatchLabelKeys"?: [...string]
3369
3370	// A label query over the set of namespaces that the term applies to. The term
3371	// is applied to the union of the namespaces selected by this field and the
3372	// ones listed in the namespaces field. null selector and null or empty
3373	// namespaces list means "this pod's namespace". An empty selector ({}) matches
3374	// all namespaces.
3375	"namespaceSelector"?: v1.#LabelSelector
3376
3377	// namespaces specifies a static list of namespace names that the term applies
3378	// to. The term is applied to the union of the namespaces listed in this field
3379	// and the ones selected by namespaceSelector. null or empty namespaces list
3380	// and null namespaceSelector means "this pod's namespace".
3381	"namespaces"?: [...string]
3382
3383	// This pod should be co-located (affinity) or not co-located (anti-affinity)
3384	// with the pods matching the labelSelector in the specified namespaces, where
3385	// co-located is defined as running on a node whose value of the label with key
3386	// topologyKey matches that of any node on which any of the selected pods is
3387	// running. Empty topologyKey is not allowed.
3388	"topologyKey"!: string
3389}
3390
3391// Pod anti affinity is a group of inter pod anti affinity scheduling rules.
3392#PodAntiAffinity: {
3393	// The scheduler will prefer to schedule pods to nodes that satisfy the
3394	// anti-affinity expressions specified by this field, but it may choose a node
3395	// that violates one or more of the expressions. The node that is most
3396	// preferred is the one with the greatest sum of weights, i.e. for each node
3397	// that meets all of the scheduling requirements (resource request,
3398	// requiredDuringScheduling anti-affinity expressions, etc.), compute a sum by
3399	// iterating through the elements of this field and subtracting "weight" from
3400	// the sum if the node has pods which matches the corresponding
3401	// podAffinityTerm; the node(s) with the highest sum are the most preferred.
3402	"preferredDuringSchedulingIgnoredDuringExecution"?: [...#WeightedPodAffinityTerm]
3403
3404	// If the anti-affinity requirements specified by this field are not met at
3405	// scheduling time, the pod will not be scheduled onto the node. If the
3406	// anti-affinity requirements specified by this field cease to be met at some
3407	// point during pod execution (e.g. due to a pod label update), the system may
3408	// or may not try to eventually evict the pod from its node. When there are
3409	// multiple elements, the lists of nodes corresponding to each podAffinityTerm
3410	// are intersected, i.e. all terms must be satisfied.
3411	"requiredDuringSchedulingIgnoredDuringExecution"?: [...#PodAffinityTerm]
3412}
3413
3414// PodCertificateProjection provides a private key and X.509 certificate in the pod filesystem.
3415#PodCertificateProjection: {
3416	// Write the certificate chain at this path in the projected volume.
3417	//
3418	// Most applications should use credentialBundlePath. When using keyPath and
3419	// certificateChainPath, your application needs to check that the key and leaf
3420	// certificate are consistent, because it is possible to read the files
3421	// mid-rotation.
3422	"certificateChainPath"?: string
3423
3424	// Write the credential bundle at this path in the projected volume.
3425	//
3426	// The credential bundle is a single file that contains multiple PEM blocks. The
3427	// first PEM block is a PRIVATE KEY block, containing a PKCS#8 private key.
3428	//
3429	// The remaining blocks are CERTIFICATE blocks, containing the issued
3430	// certificate chain from the signer (leaf and any intermediates).
3431	//
3432	// Using credentialBundlePath lets your Pod's application code make a single
3433	// atomic read that retrieves a consistent key and certificate chain. If you
3434	// project them to separate files, your application code will need to
3435	// additionally check that the leaf certificate was issued to the key.
3436	"credentialBundlePath"?: string
3437
3438	// Write the key at this path in the projected volume.
3439	//
3440	// Most applications should use credentialBundlePath. When using keyPath and
3441	// certificateChainPath, your application needs to check that the key and leaf
3442	// certificate are consistent, because it is possible to read the files
3443	// mid-rotation.
3444	"keyPath"?: string
3445
3446	// The type of keypair Kubelet will generate for the pod.
3447	//
3448	// Valid values are "RSA3072", "RSA4096", "ECDSAP256", "ECDSAP384", "ECDSAP521", and "ED25519".
3449	"keyType"!: string
3450
3451	// maxExpirationSeconds is the maximum lifetime permitted for the certificate.
3452	//
3453	// Kubelet copies this value verbatim into the PodCertificateRequests it
3454	// generates for this projection.
3455	//
3456	// If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver
3457	// will reject values shorter than 3600 (1 hour). The maximum allowable value
3458	// is 7862400 (91 days).
3459	//
3460	// The signer implementation is then free to issue a certificate with any
3461	// lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600
3462	// seconds (1 hour). This constraint is enforced by kube-apiserver.
3463	// `kubernetes.io` signers will never issue certificates with a lifetime longer
3464	// than 24 hours.
3465	"maxExpirationSeconds"?: int32 & int
3466
3467	// Kubelet's generated CSRs will be addressed to this signer.
3468	"signerName"!: string
3469
3470	// userAnnotations allow pod authors to pass additional information to the
3471	// signer implementation. Kubernetes does not restrict or validate this
3472	// metadata in any way.
3473	//
3474	// These values are copied verbatim into the `spec.unverifiedUserAnnotations`
3475	// field of the PodCertificateRequest objects that Kubelet creates.
3476	//
3477	// Entries are subject to the same validation as object metadata annotations,
3478	// with the addition that all keys must be domain-prefixed. No restrictions are
3479	// placed on values, except an overall size limitation on the entire field.
3480	//
3481	// Signers should document the keys and values they support. Signers should deny
3482	// requests that contain keys they do not recognize.
3483	"userAnnotations"?: [string]: string
3484}
3485
3486// PodCondition contains details for the current condition of this pod.
3487#PodCondition: {
3488	// Last time we probed the condition.
3489	"lastProbeTime"?: v1.#Time
3490
3491	// Last time the condition transitioned from one status to another.
3492	"lastTransitionTime"?: v1.#Time
3493
3494	// Human-readable message indicating details about last transition.
3495	"message"?: string
3496
3497	// If set, this represents the .metadata.generation that the pod condition was set based upon.
3498	"observedGeneration"?: int64 & int
3499
3500	// Unique, one-word, CamelCase reason for the condition's last transition.
3501	"reason"?: string
3502
3503	// Status is the status of the condition. Can be True, False, Unknown. More
3504	// info:
3505	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-conditions
3506	"status"!: string
3507
3508	// Type is the type of the condition. More info:
3509	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-conditions
3510	"type"!: string
3511}
3512
3513// PodDNSConfig defines the DNS parameters of a pod in addition to those generated from DNSPolicy.
3514#PodDNSConfig: {
3515	// A list of DNS name server IP addresses. This will be appended to the base
3516	// nameservers generated from DNSPolicy. Duplicated nameservers will be
3517	// removed.
3518	"nameservers"?: [...string]
3519
3520	// A list of DNS resolver options. This will be merged with the base options
3521	// generated from DNSPolicy. Duplicated entries will be removed. Resolution
3522	// options given in Options will override those that appear in the base
3523	// DNSPolicy.
3524	"options"?: [...#PodDNSConfigOption]
3525
3526	// A list of DNS search domains for host-name lookup. This will be appended to
3527	// the base search paths generated from DNSPolicy. Duplicated search paths will
3528	// be removed.
3529	"searches"?: [...string]
3530}
3531
3532// PodDNSConfigOption defines DNS resolver options of a pod.
3533#PodDNSConfigOption: {
3534	// Name is this DNS resolver option's name. Required.
3535	"name"?: string
3536
3537	// Value is this DNS resolver option's value.
3538	"value"?: string
3539}
3540
3541// PodExtendedResourceClaimStatus is stored in the PodStatus for the extended
3542// resource requests backed by DRA. It stores the generated name for the
3543// corresponding special ResourceClaim created by the scheduler.
3544#PodExtendedResourceClaimStatus: {
3545	// RequestMappings identifies the mapping of <container, extended resource
3546	// backed by DRA> to device request in the generated ResourceClaim.
3547	"requestMappings"!: [...#ContainerExtendedResourceRequest]
3548
3549	// ResourceClaimName is the name of the ResourceClaim that was generated for the
3550	// Pod in the namespace of the Pod.
3551	"resourceClaimName"!: string
3552}
3553
3554// PodIP represents a single IP address allocated to the pod.
3555#PodIP: {
3556	// IP is the IP address assigned to the pod
3557	"ip"!: string
3558}
3559
3560// PodList is a list of Pods.
3561#PodList: {
3562	// APIVersion defines the versioned schema of this representation of an object.
3563	// Servers should convert recognized schemas to the latest internal value, and
3564	// may reject unrecognized values. More info:
3565	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
3566	"apiVersion": "v1"
3567
3568	// List of pods. More info:
3569	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
3570	"items"!: [...#Pod]
3571
3572	// Kind is a string value representing the REST resource this object represents.
3573	// Servers may infer this from the endpoint the client submits requests to.
3574	// Cannot be updated. In CamelCase. More info:
3575	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3576	"kind": "PodList"
3577
3578	// Standard list metadata. More info:
3579	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
3580	"metadata"?: v1.#ListMeta
3581}
3582
3583// PodOS defines the OS parameters of a pod.
3584#PodOS: {
3585	// Name is the name of the operating system. The currently supported values are
3586	// linux and windows. Additional value may be defined in future and can be one
3587	// of:
3588	// https://github.com/opencontainers/runtime-spec/blob/master/config.md#platform-specific-configuration
3589	// Clients should expect to handle additional values and treat unrecognized
3590	// values in this field as os: null
3591	"name"!: string
3592}
3593
3594// PodReadinessGate contains the reference to a pod condition
3595#PodReadinessGate: {
3596	// ConditionType refers to a condition in the pod's condition list with matching type.
3597	"conditionType"!: string
3598}
3599
3600// PodResourceClaim references exactly one ResourceClaim, either directly or by
3601// naming a ResourceClaimTemplate which is then turned into a ResourceClaim for
3602// the pod.
3603//
3604// It adds a name to it that uniquely identifies the ResourceClaim inside the
3605// Pod. Containers that need access to the ResourceClaim reference it with this
3606// name.
3607//
3608// When the DRAWorkloadResourceClaims feature gate is enabled and this Pod
3609// belongs to a PodGroup, a PodResourceClaim is matched to a
3610// PodGroupResourceClaim if all of their fields are equal (Name,
3611// ResourceClaimName, and ResourceClaimTemplateName). A matched claim
3612// references a single ResourceClaim shared across all Pods in the PodGroup,
3613// reserved for the PodGroup in ResourceClaimStatus.ReservedFor rather than for
3614// individual Pods.
3615#PodResourceClaim: {
3616	// Name uniquely identifies this resource claim inside the pod. This must be a DNS_LABEL.
3617	"name"!: string
3618
3619	// ResourceClaimName is the name of a ResourceClaim object in the same namespace as this pod.
3620	//
3621	// Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
3622	"resourceClaimName"?: string
3623
3624	// ResourceClaimTemplateName is the name of a ResourceClaimTemplate object in
3625	// the same namespace as this pod.
3626	//
3627	// The template will be used to create a new ResourceClaim, which will be bound
3628	// to this pod. When this pod is deleted, the ResourceClaim will also be
3629	// deleted. The pod name and resource name, along with a generated component,
3630	// will be used to form a unique name for the ResourceClaim, which will be
3631	// recorded in pod.status.resourceClaimStatuses.
3632	//
3633	// When the DRAWorkloadResourceClaims feature gate is enabled and the pod
3634	// belongs to a PodGroup that defines a PodGroupResourceClaim with the same
3635	// Name and ResourceClaimTemplateName, this PodResourceClaim resolves to the
3636	// ResourceClaim generated for the PodGroup. All pods in the group that define
3637	// an equivalent PodResourceClaim matching the PodGroupResourceClaim's Name and
3638	// ResourceClaimTemplateName share the same generated ResourceClaim.
3639	// ResourceClaims generated for a PodGroup are owned by the PodGroup and their
3640	// lifecycles are tied to the PodGroup instead of any individual pod.
3641	//
3642	// This field is immutable and no changes will be made to the corresponding
3643	// ResourceClaim by the control plane after creating the ResourceClaim.
3644	//
3645	// Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
3646	"resourceClaimTemplateName"?: string
3647}
3648
3649// PodResourceClaimStatus is stored in the PodStatus for each PodResourceClaim
3650// which references a ResourceClaimTemplate. It stores the generated name for
3651// the corresponding ResourceClaim.
3652#PodResourceClaimStatus: {
3653	// Name uniquely identifies this resource claim inside the pod. This must match
3654	// the name of an entry in pod.spec.resourceClaims, which implies that the
3655	// string must be a DNS_LABEL.
3656	"name"!: string
3657
3658	// ResourceClaimName is the name of the ResourceClaim that was generated for the
3659	// Pod in the namespace of the Pod.
3660	//
3661	// When the DRAWorkloadResourceClaims feature is enabled and the corresponding
3662	// PodResourceClaim matches a PodGroupResourceClaim made by the Pod's PodGroup,
3663	// then this is the name of the ResourceClaim generated and reserved for the
3664	// PodGroup.
3665	//
3666	// If this is unset, then generating a ResourceClaim was not necessary. The
3667	// pod.spec.resourceClaims entry can be ignored in this case.
3668	"resourceClaimName"?: string
3669}
3670
3671// PodSchedulingGate is associated to a Pod to guard its scheduling.
3672#PodSchedulingGate: {
3673	// Name of the scheduling gate. Each scheduling gate must have a unique name field.
3674	"name"!: string
3675}
3676
3677// PodSchedulingGroup identifies the runtime scheduling group instance that a
3678// Pod belongs to. The scheduler uses this information to apply workload-aware
3679// scheduling semantics. Exactly one field must be specified.
3680#PodSchedulingGroup: {
3681	// PodGroupName specifies the name of the standalone PodGroup object that
3682	// represents the runtime instance of this group. Must be a DNS subdomain.
3683	"podGroupName"?: string
3684}
3685
3686// PodSecurityContext holds pod-level security attributes and common container
3687// settings. Some fields are also present in container.securityContext. Field
3688// values of container.securityContext take precedence over field values of
3689// PodSecurityContext.
3690#PodSecurityContext: {
3691	// appArmorProfile is the AppArmor options to use by the containers in this pod.
3692	// Note that this field cannot be set when spec.os.name is windows.
3693	"appArmorProfile"?: #AppArmorProfile
3694
3695	// A special supplemental group that applies to all containers in a pod. Some
3696	// volume types allow the Kubelet to change the ownership of that volume to be
3697	// owned by the pod:
3698	//
3699	// 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files
3700	// created in the volume will be owned by FSGroup) 3. The permission bits are
3701	// OR'd with rw-rw----
3702	//
3703	// If unset, the Kubelet will not modify the ownership and permissions of any
3704	// volume. Note that this field cannot be set when spec.os.name is windows.
3705	"fsGroup"?: int64 & int
3706
3707	// fsGroupChangePolicy defines behavior of changing ownership and permission of
3708	// the volume before being exposed inside Pod. This field will only apply to
3709	// volume types which support fsGroup based ownership(and permissions). It will
3710	// have no effect on ephemeral volume types such as: secret, configmaps and
3711	// emptydir. Valid values are "OnRootMismatch" and "Always". If not specified,
3712	// "Always" is used. Note that this field cannot be set when spec.os.name is
3713	// windows.
3714	"fsGroupChangePolicy"?: string
3715
3716	// The GID to run the entrypoint of the container process. Uses runtime default
3717	// if unset. May also be set in SecurityContext. If set in both SecurityContext
3718	// and PodSecurityContext, the value specified in SecurityContext takes
3719	// precedence for that container. Note that this field cannot be set when
3720	// spec.os.name is windows.
3721	"runAsGroup"?: int64 & int
3722
3723	// Indicates that the container must run as a non-root user. If true, the
3724	// Kubelet will validate the image at runtime to ensure that it does not run as
3725	// UID 0 (root) and fail to start the container if it does. If unset or false,
3726	// no such validation will be performed. May also be set in SecurityContext. If
3727	// set in both SecurityContext and PodSecurityContext, the value specified in
3728	// SecurityContext takes precedence.
3729	"runAsNonRoot"?: bool
3730
3731	// The UID to run the entrypoint of the container process. Defaults to user
3732	// specified in image metadata if unspecified. May also be set in
3733	// SecurityContext. If set in both SecurityContext and PodSecurityContext, the
3734	// value specified in SecurityContext takes precedence for that container. Note
3735	// that this field cannot be set when spec.os.name is windows.
3736	"runAsUser"?: int64 & int
3737
3738	// seLinuxChangePolicy defines how the container's SELinux label is applied to
3739	// all volumes used by the Pod. It has no effect on nodes that do not support
3740	// SELinux or to volumes does not support SELinux. Valid values are
3741	// "MountOption" and "Recursive".
3742	//
3743	// "Recursive" means relabeling of all files on all Pod volumes by the container
3744	// runtime. This may be slow for large volumes, but allows mixing privileged
3745	// and unprivileged Pods sharing the same volume on the same node.
3746	//
3747	// "MountOption" mounts all eligible Pod volumes with `-o context` mount option.
3748	// This requires all Pods that share the same volume to use the same SELinux
3749	// label. It is not possible to share the same volume among privileged and
3750	// unprivileged Pods. Eligible volumes are in-tree FibreChannel and iSCSI
3751	// volumes, and all CSI volumes whose CSI driver announces SELinux support by
3752	// setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes
3753	// are always re-labelled recursively. "MountOption" value is allowed only when
3754	// SELinuxMount feature gate is enabled.
3755	//
3756	// If not specified and SELinuxMount feature gate is enabled, "MountOption" is
3757	// used. If not specified and SELinuxMount feature gate is disabled,
3758	// "MountOption" is used for ReadWriteOncePod volumes and "Recursive" for all
3759	// other volumes.
3760	//
3761	// This field affects only Pods that have SELinux label set, either in
3762	// PodSecurityContext or in SecurityContext of all containers.
3763	//
3764	// All Pods that use the same volume should use the same seLinuxChangePolicy,
3765	// otherwise some pods can get stuck in ContainerCreating state. Note that this
3766	// field cannot be set when spec.os.name is windows.
3767	"seLinuxChangePolicy"?: string
3768
3769	// The SELinux context to be applied to all containers. If unspecified, the
3770	// container runtime will allocate a random SELinux context for each container.
3771	// May also be set in SecurityContext. If set in both SecurityContext and
3772	// PodSecurityContext, the value specified in SecurityContext takes precedence
3773	// for that container. Note that this field cannot be set when spec.os.name is
3774	// windows.
3775	"seLinuxOptions"?: #SELinuxOptions
3776
3777	// The seccomp options to use by the containers in this pod. Note that this
3778	// field cannot be set when spec.os.name is windows.
3779	"seccompProfile"?: #SeccompProfile
3780
3781	// A list of groups applied to the first process run in each container, in
3782	// addition to the container's primary GID and fsGroup (if specified). If the
3783	// SupplementalGroupsPolicy feature is enabled, the supplementalGroupsPolicy
3784	// field determines whether these are in addition to or instead of any group
3785	// memberships defined in the container image. If unspecified, no additional
3786	// groups are added, though group memberships defined in the container image
3787	// may still be used, depending on the supplementalGroupsPolicy field. Note
3788	// that this field cannot be set when spec.os.name is windows.
3789	"supplementalGroups"?: [...int64 & int]
3790
3791	// Defines how supplemental groups of the first container processes are
3792	// calculated. Valid values are "Merge" and "Strict". If not specified, "Merge"
3793	// is used. (Alpha) Using the field requires the SupplementalGroupsPolicy
3794	// feature gate to be enabled and the container runtime must implement support
3795	// for this feature. Note that this field cannot be set when spec.os.name is
3796	// windows.
3797	"supplementalGroupsPolicy"?: string
3798
3799	// Sysctls hold a list of namespaced sysctls used for the pod. Pods with
3800	// unsupported sysctls (by the container runtime) might fail to launch. Note
3801	// that this field cannot be set when spec.os.name is windows.
3802	"sysctls"?: [...#Sysctl]
3803
3804	// The Windows specific settings applied to all containers. If unspecified, the
3805	// options within a container's SecurityContext will be used. If set in both
3806	// SecurityContext and PodSecurityContext, the value specified in
3807	// SecurityContext takes precedence. Note that this field cannot be set when
3808	// spec.os.name is linux.
3809	"windowsOptions"?: #WindowsSecurityContextOptions
3810}
3811
3812// PodSpec is a description of a pod.
3813#PodSpec: {
3814	// Optional duration in seconds the pod may be active on the node relative to
3815	// StartTime before the system will actively try to mark it failed and kill
3816	// associated containers. Value must be a positive integer.
3817	"activeDeadlineSeconds"?: int64 & int
3818
3819	// If specified, the pod's scheduling constraints
3820	"affinity"?: #Affinity
3821
3822	// AutomountServiceAccountToken indicates whether a service account token should
3823	// be automatically mounted.
3824	"automountServiceAccountToken"?: bool
3825
3826	// List of containers belonging to the pod. Containers cannot currently be added
3827	// or removed. There must be at least one container in a Pod. Cannot be
3828	// updated.
3829	"containers"!: [...#Container]
3830
3831	// Specifies the DNS parameters of a pod. Parameters specified here will be
3832	// merged to the generated DNS configuration based on DNSPolicy.
3833	"dnsConfig"?: #PodDNSConfig
3834
3835	// Set DNS policy for the pod. Defaults to "ClusterFirst". Valid values are
3836	// 'ClusterFirstWithHostNet', 'ClusterFirst', 'Default' or 'None'. DNS
3837	// parameters given in DNSConfig will be merged with the policy selected with
3838	// DNSPolicy. To have DNS options set along with hostNetwork, you have to
3839	// specify DNS policy explicitly to 'ClusterFirstWithHostNet'.
3840	"dnsPolicy"?: string
3841
3842	// EnableServiceLinks indicates whether information about services should be
3843	// injected into pod's environment variables, matching the syntax of Docker
3844	// links. Optional: Defaults to true.
3845	"enableServiceLinks"?: bool
3846
3847	// List of ephemeral containers run in this pod. Ephemeral containers may be run
3848	// in an existing pod to perform user-initiated actions such as debugging. This
3849	// list cannot be specified when creating a pod, and it cannot be modified by
3850	// updating the pod spec. In order to add an ephemeral container to an existing
3851	// pod, use the pod's ephemeralcontainers subresource.
3852	"ephemeralContainers"?: [...#EphemeralContainer]
3853
3854	// HostAliases is an optional list of hosts and IPs that will be injected into
3855	// the pod's hosts file if specified.
3856	"hostAliases"?: [...#HostAlias]
3857
3858	// Use the host's ipc namespace. Optional: Default to false.
3859	"hostIPC"?: bool
3860
3861	// Host networking requested for this pod. Use the host's network namespace.
3862	// When using HostNetwork you should specify ports so the scheduler is aware.
3863	// When `hostNetwork` is true, specified `hostPort` fields in port definitions
3864	// must match `containerPort`, and unspecified `hostPort` fields in port
3865	// definitions are defaulted to match `containerPort`. Default to false.
3866	"hostNetwork"?: bool
3867
3868	// Use the host's pid namespace. Optional: Default to false.
3869	"hostPID"?: bool
3870
3871	// Use the host's user namespace. Optional: Default to true. If set to true or
3872	// not present, the pod will be run in the host user namespace, useful for when
3873	// the pod needs a feature only available to the host user namespace, such as
3874	// loading a kernel module with CAP_SYS_MODULE. When set to false, a new userns
3875	// is created for the pod. Setting false is useful for mitigating container
3876	// breakout vulnerabilities even allowing users to run their containers as root
3877	// without actually having root privileges on the host.
3878	"hostUsers"?: bool
3879
3880	// Specifies the hostname of the Pod If not specified, the pod's hostname will
3881	// be set to a system-defined value.
3882	"hostname"?: string
3883
3884	// HostnameOverride specifies an explicit override for the pod's hostname as
3885	// perceived by the pod. This field only specifies the pod's hostname and does
3886	// not affect its DNS records. When this field is set to a non-empty string: -
3887	// It takes precedence over the values set in `hostname` and `subdomain`. - The
3888	// Pod's hostname will be set to this value. - `setHostnameAsFQDN` must be nil
3889	// or set to false. - `hostNetwork` must be set to false.
3890	//
3891	// This field must be a valid DNS subdomain as defined in RFC 1123 and contain
3892	// at most 64 characters. Requires the HostnameOverride feature gate to be
3893	// enabled.
3894	"hostnameOverride"?: string
3895
3896	// ImagePullSecrets is an optional list of references to secrets in the same
3897	// namespace to use for pulling any of the images used by this PodSpec. If
3898	// specified, these secrets will be passed to individual puller implementations
3899	// for them to use. More info:
3900	// https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod
3901	"imagePullSecrets"?: [...#LocalObjectReference]
3902
3903	// List of initialization containers belonging to the pod. Init containers are
3904	// executed in order prior to containers being started. If any init container
3905	// fails, the pod is considered to have failed and is handled according to its
3906	// restartPolicy. The name for an init container or normal container must be
3907	// unique among all containers. Init containers may not have Lifecycle actions,
3908	// Readiness probes, Liveness probes, or Startup probes. The
3909	// resourceRequirements of an init container are taken into account during
3910	// scheduling by finding the highest request/limit for each resource type, and
3911	// then using the max of that value or the sum of the normal containers. Limits
3912	// are applied to init containers in a similar fashion. Init containers cannot
3913	// currently be added or removed. Cannot be updated. More info:
3914	// https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
3915	"initContainers"?: [...#Container]
3916
3917	// NodeName indicates in which node this pod is scheduled. If empty, this pod is
3918	// a candidate for scheduling by the scheduler defined in schedulerName. Once
3919	// this field is set, the kubelet for this node becomes responsible for the
3920	// lifecycle of this pod. This field should not be used to express a desire for
3921	// the pod to be scheduled on a specific node.
3922	// https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodename
3923	"nodeName"?: string
3924
3925	// NodeSelector is a selector which must be true for the pod to fit on a node.
3926	// Selector which must match a node's labels for the pod to be scheduled on
3927	// that node. More info:
3928	// https://kubernetes.io/docs/concepts/configuration/assign-pod-node/
3929	"nodeSelector"?: [string]: string
3930
3931	// Specifies the OS of the containers in the pod. Some pod and container fields
3932	// are restricted if this is set.
3933	//
3934	// If the OS field is set to linux, the following fields must be unset:
3935	// -securityContext.windowsOptions
3936	//
3937	// If the OS field is set to windows, following fields must be unset: -
3938	// spec.hostPID - spec.hostIPC - spec.hostUsers - spec.resources -
3939	// spec.securityContext.appArmorProfile - spec.securityContext.seLinuxOptions -
3940	// spec.securityContext.seccompProfile - spec.securityContext.fsGroup -
3941	// spec.securityContext.fsGroupChangePolicy - spec.securityContext.sysctls -
3942	// spec.shareProcessNamespace - spec.securityContext.runAsUser -
3943	// spec.securityContext.runAsGroup - spec.securityContext.supplementalGroups -
3944	// spec.securityContext.supplementalGroupsPolicy -
3945	// spec.containers[*].securityContext.appArmorProfile -
3946	// spec.containers[*].securityContext.seLinuxOptions -
3947	// spec.containers[*].securityContext.seccompProfile -
3948	// spec.containers[*].securityContext.capabilities -
3949	// spec.containers[*].securityContext.readOnlyRootFilesystem -
3950	// spec.containers[*].securityContext.privileged -
3951	// spec.containers[*].securityContext.allowPrivilegeEscalation -
3952	// spec.containers[*].securityContext.procMount -
3953	// spec.containers[*].securityContext.runAsUser -
3954	// spec.containers[*].securityContext.runAsGroup
3955	"os"?: #PodOS
3956
3957	// Overhead represents the resource overhead associated with running a pod for a
3958	// given RuntimeClass. This field will be autopopulated at admission time by
3959	// the RuntimeClass admission controller. If the RuntimeClass admission
3960	// controller is enabled, overhead must not be set in Pod create requests. The
3961	// RuntimeClass admission controller will reject Pod create requests which have
3962	// the overhead already set. If RuntimeClass is configured and selected in the
3963	// PodSpec, Overhead will be set to the value defined in the corresponding
3964	// RuntimeClass, otherwise it will remain unset and treated as zero. More info:
3965	// https://git.k8s.io/enhancements/keps/sig-node/688-pod-overhead/README.md
3966	"overhead"?: [string]: resource.#Quantity
3967
3968	// PreemptionPolicy is the Policy for preempting pods with lower priority. One
3969	// of Never, PreemptLowerPriority. Defaults to PreemptLowerPriority if unset.
3970	"preemptionPolicy"?: string
3971
3972	// The priority value. Various system components use this field to find the
3973	// priority of the pod. When Priority Admission Controller is enabled, it
3974	// prevents users from setting this field. The admission controller populates
3975	// this field from PriorityClassName. The higher the value, the higher the
3976	// priority.
3977	"priority"?: int32 & int
3978
3979	// If specified, indicates the pod's priority. "system-node-critical" and
3980	// "system-cluster-critical" are two special keywords which indicate the
3981	// highest priorities with the former being the highest priority. Any other
3982	// name must be defined by creating a PriorityClass object with that name. If
3983	// not specified, the pod priority will be default or zero if there is no
3984	// default.
3985	"priorityClassName"?: string
3986
3987	// If specified, all readiness gates will be evaluated for pod readiness. A pod
3988	// is ready when all its containers are ready AND all conditions specified in
3989	// the readiness gates have status equal to "True" More info:
3990	// https://git.k8s.io/enhancements/keps/sig-network/580-pod-readiness-gates
3991	"readinessGates"?: [...#PodReadinessGate]
3992
3993	// ResourceClaims defines which ResourceClaims must be allocated and reserved
3994	// before the Pod is allowed to start. The resources will be made available to
3995	// those containers which consume them by name.
3996	//
3997	// This is a stable field but requires that the DynamicResourceAllocation feature gate is enabled.
3998	//
3999	// This field is immutable.
4000	"resourceClaims"?: [...#PodResourceClaim]
4001
4002	// Resources is the total amount of CPU and Memory resources required by all
4003	// containers in the pod. It supports specifying Requests and Limits for "cpu",
4004	// "memory" and "hugepages-" resource names only. ResourceClaims are not
4005	// supported.
4006	//
4007	// This field enables fine-grained control over resource allocation for the
4008	// entire pod, allowing resource sharing among containers in a pod.
4009	//
4010	// This is an alpha field and requires enabling the PodLevelResources feature gate.
4011	"resources"?: #ResourceRequirements
4012
4013	// Restart policy for all containers within the pod. One of Always, OnFailure,
4014	// Never. In some contexts, only a subset of those values may be permitted.
4015	// Default to Always. More info:
4016	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#restart-policy
4017	"restartPolicy"?: string
4018
4019	// RuntimeClassName refers to a RuntimeClass object in the node.k8s.io group,
4020	// which should be used to run this pod. If no RuntimeClass resource matches
4021	// the named class, the pod will not be run. If unset or empty, the "legacy"
4022	// RuntimeClass will be used, which is an implicit class with an empty
4023	// definition that uses the default runtime handler. More info:
4024	// https://git.k8s.io/enhancements/keps/sig-node/585-runtime-class
4025	"runtimeClassName"?: string
4026
4027	// If specified, the pod will be dispatched by specified scheduler. If not
4028	// specified, the pod will be dispatched by default scheduler.
4029	"schedulerName"?: string
4030
4031	// SchedulingGates is an opaque list of values that if specified will block
4032	// scheduling the pod. If schedulingGates is not empty, the pod will stay in
4033	// the SchedulingGated state and the scheduler will not attempt to schedule the
4034	// pod.
4035	//
4036	// SchedulingGates can only be set at pod creation time, and be removed only afterwards.
4037	"schedulingGates"?: [...#PodSchedulingGate]
4038
4039	// SchedulingGroup provides a reference to the immediate scheduling runtime
4040	// grouping object that this Pod belongs to. This field is used by the
4041	// scheduler to identify the group and apply the correct group scheduling
4042	// policies. The association with a group also impacts other lifecycle aspects
4043	// of a Pod that are relevant in a wider context of scheduling like preemption,
4044	// resource attachment, etc. If not specified, the Pod is treated as a single
4045	// unit in all of these aspects. The group object referenced by this field may
4046	// not exist at the time the Pod is created. This field is immutable, but a
4047	// group object with the same name may be recreated with different policies.
4048	// Doing this during pod scheduling may result in the placement not conforming
4049	// to the expected policies.
4050	"schedulingGroup"?: #PodSchedulingGroup
4051
4052	// SecurityContext holds pod-level security attributes and common container
4053	// settings. Optional: Defaults to empty. See type description for default
4054	// values of each field.
4055	"securityContext"?: #PodSecurityContext
4056
4057	// DeprecatedServiceAccount is a deprecated alias for ServiceAccountName.
4058	// Deprecated: Use serviceAccountName instead.
4059	"serviceAccount"?: string
4060
4061	// ServiceAccountName is the name of the ServiceAccount to use to run this pod.
4062	// More info:
4063	// https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
4064	"serviceAccountName"?: string
4065
4066	// If true the pod's hostname will be configured as the pod's FQDN, rather than
4067	// the leaf name (the default). In Linux containers, this means setting the
4068	// FQDN in the hostname field of the kernel (the nodename field of struct
4069	// utsname). In Windows containers, this means setting the registry value of
4070	// hostname for the registry key
4071	// HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters
4072	// to FQDN. If a pod does not have FQDN, this has no effect. Default to false.
4073	"setHostnameAsFQDN"?: bool
4074
4075	// Share a single process namespace between all of the containers in a pod. When
4076	// this is set containers will be able to view and signal processes from other
4077	// containers in the same pod, and the first process in each container will not
4078	// be assigned PID 1. HostPID and ShareProcessNamespace cannot both be set.
4079	// Optional: Default to false.
4080	"shareProcessNamespace"?: bool
4081
4082	// If specified, the fully qualified Pod hostname will be
4083	// "<hostname>.<subdomain>.<pod namespace>.svc.<cluster domain>". If not
4084	// specified, the pod will not have a domainname at all.
4085	"subdomain"?: string
4086
4087	// Optional duration in seconds the pod needs to terminate gracefully. May be
4088	// decreased in delete request. Value must be non-negative integer. The value
4089	// zero indicates stop immediately via the kill signal (no opportunity to shut
4090	// down). If this value is nil, the default grace period will be used instead.
4091	// The grace period is the duration in seconds after the processes running in
4092	// the pod are sent a termination signal and the time when the processes are
4093	// forcibly halted with a kill signal. Set this value longer than the expected
4094	// cleanup time for your process. Defaults to 30 seconds.
4095	"terminationGracePeriodSeconds"?: int64 & int
4096
4097	// If specified, the pod's tolerations.
4098	"tolerations"?: [...#Toleration]
4099
4100	// TopologySpreadConstraints describes how a group of pods ought to spread
4101	// across topology domains. Scheduler will schedule pods in a way which abides
4102	// by the constraints. All topologySpreadConstraints are ANDed.
4103	"topologySpreadConstraints"?: [...#TopologySpreadConstraint]
4104
4105	// List of volumes that can be mounted by containers belonging to the pod. More
4106	// info: https://kubernetes.io/docs/concepts/storage/volumes
4107	"volumes"?: [...#Volume]
4108}
4109
4110// PodStatus represents information about the status of a pod. Status may trail
4111// the actual state of a system, especially if the node that hosts the pod
4112// cannot contact the control plane.
4113#PodStatus: {
4114	// AllocatedResources is the total requests allocated for this pod by the node.
4115	// If pod-level requests are not set, this will be the total requests
4116	// aggregated across containers in the pod.
4117	"allocatedResources"?: [string]: resource.#Quantity
4118
4119	// Current service state of pod. More info:
4120	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-conditions
4121	"conditions"?: [...#PodCondition]
4122
4123	// Statuses of containers in this pod. Each container in the pod should have at
4124	// most one status in this list, and all statuses should be for containers in
4125	// the pod. However this is not enforced. If a status for a non-existent
4126	// container is present in the list, or the list has duplicate names, the
4127	// behavior of various Kubernetes components is not defined and those statuses
4128	// might be ignored. More info:
4129	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-and-container-status
4130	"containerStatuses"?: [...#ContainerStatus]
4131
4132	// Statuses for any ephemeral containers that have run in this pod. Each
4133	// ephemeral container in the pod should have at most one status in this list,
4134	// and all statuses should be for containers in the pod. However this is not
4135	// enforced. If a status for a non-existent container is present in the list,
4136	// or the list has duplicate names, the behavior of various Kubernetes
4137	// components is not defined and those statuses might be ignored. More info:
4138	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-and-container-status
4139	"ephemeralContainerStatuses"?: [...#ContainerStatus]
4140
4141	// Status of extended resource claim backed by DRA.
4142	"extendedResourceClaimStatus"?: #PodExtendedResourceClaimStatus
4143
4144	// hostIP holds the IP address of the host to which the pod is assigned. Empty
4145	// if the pod has not started yet. A pod can be assigned to a node that has a
4146	// problem in kubelet which in turns mean that HostIP will not be updated even
4147	// if there is a node is assigned to pod
4148	"hostIP"?: string
4149
4150	// hostIPs holds the IP addresses allocated to the host. If this field is
4151	// specified, the first entry must match the hostIP field. This list is empty
4152	// if the pod has not started yet. A pod can be assigned to a node that has a
4153	// problem in kubelet which in turns means that HostIPs will not be updated
4154	// even if there is a node is assigned to this pod.
4155	"hostIPs"?: [...#HostIP]
4156
4157	// Statuses of init containers in this pod. The most recent successful
4158	// non-restartable init container will have ready = true, the most recently
4159	// started container will have startTime set. Each init container in the pod
4160	// should have at most one status in this list, and all statuses should be for
4161	// containers in the pod. However this is not enforced. If a status for a
4162	// non-existent container is present in the list, or the list has duplicate
4163	// names, the behavior of various Kubernetes components is not defined and
4164	// those statuses might be ignored. More info:
4165	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-and-container-status
4166	"initContainerStatuses"?: [...#ContainerStatus]
4167
4168	// A human readable message indicating details about why the pod is in this condition.
4169	"message"?: string
4170
4171	// NodeAllocatableResourceClaimStatuses contains the status of node-allocatable
4172	// resources that were allocated for this pod through DRA claims. This includes
4173	// resources currently reported in v1.Node `status.allocatable` that are not
4174	// extended resources (see
4175	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#extended-resources).
4176	// Examples include "cpu", "memory", "ephemeral-storage", and hugepages.
4177	"nodeAllocatableResourceClaimStatuses"?: [...#NodeAllocatableResourceClaimStatus]
4178
4179	// nominatedNodeName is set only when this pod preempts other pods on the node,
4180	// but it cannot be scheduled right away as preemption victims receive their
4181	// graceful termination periods. This field does not guarantee that the pod
4182	// will be scheduled on this node. Scheduler may decide to place the pod
4183	// elsewhere if other nodes become available sooner. Scheduler may also decide
4184	// to give the resources on this node to a higher priority pod that is created
4185	// after preemption. As a result, this field may be different than
4186	// PodSpec.nodeName when the pod is scheduled.
4187	"nominatedNodeName"?: string
4188
4189	// If set, this represents the .metadata.generation that the pod status was set
4190	// based upon. The PodObservedGenerationTracking feature gate must be enabled
4191	// to use this field.
4192	"observedGeneration"?: int64 & int
4193
4194	// The phase of a Pod is a simple, high-level summary of where the Pod is in its
4195	// lifecycle. The conditions array, the reason and message fields, and the
4196	// individual container status arrays contain more detail about the pod's
4197	// status. There are five possible phase values:
4198	//
4199	// Pending: The pod has been accepted by the Kubernetes system, but one or more
4200	// of the container images has not been created. This includes time before
4201	// being scheduled as well as time spent downloading images over the network,
4202	// which could take a while. Running: The pod has been bound to a node, and all
4203	// of the containers have been created. At least one container is still
4204	// running, or is in the process of starting or restarting. Succeeded: All
4205	// containers in the pod have terminated in success, and will not be restarted.
4206	// Failed: All containers in the pod have terminated, and at least one
4207	// container has terminated in failure. The container either exited with
4208	// non-zero status or was terminated by the system. Unknown: For some reason
4209	// the state of the pod could not be obtained, typically due to an error in
4210	// communicating with the host of the pod.
4211	//
4212	// More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-phase
4213	"phase"?: string
4214
4215	// podIP address allocated to the pod. Routable at least within the cluster.
4216	// Empty if not yet allocated.
4217	"podIP"?: string
4218
4219	// podIPs holds the IP addresses allocated to the pod. If this field is
4220	// specified, the 0th entry must match the podIP field. Pods may be allocated
4221	// at most 1 value for each of IPv4 and IPv6. This list is empty if no IPs have
4222	// been allocated yet.
4223	"podIPs"?: [...#PodIP]
4224
4225	// The Quality of Service (QOS) classification assigned to the pod based on
4226	// resource requirements See PodQOSClass type for available QOS classes More
4227	// info:
4228	// https://kubernetes.io/docs/concepts/workloads/pods/pod-qos/#quality-of-service-classes
4229	"qosClass"?: string
4230
4231	// A brief CamelCase message indicating details about why the pod is in this state. e.g. 'Evicted'
4232	"reason"?: string
4233
4234	// Status of resources resize desired for pod's containers. It is empty if no
4235	// resources resize is pending. Any changes to container resources will
4236	// automatically set this to "Proposed" Deprecated: Resize status is moved to
4237	// two pod conditions PodResizePending and PodResizeInProgress.
4238	// PodResizePending will track states where the spec has been resized, but the
4239	// Kubelet has not yet allocated the resources. PodResizeInProgress will track
4240	// in-progress resizes, and should be present whenever allocated resources !=
4241	// acknowledged resources.
4242	"resize"?: string
4243
4244	// Status of resource claims.
4245	"resourceClaimStatuses"?: [...#PodResourceClaimStatus]
4246
4247	// Resources represents the compute resource requests and limits that have been
4248	// applied at the pod level if pod-level requests or limits are set in
4249	// PodSpec.Resources
4250	"resources"?: #ResourceRequirements
4251
4252	// RFC 3339 date and time at which the object was acknowledged by the Kubelet.
4253	// This is before the Kubelet pulled the container image(s) for the pod.
4254	"startTime"?: v1.#Time
4255}
4256
4257// PodTemplate describes a template for creating copies of a predefined pod.
4258#PodTemplate: {
4259	// APIVersion defines the versioned schema of this representation of an object.
4260	// Servers should convert recognized schemas to the latest internal value, and
4261	// may reject unrecognized values. More info:
4262	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4263	"apiVersion": "v1"
4264
4265	// Kind is a string value representing the REST resource this object represents.
4266	// Servers may infer this from the endpoint the client submits requests to.
4267	// Cannot be updated. In CamelCase. More info:
4268	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4269	"kind": "PodTemplate"
4270
4271	// Standard object's metadata. More info:
4272	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4273	"metadata"?: v1.#ObjectMeta
4274
4275	// Template defines the pods that will be created from this pod template.
4276	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4277	"template"?: #PodTemplateSpec
4278}
4279
4280// PodTemplateList is a list of PodTemplates.
4281#PodTemplateList: {
4282	// APIVersion defines the versioned schema of this representation of an object.
4283	// Servers should convert recognized schemas to the latest internal value, and
4284	// may reject unrecognized values. More info:
4285	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4286	"apiVersion": "v1"
4287
4288	// List of pod templates
4289	"items"!: [...#PodTemplate]
4290
4291	// Kind is a string value representing the REST resource this object represents.
4292	// Servers may infer this from the endpoint the client submits requests to.
4293	// Cannot be updated. In CamelCase. More info:
4294	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4295	"kind": "PodTemplateList"
4296
4297	// Standard list metadata. More info:
4298	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4299	"metadata"?: v1.#ListMeta
4300}
4301
4302// PodTemplateSpec describes the data a pod should have when created from a template
4303#PodTemplateSpec: {
4304	// Standard object's metadata. More info:
4305	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4306	"metadata"?: v1.#ObjectMeta
4307
4308	// Specification of the desired behavior of the pod. More info:
4309	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4310	"spec"?: #PodSpec
4311}
4312
4313// PortStatus represents the error condition of a service port
4314#PortStatus: {
4315	// Error is to record the problem with the service port The format of the error
4316	// shall comply with the following rules: - built-in error values shall be
4317	// specified in this file and those shall use
4318	// CamelCase names
4319	// - cloud provider specific error values must have names that comply with the
4320	// format foo.example.com/CamelCase.
4321	"error"?: string
4322
4323	// Port is the port number of the service port of which status is recorded here
4324	"port"!: int32 & int
4325
4326	// Protocol is the protocol of the service port of which status is recorded here
4327	// The supported values are: "TCP", "UDP", "SCTP"
4328	"protocol"!: string
4329}
4330
4331// PortworxVolumeSource represents a Portworx volume resource.
4332#PortworxVolumeSource: {
4333	// fSType represents the filesystem type to mount Must be a filesystem type
4334	// supported by the host operating system. Ex. "ext4", "xfs". Implicitly
4335	// inferred to be "ext4" if unspecified.
4336	"fsType"?: string
4337
4338	// readOnly defaults to false (read/write). ReadOnly here will force the
4339	// ReadOnly setting in VolumeMounts.
4340	"readOnly"?: bool
4341
4342	// volumeID uniquely identifies a Portworx volume
4343	"volumeID"!: string
4344}
4345
4346// An empty preferred scheduling term matches all objects with implicit weight 0
4347// (i.e. it's a no-op). A null preferred scheduling term matches no objects
4348// (i.e. is also a no-op).
4349#PreferredSchedulingTerm: {
4350	// A node selector term, associated with the corresponding weight.
4351	"preference"!: #NodeSelectorTerm
4352
4353	// Weight associated with matching the corresponding nodeSelectorTerm, in the range 1-100.
4354	"weight"!: int32 & int
4355}
4356
4357// Probe describes a health check to be performed against a container to
4358// determine whether it is alive or ready to receive traffic.
4359#Probe: {
4360	// Exec specifies a command to execute in the container.
4361	"exec"?: #ExecAction
4362
4363	// Minimum consecutive failures for the probe to be considered failed after
4364	// having succeeded. Defaults to 3. Minimum value is 1.
4365	"failureThreshold"?: int32 & int
4366
4367	// GRPC specifies a GRPC HealthCheckRequest.
4368	"grpc"?: #GRPCAction
4369
4370	// HTTPGet specifies an HTTP GET request to perform.
4371	"httpGet"?: #HTTPGetAction
4372
4373	// Number of seconds after the container has started before liveness probes are
4374	// initiated. More info:
4375	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
4376	"initialDelaySeconds"?: int32 & int
4377
4378	// How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is 1.
4379	"periodSeconds"?: int32 & int
4380
4381	// Minimum consecutive successes for the probe to be considered successful after
4382	// having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum
4383	// value is 1.
4384	"successThreshold"?: int32 & int
4385
4386	// TCPSocket specifies a connection to a TCP port.
4387	"tcpSocket"?: #TCPSocketAction
4388
4389	// Optional duration in seconds the pod needs to terminate gracefully upon probe
4390	// failure. The grace period is the duration in seconds after the processes
4391	// running in the pod are sent a termination signal and the time when the
4392	// processes are forcibly halted with a kill signal. Set this value longer than
4393	// the expected cleanup time for your process. If this value is nil, the pod's
4394	// terminationGracePeriodSeconds will be used. Otherwise, this value overrides
4395	// the value provided by the pod spec. Value must be non-negative integer. The
4396	// value zero indicates stop immediately via the kill signal (no opportunity to
4397	// shut down). This is a beta field and requires enabling
4398	// ProbeTerminationGracePeriod feature gate. Minimum value is 1.
4399	// spec.terminationGracePeriodSeconds is used if unset.
4400	"terminationGracePeriodSeconds"?: int64 & int
4401
4402	// Number of seconds after which the probe times out. Defaults to 1 second.
4403	// Minimum value is 1. More info:
4404	// https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
4405	"timeoutSeconds"?: int32 & int
4406}
4407
4408// Represents a projected volume source
4409#ProjectedVolumeSource: {
4410	// defaultMode are the mode bits used to set permissions on created files by
4411	// default. Must be an octal value between 0000 and 0777 or a decimal value
4412	// between 0 and 511. YAML accepts both octal and decimal values, JSON requires
4413	// decimal values for mode bits. Directories within the path are not affected
4414	// by this setting. This might be in conflict with other options that affect
4415	// the file mode, like fsGroup, and the result can be other mode bits set.
4416	"defaultMode"?: int32 & int
4417
4418	// sources is the list of volume projections. Each entry in this list handles one source.
4419	"sources"?: [...#VolumeProjection]
4420}
4421
4422// Represents a Quobyte mount that lasts the lifetime of a pod. Quobyte volumes
4423// do not support ownership management or SELinux relabeling.
4424#QuobyteVolumeSource: {
4425	// group to map volume access to Default is no group
4426	"group"?: string
4427
4428	// readOnly here will force the Quobyte volume to be mounted with read-only
4429	// permissions. Defaults to false.
4430	"readOnly"?: bool
4431
4432	// registry represents a single or multiple Quobyte Registry services specified
4433	// as a string as host:port pair (multiple entries are separated with commas)
4434	// which acts as the central registry for volumes
4435	"registry"!: string
4436
4437	// tenant owning the given Quobyte volume in the Backend Used with dynamically
4438	// provisioned Quobyte volumes, value is set by the plugin
4439	"tenant"?: string
4440
4441	// user to map volume access to Defaults to serivceaccount user
4442	"user"?: string
4443
4444	// volume is a string that references an already created Quobyte volume by name.
4445	"volume"!: string
4446}
4447
4448// Represents a Rados Block Device mount that lasts the lifetime of a pod. RBD
4449// volumes support ownership management and SELinux relabeling.
4450#RBDPersistentVolumeSource: {
4451	// fsType is the filesystem type of the volume that you want to mount. Tip:
4452	// Ensure that the filesystem type is supported by the host operating system.
4453	// Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
4454	// unspecified. More info:
4455	// https://kubernetes.io/docs/concepts/storage/volumes#rbd
4456	"fsType"?: string
4457
4458	// image is the rados image name. More info:
4459	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4460	"image"!: string
4461
4462	// keyring is the path to key ring for RBDUser. Default is /etc/ceph/keyring.
4463	// More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4464	"keyring"?: string
4465
4466	// monitors is a collection of Ceph monitors. More info:
4467	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4468	"monitors"!: [...string]
4469
4470	// pool is the rados pool name. Default is rbd. More info:
4471	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4472	"pool"?: string
4473
4474	// readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to
4475	// false. More info:
4476	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4477	"readOnly"?: bool
4478
4479	// secretRef is name of the authentication secret for RBDUser. If provided
4480	// overrides keyring. Default is nil. More info:
4481	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4482	"secretRef"?: #SecretReference
4483
4484	// user is the rados user name. Default is admin. More info:
4485	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4486	"user"?: string
4487}
4488
4489// Represents a Rados Block Device mount that lasts the lifetime of a pod. RBD
4490// volumes support ownership management and SELinux relabeling.
4491#RBDVolumeSource: {
4492	// fsType is the filesystem type of the volume that you want to mount. Tip:
4493	// Ensure that the filesystem type is supported by the host operating system.
4494	// Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
4495	// unspecified. More info:
4496	// https://kubernetes.io/docs/concepts/storage/volumes#rbd
4497	"fsType"?: string
4498
4499	// image is the rados image name. More info:
4500	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4501	"image"!: string
4502
4503	// keyring is the path to key ring for RBDUser. Default is /etc/ceph/keyring.
4504	// More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4505	"keyring"?: string
4506
4507	// monitors is a collection of Ceph monitors. More info:
4508	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4509	"monitors"!: [...string]
4510
4511	// pool is the rados pool name. Default is rbd. More info:
4512	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4513	"pool"?: string
4514
4515	// readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to
4516	// false. More info:
4517	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4518	"readOnly"?: bool
4519
4520	// secretRef is name of the authentication secret for RBDUser. If provided
4521	// overrides keyring. Default is nil. More info:
4522	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4523	"secretRef"?: #LocalObjectReference
4524
4525	// user is the rados user name. Default is admin. More info:
4526	// https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
4527	"user"?: string
4528}
4529
4530// ReplicationController represents the configuration of a replication controller.
4531#ReplicationController: {
4532	// APIVersion defines the versioned schema of this representation of an object.
4533	// Servers should convert recognized schemas to the latest internal value, and
4534	// may reject unrecognized values. More info:
4535	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4536	"apiVersion": "v1"
4537
4538	// Kind is a string value representing the REST resource this object represents.
4539	// Servers may infer this from the endpoint the client submits requests to.
4540	// Cannot be updated. In CamelCase. More info:
4541	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4542	"kind": "ReplicationController"
4543
4544	// If the Labels of a ReplicationController are empty, they are defaulted to be
4545	// the same as the Pod(s) that the replication controller manages. Standard
4546	// object's metadata. More info:
4547	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4548	"metadata"?: v1.#ObjectMeta
4549
4550	// Spec defines the specification of the desired behavior of the replication
4551	// controller. More info:
4552	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4553	"spec"?: #ReplicationControllerSpec
4554
4555	// Status is the most recently observed status of the replication controller.
4556	// This data may be out of date by some window of time. Populated by the
4557	// system. Read-only. More info:
4558	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4559	"status"?: #ReplicationControllerStatus
4560}
4561
4562// ReplicationControllerCondition describes the state of a replication
4563// controller at a certain point.
4564#ReplicationControllerCondition: {
4565	// The last time the condition transitioned from one status to another.
4566	"lastTransitionTime"?: v1.#Time
4567
4568	// A human readable message indicating details about the transition.
4569	"message"?: string
4570
4571	// The reason for the condition's last transition.
4572	"reason"?: string
4573
4574	// Status of the condition, one of True, False, Unknown.
4575	"status"!: string
4576
4577	// Type of replication controller condition.
4578	"type"!: string
4579}
4580
4581// ReplicationControllerList is a collection of replication controllers.
4582#ReplicationControllerList: {
4583	// APIVersion defines the versioned schema of this representation of an object.
4584	// Servers should convert recognized schemas to the latest internal value, and
4585	// may reject unrecognized values. More info:
4586	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4587	"apiVersion": "v1"
4588
4589	// List of replication controllers. More info:
4590	// https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller
4591	"items"!: [...#ReplicationController]
4592
4593	// Kind is a string value representing the REST resource this object represents.
4594	// Servers may infer this from the endpoint the client submits requests to.
4595	// Cannot be updated. In CamelCase. More info:
4596	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4597	"kind": "ReplicationControllerList"
4598
4599	// Standard list metadata. More info:
4600	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4601	"metadata"?: v1.#ListMeta
4602}
4603
4604// ReplicationControllerSpec is the specification of a replication controller.
4605#ReplicationControllerSpec: {
4606	// Minimum number of seconds for which a newly created pod should be ready
4607	// without any of its container crashing, for it to be considered available.
4608	// Defaults to 0 (pod will be considered available as soon as it is ready)
4609	"minReadySeconds"?: int32 & int
4610
4611	// Replicas is the number of desired replicas. This is a pointer to distinguish
4612	// between explicit zero and unspecified. Defaults to 1. More info:
4613	// https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#what-is-a-replicationcontroller
4614	"replicas"?: int32 & int
4615
4616	// Selector is a label query over pods that should match the Replicas count. If
4617	// Selector is empty, it is defaulted to the labels present on the Pod
4618	// template. Label keys and values that must match in order to be controlled by
4619	// this replication controller, if empty defaulted to labels on Pod template.
4620	// More info:
4621	// https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors
4622	"selector"?: [string]: string
4623
4624	// Template is the object that describes the pod that will be created if
4625	// insufficient replicas are detected. This takes precedence over a
4626	// TemplateRef. The only allowed template.spec.restartPolicy value is "Always".
4627	// More info:
4628	// https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#pod-template
4629	"template"?: #PodTemplateSpec
4630}
4631
4632// ReplicationControllerStatus represents the current status of a replication controller.
4633#ReplicationControllerStatus: {
4634	// The number of available replicas (ready for at least minReadySeconds) for
4635	// this replication controller.
4636	"availableReplicas"?: int32 & int
4637
4638	// Represents the latest available observations of a replication controller's current state.
4639	"conditions"?: [...#ReplicationControllerCondition]
4640
4641	// The number of pods that have labels matching the labels of the pod template
4642	// of the replication controller.
4643	"fullyLabeledReplicas"?: int32 & int
4644
4645	// ObservedGeneration reflects the generation of the most recently observed replication controller.
4646	"observedGeneration"?: int64 & int
4647
4648	// The number of ready replicas for this replication controller.
4649	"readyReplicas"?: int32 & int
4650
4651	// Replicas is the most recently observed number of replicas. More info:
4652	// https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#what-is-a-replicationcontroller
4653	"replicas"!: int32 & int
4654}
4655
4656// ResourceClaim references one entry in PodSpec.ResourceClaims.
4657#ResourceClaim: {
4658	// Name must match the name of one entry in pod.spec.resourceClaims of the Pod
4659	// where this field is used. It makes that resource available inside a
4660	// container.
4661	"name"!: string
4662
4663	// Request is the name chosen for a request in the referenced claim. If empty,
4664	// everything from the claim is made available, otherwise only the result of
4665	// this request.
4666	"request"?: string
4667}
4668
4669// ResourceFieldSelector represents container resources (cpu, memory) and their output format
4670#ResourceFieldSelector: {
4671	// Container name: required for volumes, optional for env vars
4672	"containerName"?: string
4673
4674	// Specifies the output format of the exposed resources, defaults to "1"
4675	"divisor"?: resource.#Quantity
4676
4677	// Required: resource to select
4678	"resource"!: string
4679}
4680
4681// ResourceHealth represents the health of a resource. It has the latest device
4682// health information. This is a part of KEP https://kep.k8s.io/4680.
4683#ResourceHealth: {
4684	// Health of the resource. can be one of:
4685	// - Healthy: operates as normal
4686	// - Unhealthy: reported unhealthy. We consider this a temporary health issue
4687	// since we do not have a mechanism today to distinguish
4688	// temporary and permanent issues.
4689	// - Unknown: The status cannot be determined.
4690	// For example, Device Plugin got unregistered and hasn't been re-registered since.
4691	//
4692	// In future we may want to introduce the PermanentlyUnhealthy Status.
4693	"health"?: string
4694
4695	// Message provides human-readable context for Health (e.g. "ECC error count
4696	// exceeded threshold"). This field is populated by the kubelet when
4697	// ResourceHealthStatusMessage is enabled if the DRA plugin returns a message,
4698	// and is null otherwise.
4699	"message"?: string
4700
4701	// ResourceID is the unique identifier of the resource. See the ResourceID type
4702	// for more information.
4703	"resourceID"!: string
4704}
4705
4706// ResourceQuota sets aggregate quota restrictions enforced per namespace
4707#ResourceQuota: {
4708	// APIVersion defines the versioned schema of this representation of an object.
4709	// Servers should convert recognized schemas to the latest internal value, and
4710	// may reject unrecognized values. More info:
4711	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4712	"apiVersion": "v1"
4713
4714	// Kind is a string value representing the REST resource this object represents.
4715	// Servers may infer this from the endpoint the client submits requests to.
4716	// Cannot be updated. In CamelCase. More info:
4717	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4718	"kind": "ResourceQuota"
4719
4720	// Standard object's metadata. More info:
4721	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4722	"metadata"?: v1.#ObjectMeta
4723
4724	// Spec defines the desired quota.
4725	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4726	"spec"?: #ResourceQuotaSpec
4727
4728	// Status defines the actual enforced quota and its current usage.
4729	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
4730	"status"?: #ResourceQuotaStatus
4731}
4732
4733// ResourceQuotaList is a list of ResourceQuota items.
4734#ResourceQuotaList: {
4735	// APIVersion defines the versioned schema of this representation of an object.
4736	// Servers should convert recognized schemas to the latest internal value, and
4737	// may reject unrecognized values. More info:
4738	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4739	"apiVersion": "v1"
4740
4741	// Items is a list of ResourceQuota objects. More info:
4742	// https://kubernetes.io/docs/concepts/policy/resource-quotas/
4743	"items"!: [...#ResourceQuota]
4744
4745	// Kind is a string value representing the REST resource this object represents.
4746	// Servers may infer this from the endpoint the client submits requests to.
4747	// Cannot be updated. In CamelCase. More info:
4748	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4749	"kind": "ResourceQuotaList"
4750
4751	// Standard list metadata. More info:
4752	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4753	"metadata"?: v1.#ListMeta
4754}
4755
4756// ResourceQuotaSpec defines the desired hard limits to enforce for Quota.
4757#ResourceQuotaSpec: {
4758	// hard is the set of desired hard limits for each named resource. More info:
4759	// https://kubernetes.io/docs/concepts/policy/resource-quotas/
4760	"hard"?: [string]: resource.#Quantity
4761
4762	// scopeSelector is also a collection of filters like scopes that must match
4763	// each object tracked by a quota but expressed using ScopeSelectorOperator in
4764	// combination with possible values. For a resource to match, both scopes AND
4765	// scopeSelector (if specified in spec), must be matched.
4766	"scopeSelector"?: #ScopeSelector
4767
4768	// A collection of filters that must match each object tracked by a quota. If
4769	// not specified, the quota matches all objects.
4770	"scopes"?: [...string]
4771}
4772
4773// ResourceQuotaStatus defines the enforced hard limits and observed use.
4774#ResourceQuotaStatus: {
4775	// Hard is the set of enforced hard limits for each named resource. More info:
4776	// https://kubernetes.io/docs/concepts/policy/resource-quotas/
4777	"hard"?: [string]: resource.#Quantity
4778
4779	// Used is the current observed total usage of the resource in the namespace.
4780	"used"?: [string]: resource.#Quantity
4781}
4782
4783// ResourceRequirements describes the compute resource requirements.
4784#ResourceRequirements: {
4785	// Claims lists the names of resources, defined in spec.resourceClaims, that are
4786	// used by this container.
4787	//
4788	// This field depends on the DynamicResourceAllocation feature gate.
4789	//
4790	// This field is immutable. It can only be set for containers.
4791	"claims"?: [...#ResourceClaim]
4792
4793	// Limits describes the maximum amount of compute resources allowed. More info:
4794	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
4795	"limits"?: [string]: resource.#Quantity
4796
4797	// Requests describes the minimum amount of compute resources required. If
4798	// Requests is omitted for a container, it defaults to Limits if that is
4799	// explicitly specified, otherwise to an implementation-defined value. Requests
4800	// cannot exceed Limits. More info:
4801	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
4802	"requests"?: [string]: resource.#Quantity
4803}
4804
4805// ResourceStatus represents the status of a single resource allocated to a Pod.
4806#ResourceStatus: {
4807	// Name of the resource. Must be unique within the pod and in case of non-DRA
4808	// resource, match one of the resources from the pod spec. For DRA resources,
4809	// the value must be "claim:<claim_name>/<request>". When this status is
4810	// reported about a container, the "claim_name" and "request" must match one of
4811	// the claims of this container.
4812	"name"!: string
4813
4814	// List of unique resources health. Each element in the list contains an unique
4815	// resource ID and its health. At a minimum, for the lifetime of a Pod,
4816	// resource ID must uniquely identify the resource allocated to the Pod on the
4817	// Node. If other Pod on the same Node reports the status with the same
4818	// resource ID, it must be the same resource they share. See ResourceID type
4819	// definition for a specific format it has in various use cases.
4820	"resources"?: [...#ResourceHealth]
4821}
4822
4823// SELinuxOptions are the labels to be applied to the container
4824#SELinuxOptions: {
4825	// Level is SELinux level label that applies to the container.
4826	"level"?: string
4827
4828	// Role is a SELinux role label that applies to the container.
4829	"role"?: string
4830
4831	// Type is a SELinux type label that applies to the container.
4832	"type"?: string
4833
4834	// User is a SELinux user label that applies to the container.
4835	"user"?: string
4836}
4837
4838// ScaleIOPersistentVolumeSource represents a persistent ScaleIO volume
4839#ScaleIOPersistentVolumeSource: {
4840	// fsType is the filesystem type to mount. Must be a filesystem type supported
4841	// by the host operating system. Ex. "ext4", "xfs", "ntfs". Default is "xfs"
4842	"fsType"?: string
4843
4844	// gateway is the host address of the ScaleIO API Gateway.
4845	"gateway"!: string
4846
4847	// protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.
4848	"protectionDomain"?: string
4849
4850	// readOnly defaults to false (read/write). ReadOnly here will force the
4851	// ReadOnly setting in VolumeMounts.
4852	"readOnly"?: bool
4853
4854	// secretRef references to the secret for ScaleIO user and other sensitive
4855	// information. If this is not provided, Login operation will fail.
4856	"secretRef"!: #SecretReference
4857
4858	// sslEnabled is the flag to enable/disable SSL communication with Gateway, default false
4859	"sslEnabled"?: bool
4860
4861	// storageMode indicates whether the storage for a volume should be
4862	// ThickProvisioned or ThinProvisioned. Default is ThinProvisioned.
4863	"storageMode"?: string
4864
4865	// storagePool is the ScaleIO Storage Pool associated with the protection domain.
4866	"storagePool"?: string
4867
4868	// system is the name of the storage system as configured in ScaleIO.
4869	"system"!: string
4870
4871	// volumeName is the name of a volume already created in the ScaleIO system that
4872	// is associated with this volume source.
4873	"volumeName"?: string
4874}
4875
4876// ScaleIOVolumeSource represents a persistent ScaleIO volume
4877#ScaleIOVolumeSource: {
4878	// fsType is the filesystem type to mount. Must be a filesystem type supported
4879	// by the host operating system. Ex. "ext4", "xfs", "ntfs". Default is "xfs".
4880	"fsType"?: string
4881
4882	// gateway is the host address of the ScaleIO API Gateway.
4883	"gateway"!: string
4884
4885	// protectionDomain is the name of the ScaleIO Protection Domain for the configured storage.
4886	"protectionDomain"?: string
4887
4888	// readOnly Defaults to false (read/write). ReadOnly here will force the
4889	// ReadOnly setting in VolumeMounts.
4890	"readOnly"?: bool
4891
4892	// secretRef references to the secret for ScaleIO user and other sensitive
4893	// information. If this is not provided, Login operation will fail.
4894	"secretRef"!: #LocalObjectReference
4895
4896	// sslEnabled Flag enable/disable SSL communication with Gateway, default false
4897	"sslEnabled"?: bool
4898
4899	// storageMode indicates whether the storage for a volume should be
4900	// ThickProvisioned or ThinProvisioned. Default is ThinProvisioned.
4901	"storageMode"?: string
4902
4903	// storagePool is the ScaleIO Storage Pool associated with the protection domain.
4904	"storagePool"?: string
4905
4906	// system is the name of the storage system as configured in ScaleIO.
4907	"system"!: string
4908
4909	// volumeName is the name of a volume already created in the ScaleIO system that
4910	// is associated with this volume source.
4911	"volumeName"?: string
4912}
4913
4914// A scope selector represents the AND of the selectors represented by the
4915// scoped-resource selector requirements.
4916#ScopeSelector: {
4917	// A list of scope selector requirements by scope of the resources.
4918	"matchExpressions"?: [...#ScopedResourceSelectorRequirement]
4919}
4920
4921// A scoped-resource selector requirement is a selector that contains values, a
4922// scope name, and an operator that relates the scope name and values.
4923#ScopedResourceSelectorRequirement: {
4924	// Represents a scope's relationship to a set of values. Valid operators are In,
4925	// NotIn, Exists, DoesNotExist.
4926	"operator"!: string
4927
4928	// The name of the scope that the selector applies to.
4929	"scopeName"!: string
4930
4931	// An array of string values. If the operator is In or NotIn, the values array
4932	// must be non-empty. If the operator is Exists or DoesNotExist, the values
4933	// array must be empty. This array is replaced during a strategic merge patch.
4934	"values"?: [...string]
4935}
4936
4937// SeccompProfile defines a pod/container's seccomp profile settings. Only one
4938// profile source may be set.
4939#SeccompProfile: {
4940	// localhostProfile indicates a profile defined in a file on the node should be
4941	// used. The profile must be preconfigured on the node to work. Must be a
4942	// descending path, relative to the kubelet's configured seccomp profile
4943	// location. Must be set if type is "Localhost". Must NOT be set for any other
4944	// type.
4945	"localhostProfile"?: string
4946
4947	// type indicates which kind of seccomp profile will be applied. Valid options are:
4948	//
4949	// Localhost - a profile defined in a file on the node should be used.
4950	// RuntimeDefault - the container runtime default profile should be used.
4951	// Unconfined - no profile should be applied.
4952	"type"!: string
4953}
4954
4955// Secret holds secret data of a certain type. The total bytes of the values in
4956// the Data field must be less than MaxSecretSize bytes.
4957#Secret: {
4958	// APIVersion defines the versioned schema of this representation of an object.
4959	// Servers should convert recognized schemas to the latest internal value, and
4960	// may reject unrecognized values. More info:
4961	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
4962	"apiVersion": "v1"
4963
4964	// Data contains the secret data. Each key must consist of alphanumeric
4965	// characters, '-', '_' or '.'. The serialized form of the secret data is a
4966	// base64 encoded string, representing the arbitrary (possibly non-string) data
4967	// value here. Described in https://tools.ietf.org/html/rfc4648#section-4
4968	"data"?: [string]: string
4969
4970	// Immutable, if set to true, ensures that data stored in the Secret cannot be
4971	// updated (only object metadata can be modified). If not set to true, the
4972	// field can be modified at any time. Defaulted to nil.
4973	"immutable"?: bool
4974
4975	// Kind is a string value representing the REST resource this object represents.
4976	// Servers may infer this from the endpoint the client submits requests to.
4977	// Cannot be updated. In CamelCase. More info:
4978	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
4979	"kind": "Secret"
4980
4981	// Standard object's metadata. More info:
4982	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
4983	"metadata"?: v1.#ObjectMeta
4984
4985	// stringData allows specifying non-binary secret data in string form. It is
4986	// provided as a write-only input field for convenience. All keys and values
4987	// are merged into the data field on write, overwriting any existing values.
4988	// The stringData field is never output when reading from the API.
4989	"stringData"?: [string]: string
4990
4991	// Used to facilitate programmatic handling of secret data. More info:
4992	// https://kubernetes.io/docs/concepts/configuration/secret/#secret-types
4993	"type"?: string
4994}
4995
4996// SecretEnvSource selects a Secret to populate the environment variables with.
4997//
4998// The contents of the target Secret's Data field will represent the key-value
4999// pairs as environment variables.
5000#SecretEnvSource: {
5001	// Name of the referent. This field is effectively required, but due to
5002	// backwards compatibility is allowed to be empty. Instances of this type with
5003	// an empty value here are almost certainly wrong. More info:
5004	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
5005	"name"?: string
5006
5007	// Specify whether the Secret must be defined
5008	"optional"?: bool
5009}
5010
5011// SecretKeySelector selects a key of a Secret.
5012#SecretKeySelector: {
5013	// The key of the secret to select from. Must be a valid secret key.
5014	"key"!: string
5015
5016	// Name of the referent. This field is effectively required, but due to
5017	// backwards compatibility is allowed to be empty. Instances of this type with
5018	// an empty value here are almost certainly wrong. More info:
5019	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
5020	"name"?: string
5021
5022	// Specify whether the Secret or its key must be defined
5023	"optional"?: bool
5024}
5025
5026// SecretList is a list of Secret.
5027#SecretList: {
5028	// APIVersion defines the versioned schema of this representation of an object.
5029	// Servers should convert recognized schemas to the latest internal value, and
5030	// may reject unrecognized values. More info:
5031	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5032	"apiVersion": "v1"
5033
5034	// Items is a list of secret objects. More info:
5035	// https://kubernetes.io/docs/concepts/configuration/secret
5036	"items"!: [...#Secret]
5037
5038	// Kind is a string value representing the REST resource this object represents.
5039	// Servers may infer this from the endpoint the client submits requests to.
5040	// Cannot be updated. In CamelCase. More info:
5041	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5042	"kind": "SecretList"
5043
5044	// Standard list metadata. More info:
5045	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5046	"metadata"?: v1.#ListMeta
5047}
5048
5049// Adapts a secret into a projected volume.
5050//
5051// The contents of the target Secret's Data field will be presented in a
5052// projected volume as files using the keys in the Data field as the file
5053// names. Note that this is identical to a secret volume source without the
5054// default mode.
5055#SecretProjection: {
5056	// items if unspecified, each key-value pair in the Data field of the referenced
5057	// Secret will be projected into the volume as a file whose name is the key and
5058	// content is the value. If specified, the listed keys will be projected into
5059	// the specified paths, and unlisted keys will not be present. If a key is
5060	// specified which is not present in the Secret, the volume setup will error
5061	// unless it is marked optional. Paths must be relative and may not contain the
5062	// '..' path or start with '..'.
5063	"items"?: [...#KeyToPath]
5064
5065	// Name of the referent. This field is effectively required, but due to
5066	// backwards compatibility is allowed to be empty. Instances of this type with
5067	// an empty value here are almost certainly wrong. More info:
5068	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
5069	"name"?: string
5070
5071	// optional field specify whether the Secret or its key must be defined
5072	"optional"?: bool
5073}
5074
5075// SecretReference represents a Secret Reference. It has enough information to
5076// retrieve secret in any namespace
5077#SecretReference: {
5078	// name is unique within a namespace to reference a secret resource.
5079	"name"?: string
5080
5081	// namespace defines the space within which the secret name must be unique.
5082	"namespace"?: string
5083}
5084
5085// Adapts a Secret into a volume.
5086//
5087// The contents of the target Secret's Data field will be presented in a volume
5088// as files using the keys in the Data field as the file names. Secret volumes
5089// support ownership management and SELinux relabeling.
5090#SecretVolumeSource: {
5091	// defaultMode is Optional: mode bits used to set permissions on created files
5092	// by default. Must be an octal value between 0000 and 0777 or a decimal value
5093	// between 0 and 511. YAML accepts both octal and decimal values, JSON requires
5094	// decimal values for mode bits. Defaults to 0644. Directories within the path
5095	// are not affected by this setting. This might be in conflict with other
5096	// options that affect the file mode, like fsGroup, and the result can be other
5097	// mode bits set.
5098	"defaultMode"?: int32 & int
5099
5100	// items If unspecified, each key-value pair in the Data field of the referenced
5101	// Secret will be projected into the volume as a file whose name is the key and
5102	// content is the value. If specified, the listed keys will be projected into
5103	// the specified paths, and unlisted keys will not be present. If a key is
5104	// specified which is not present in the Secret, the volume setup will error
5105	// unless it is marked optional. Paths must be relative and may not contain the
5106	// '..' path or start with '..'.
5107	"items"?: [...#KeyToPath]
5108
5109	// optional field specify whether the Secret or its keys must be defined
5110	"optional"?: bool
5111
5112	// secretName is the name of the secret in the pod's namespace to use. More
5113	// info: https://kubernetes.io/docs/concepts/storage/volumes#secret
5114	"secretName"?: string
5115}
5116
5117// SecurityContext holds security configuration that will be applied to a
5118// container. Some fields are present in both SecurityContext and
5119// PodSecurityContext. When both are set, the values in SecurityContext take
5120// precedence.
5121#SecurityContext: {
5122	// AllowPrivilegeEscalation controls whether a process can gain more privileges
5123	// than its parent process. This bool directly controls if the no_new_privs
5124	// flag will be set on the container process. AllowPrivilegeEscalation is true
5125	// always when the container is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note
5126	// that this field cannot be set when spec.os.name is windows.
5127	"allowPrivilegeEscalation"?: bool
5128
5129	// appArmorProfile is the AppArmor options to use by this container. If set,
5130	// this profile overrides the pod's appArmorProfile. Note that this field
5131	// cannot be set when spec.os.name is windows.
5132	"appArmorProfile"?: #AppArmorProfile
5133
5134	// The capabilities to add/drop when running containers. Defaults to the default
5135	// set of capabilities granted by the container runtime. Note that this field
5136	// cannot be set when spec.os.name is windows.
5137	"capabilities"?: #Capabilities
5138
5139	// Run container in privileged mode. Processes in privileged containers are
5140	// essentially equivalent to root on the host. Defaults to false. Note that
5141	// this field cannot be set when spec.os.name is windows.
5142	"privileged"?: bool
5143
5144	// procMount denotes the type of proc mount to use for the containers. The
5145	// default value is Default which uses the container runtime defaults for
5146	// readonly paths and masked paths. Note that this field cannot be set when
5147	// spec.os.name is windows.
5148	"procMount"?: string
5149
5150	// Whether this container has a read-only root filesystem. Default is false.
5151	// Note that this field cannot be set when spec.os.name is windows.
5152	"readOnlyRootFilesystem"?: bool
5153
5154	// The GID to run the entrypoint of the container process. Uses runtime default
5155	// if unset. May also be set in PodSecurityContext. If set in both
5156	// SecurityContext and PodSecurityContext, the value specified in
5157	// SecurityContext takes precedence. Note that this field cannot be set when
5158	// spec.os.name is windows.
5159	"runAsGroup"?: int64 & int
5160
5161	// Indicates that the container must run as a non-root user. If true, the
5162	// Kubelet will validate the image at runtime to ensure that it does not run as
5163	// UID 0 (root) and fail to start the container if it does. If unset or false,
5164	// no such validation will be performed. May also be set in PodSecurityContext.
5165	// If set in both SecurityContext and PodSecurityContext, the value specified
5166	// in SecurityContext takes precedence.
5167	"runAsNonRoot"?: bool
5168
5169	// The UID to run the entrypoint of the container process. Defaults to user
5170	// specified in image metadata if unspecified. May also be set in
5171	// PodSecurityContext. If set in both SecurityContext and PodSecurityContext,
5172	// the value specified in SecurityContext takes precedence. Note that this
5173	// field cannot be set when spec.os.name is windows.
5174	"runAsUser"?: int64 & int
5175
5176	// The SELinux context to be applied to the container. If unspecified, the
5177	// container runtime will allocate a random SELinux context for each container.
5178	// May also be set in PodSecurityContext. If set in both SecurityContext and
5179	// PodSecurityContext, the value specified in SecurityContext takes precedence.
5180	// Note that this field cannot be set when spec.os.name is windows.
5181	"seLinuxOptions"?: #SELinuxOptions
5182
5183	// The seccomp options to use by this container. If seccomp options are provided
5184	// at both the pod & container level, the container options override the pod
5185	// options. Note that this field cannot be set when spec.os.name is windows.
5186	"seccompProfile"?: #SeccompProfile
5187
5188	// The Windows specific settings applied to all containers. If unspecified, the
5189	// options from the PodSecurityContext will be used. If set in both
5190	// SecurityContext and PodSecurityContext, the value specified in
5191	// SecurityContext takes precedence. Note that this field cannot be set when
5192	// spec.os.name is linux.
5193	"windowsOptions"?: #WindowsSecurityContextOptions
5194}
5195
5196// Service is a named abstraction of software service (for example, mysql)
5197// consisting of local port (for example 3306) that the proxy listens on, and
5198// the selector that determines which pods will answer requests sent through
5199// the proxy.
5200#Service: {
5201	// APIVersion defines the versioned schema of this representation of an object.
5202	// Servers should convert recognized schemas to the latest internal value, and
5203	// may reject unrecognized values. More info:
5204	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5205	"apiVersion": "v1"
5206
5207	// Kind is a string value representing the REST resource this object represents.
5208	// Servers may infer this from the endpoint the client submits requests to.
5209	// Cannot be updated. In CamelCase. More info:
5210	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5211	"kind": "Service"
5212
5213	// Standard object's metadata. More info:
5214	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
5215	"metadata"?: v1.#ObjectMeta
5216
5217	// Spec defines the behavior of a service.
5218	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
5219	"spec"?: #ServiceSpec
5220
5221	// Most recently observed status of the service. Populated by the system.
5222	// Read-only. More info:
5223	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
5224	"status"?: #ServiceStatus
5225}
5226
5227// ServiceAccount binds together: * a name, understood by users, and perhaps by
5228// peripheral systems, for an identity * a principal that can be authenticated
5229// and authorized * a set of secrets
5230#ServiceAccount: {
5231	// APIVersion defines the versioned schema of this representation of an object.
5232	// Servers should convert recognized schemas to the latest internal value, and
5233	// may reject unrecognized values. More info:
5234	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5235	"apiVersion": "v1"
5236
5237	// AutomountServiceAccountToken indicates whether pods running as this service
5238	// account should have an API token automatically mounted. Can be overridden at
5239	// the pod level.
5240	"automountServiceAccountToken"?: bool
5241
5242	// ImagePullSecrets is a list of references to secrets in the same namespace to
5243	// use for pulling any images in pods that reference this ServiceAccount.
5244	// ImagePullSecrets are distinct from Secrets because Secrets can be mounted in
5245	// the pod, but ImagePullSecrets are only accessed by the kubelet. More info:
5246	// https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
5247	"imagePullSecrets"?: [...#LocalObjectReference]
5248
5249	// Kind is a string value representing the REST resource this object represents.
5250	// Servers may infer this from the endpoint the client submits requests to.
5251	// Cannot be updated. In CamelCase. More info:
5252	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5253	"kind": "ServiceAccount"
5254
5255	// Standard object's metadata. More info:
5256	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
5257	"metadata"?: v1.#ObjectMeta
5258
5259	// Secrets is a list of the secrets in the same namespace that pods running
5260	// using this ServiceAccount are allowed to use. Pods are only limited to this
5261	// list if this service account has a "kubernetes.io/enforce-mountable-secrets"
5262	// annotation set to "true". The "kubernetes.io/enforce-mountable-secrets"
5263	// annotation is deprecated since v1.32. Prefer separate namespaces to isolate
5264	// access to mounted secrets. This field should not be used to find
5265	// auto-generated service account token secrets for use outside of pods.
5266	// Instead, tokens can be requested directly using the TokenRequest API, or
5267	// service account token secrets can be manually created. More info:
5268	// https://kubernetes.io/docs/concepts/configuration/secret
5269	"secrets"?: [...#ObjectReference]
5270}
5271
5272// ServiceAccountList is a list of ServiceAccount objects
5273#ServiceAccountList: {
5274	// APIVersion defines the versioned schema of this representation of an object.
5275	// Servers should convert recognized schemas to the latest internal value, and
5276	// may reject unrecognized values. More info:
5277	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5278	"apiVersion": "v1"
5279
5280	// List of ServiceAccounts. More info:
5281	// https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
5282	"items"!: [...#ServiceAccount]
5283
5284	// Kind is a string value representing the REST resource this object represents.
5285	// Servers may infer this from the endpoint the client submits requests to.
5286	// Cannot be updated. In CamelCase. More info:
5287	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5288	"kind": "ServiceAccountList"
5289
5290	// Standard list metadata. More info:
5291	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5292	"metadata"?: v1.#ListMeta
5293}
5294
5295// ServiceAccountTokenProjection represents a projected service account token
5296// volume. This projection can be used to insert a service account token into
5297// the pods runtime filesystem for use against APIs (Kubernetes API Server or
5298// otherwise).
5299#ServiceAccountTokenProjection: {
5300	// audience is the intended audience of the token. A recipient of a token must
5301	// identify itself with an identifier specified in the audience of the token,
5302	// and otherwise should reject the token. The audience defaults to the
5303	// identifier of the apiserver.
5304	"audience"?: string
5305
5306	// expirationSeconds is the requested duration of validity of the service
5307	// account token. As the token approaches expiration, the kubelet volume plugin
5308	// will proactively rotate the service account token. The kubelet will start
5309	// trying to rotate the token if the token is older than 80 percent of its time
5310	// to live or if the token is older than 24 hours.Defaults to 1 hour and must
5311	// be at least 10 minutes.
5312	"expirationSeconds"?: int64 & int
5313
5314	// path is the path relative to the mount point of the file to project the token into.
5315	"path"!: string
5316}
5317
5318// ServiceList holds a list of services.
5319#ServiceList: {
5320	// APIVersion defines the versioned schema of this representation of an object.
5321	// Servers should convert recognized schemas to the latest internal value, and
5322	// may reject unrecognized values. More info:
5323	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
5324	"apiVersion": "v1"
5325
5326	// List of services
5327	"items"!: [...#Service]
5328
5329	// Kind is a string value representing the REST resource this object represents.
5330	// Servers may infer this from the endpoint the client submits requests to.
5331	// Cannot be updated. In CamelCase. More info:
5332	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5333	"kind": "ServiceList"
5334
5335	// Standard list metadata. More info:
5336	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
5337	"metadata"?: v1.#ListMeta
5338}
5339
5340// ServicePort contains information on service's port.
5341#ServicePort: {
5342	// The application protocol for this port. This is used as a hint for
5343	// implementations to offer richer behavior for protocols that they understand.
5344	// This field follows standard Kubernetes label syntax. Valid values are
5345	// either:
5346	//
5347	// * Un-prefixed protocol names - reserved for IANA standard service names (as
5348	// per RFC-6335 and https://www.iana.org/assignments/service-names).
5349	//
5350	// * Kubernetes-defined prefixed names:
5351	// * 'kubernetes.io/h2c' - HTTP/2 prior knowledge over cleartext as described in
5352	// https://www.rfc-editor.org/rfc/rfc9113.html#name-starting-http-2-with-prior-
5353	// * 'kubernetes.io/ws' - WebSocket over cleartext as described in
5354	// https://www.rfc-editor.org/rfc/rfc6455
5355	// * 'kubernetes.io/wss' - WebSocket over TLS as described in https://www.rfc-editor.org/rfc/rfc6455
5356	//
5357	// * Other protocols should use implementation-defined prefixed names such as
5358	// mycompany.com/my-custom-protocol.
5359	"appProtocol"?: string
5360
5361	// The name of this port within the service. This must be a DNS_LABEL. All ports
5362	// within a ServiceSpec must have unique names. When considering the endpoints
5363	// for a Service, this must match the 'name' field in the EndpointPort.
5364	// Optional if only one ServicePort is defined on this service.
5365	"name"?: string
5366
5367	// The port on each node on which this service is exposed when type is NodePort
5368	// or LoadBalancer. Usually assigned by the system. If a value is specified,
5369	// in-range, and not in use it will be used, otherwise the operation will fail.
5370	// If not specified, a port will be allocated if this Service requires one. If
5371	// this field is specified when creating a Service which does not need it,
5372	// creation will fail. This field will be wiped when updating a Service to no
5373	// longer need it (e.g. changing type from NodePort to ClusterIP). More info:
5374	// https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
5375	"nodePort"?: int32 & int
5376
5377	// The port that will be exposed by this service.
5378	"port"!: int32 & int
5379
5380	// The IP protocol for this port. Supports "TCP", "UDP", and "SCTP". Default is TCP.
5381	"protocol"?: string
5382
5383	// Number or name of the port to access on the pods targeted by the service.
5384	// Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. If
5385	// this is a string, it will be looked up as a named port in the target Pod's
5386	// container ports. If this is not specified, the value of the 'port' field is
5387	// used (an identity map). This field is ignored for services with
5388	// clusterIP=None, and should be omitted or set equal to the 'port' field. More
5389	// info:
5390	// https://kubernetes.io/docs/concepts/services-networking/service/#defining-a-service
5391	"targetPort"?: intstr.#IntOrString
5392}
5393
5394// ServiceSpec describes the attributes that a user creates on a service.
5395#ServiceSpec: {
5396	// allocateLoadBalancerNodePorts defines if NodePorts will be automatically
5397	// allocated for services with type LoadBalancer. Default is "true". It may be
5398	// set to "false" if the cluster load-balancer does not rely on NodePorts. If
5399	// the caller requests specific NodePorts (by specifying a value), those
5400	// requests will be respected, regardless of this field. This field may only be
5401	// set for services with type LoadBalancer and will be cleared if the type is
5402	// changed to any other type.
5403	"allocateLoadBalancerNodePorts"?: bool
5404
5405	// clusterIP is the IP address of the service and is usually assigned randomly.
5406	// If an address is specified manually, is in-range (as per system
5407	// configuration), and is not in use, it will be allocated to the service;
5408	// otherwise creation of the service will fail. This field may not be changed
5409	// through updates unless the type field is also being changed to ExternalName
5410	// (which requires this field to be blank) or the type field is being changed
5411	// from ExternalName (in which case this field may optionally be specified, as
5412	// describe above). Valid values are "None", empty string (""), or a valid IP
5413	// address. Setting this to "None" makes a "headless service" (no virtual IP),
5414	// which is useful when direct endpoint connections are preferred and proxying
5415	// is not required. Only applies to types ClusterIP, NodePort, and
5416	// LoadBalancer. If this field is specified when creating a Service of type
5417	// ExternalName, creation will fail. This field will be wiped when updating a
5418	// Service to type ExternalName. More info:
5419	// https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5420	"clusterIP"?: string
5421
5422	// ClusterIPs is a list of IP addresses assigned to this service, and are
5423	// usually assigned randomly. If an address is specified manually, is in-range
5424	// (as per system configuration), and is not in use, it will be allocated to
5425	// the service; otherwise creation of the service will fail. This field may not
5426	// be changed through updates unless the type field is also being changed to
5427	// ExternalName (which requires this field to be empty) or the type field is
5428	// being changed from ExternalName (in which case this field may optionally be
5429	// specified, as describe above). Valid values are "None", empty string (""),
5430	// or a valid IP address. Setting this to "None" makes a "headless service" (no
5431	// virtual IP), which is useful when direct endpoint connections are preferred
5432	// and proxying is not required. Only applies to types ClusterIP, NodePort, and
5433	// LoadBalancer. If this field is specified when creating a Service of type
5434	// ExternalName, creation will fail. This field will be wiped when updating a
5435	// Service to type ExternalName. If this field is not specified, it will be
5436	// initialized from the clusterIP field. If this field is specified, clients
5437	// must ensure that clusterIPs[0] and clusterIP have the same value.
5438	//
5439	// This field may hold a maximum of two entries (dual-stack IPs, in either
5440	// order). These IPs must correspond to the values of the ipFamilies field.
5441	// Both clusterIPs and ipFamilies are governed by the ipFamilyPolicy field.
5442	// More info:
5443	// https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5444	"clusterIPs"?: [...string]
5445
5446	// externalIPs is a list of IP addresses for which nodes in the cluster will
5447	// also accept traffic for this service. These IPs are not managed by
5448	// Kubernetes. The user is responsible for ensuring that traffic arrives at a
5449	// node with this IP. A common example is external load-balancers that are not
5450	// part of the Kubernetes system.
5451	"externalIPs"?: [...string]
5452
5453	// externalName is the external reference that discovery mechanisms will return
5454	// as an alias for this service (e.g. a DNS CNAME record). No proxying will be
5455	// involved. Must be a lowercase RFC-1123 hostname
5456	// (https://tools.ietf.org/html/rfc1123) and requires `type` to be
5457	// "ExternalName".
5458	"externalName"?: string
5459
5460	// externalTrafficPolicy describes how nodes distribute service traffic they
5461	// receive on one of the Service's "externally-facing" addresses (NodePorts,
5462	// ExternalIPs, and LoadBalancer IPs). If set to "Local", the proxy will
5463	// configure the service in a way that assumes that external load balancers
5464	// will take care of balancing the service traffic between nodes, and so each
5465	// node will deliver traffic only to the node-local endpoints of the service,
5466	// without masquerading the client source IP. (Traffic mistakenly sent to a
5467	// node with no endpoints will be dropped.) The default value, "Cluster", uses
5468	// the standard behavior of routing to all endpoints evenly (possibly modified
5469	// by topology and other features). Note that traffic sent to an External IP or
5470	// LoadBalancer IP from within the cluster will always get "Cluster" semantics,
5471	// but clients sending to a NodePort from within the cluster may need to take
5472	// traffic policy into account when picking a node.
5473	"externalTrafficPolicy"?: string
5474
5475	// healthCheckNodePort specifies the healthcheck nodePort for the service. This
5476	// only applies when type is set to LoadBalancer and externalTrafficPolicy is
5477	// set to Local. If a value is specified, is in-range, and is not in use, it
5478	// will be used. If not specified, a value will be automatically allocated.
5479	// External systems (e.g. load-balancers) can use this port to determine if a
5480	// given node holds endpoints for this service or not. If this field is
5481	// specified when creating a Service which does not need it, creation will
5482	// fail. This field will be wiped when updating a Service to no longer need it
5483	// (e.g. changing type). This field cannot be updated once set.
5484	"healthCheckNodePort"?: int32 & int
5485
5486	// InternalTrafficPolicy describes how nodes distribute service traffic they
5487	// receive on the ClusterIP. If set to "Local", the proxy will assume that pods
5488	// only want to talk to endpoints of the service on the same node as the pod,
5489	// dropping the traffic if there are no local endpoints. The default value,
5490	// "Cluster", uses the standard behavior of routing to all endpoints evenly
5491	// (possibly modified by topology and other features).
5492	"internalTrafficPolicy"?: string
5493
5494	// IPFamilies is a list of IP families (e.g. IPv4, IPv6) assigned to this
5495	// service. This field is usually assigned automatically based on cluster
5496	// configuration and the ipFamilyPolicy field. If this field is specified
5497	// manually, the requested family is available in the cluster, and
5498	// ipFamilyPolicy allows it, it will be used; otherwise creation of the service
5499	// will fail. This field is conditionally mutable: it allows for adding or
5500	// removing a secondary IP family, but it does not allow changing the primary
5501	// IP family of the Service. Valid values are "IPv4" and "IPv6". This field
5502	// only applies to Services of types ClusterIP, NodePort, and LoadBalancer, and
5503	// does apply to "headless" services. This field will be wiped when updating a
5504	// Service to type ExternalName.
5505	//
5506	// This field may hold a maximum of two entries (dual-stack families, in either
5507	// order). These families must correspond to the values of the clusterIPs
5508	// field, if specified. Both clusterIPs and ipFamilies are governed by the
5509	// ipFamilyPolicy field.
5510	"ipFamilies"?: [...string]
5511
5512	// IPFamilyPolicy represents the dual-stack-ness requested or required by this
5513	// Service. If there is no value provided, then this field will be set to
5514	// SingleStack. Services can be "SingleStack" (a single IP family),
5515	// "PreferDualStack" (two IP families on dual-stack configured clusters or a
5516	// single IP family on single-stack clusters), or "RequireDualStack" (two IP
5517	// families on dual-stack configured clusters, otherwise fail). The ipFamilies
5518	// and clusterIPs fields depend on the value of this field. This field will be
5519	// wiped when updating a service to type ExternalName.
5520	"ipFamilyPolicy"?: string
5521
5522	// loadBalancerClass is the class of the load balancer implementation this
5523	// Service belongs to. If specified, the value of this field must be a
5524	// label-style identifier, with an optional prefix, e.g. "internal-vip" or
5525	// "example.com/internal-vip". Unprefixed names are reserved for end-users.
5526	// This field can only be set when the Service type is 'LoadBalancer'. If not
5527	// set, the default load balancer implementation is used, today this is
5528	// typically done through the cloud provider integration, but should apply for
5529	// any default implementation. If set, it is assumed that a load balancer
5530	// implementation is watching for Services with a matching class. Any default
5531	// load balancer implementation (e.g. cloud providers) should ignore Services
5532	// that set this field. This field can only be set when creating or updating a
5533	// Service to type 'LoadBalancer'. Once set, it can not be changed. This field
5534	// will be wiped when a service is updated to a non 'LoadBalancer' type.
5535	"loadBalancerClass"?: string
5536
5537	// Only applies to Service Type: LoadBalancer. This feature depends on whether
5538	// the underlying cloud-provider supports specifying the loadBalancerIP when a
5539	// load balancer is created. This field will be ignored if the cloud-provider
5540	// does not support the feature. Deprecated: This field was under-specified and
5541	// its meaning varies across implementations. Using it is non-portable and it
5542	// may not support dual-stack. Users are encouraged to use
5543	// implementation-specific annotations when available.
5544	"loadBalancerIP"?: string
5545
5546	// If specified and supported by the platform, this will restrict traffic
5547	// through the cloud-provider load-balancer will be restricted to the specified
5548	// client IPs. This field will be ignored if the cloud-provider does not
5549	// support the feature." More info:
5550	// https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/
5551	"loadBalancerSourceRanges"?: [...string]
5552
5553	// The list of ports that are exposed by this service. More info:
5554	// https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5555	"ports"?: [...#ServicePort]
5556
5557	// publishNotReadyAddresses indicates that any agent which deals with endpoints
5558	// for this Service should disregard any indications of ready/not-ready. The
5559	// primary use case for setting this field is for a StatefulSet's Headless
5560	// Service to propagate SRV DNS records for its Pods for the purpose of peer
5561	// discovery. The Kubernetes controllers that generate Endpoints and
5562	// EndpointSlice resources for Services interpret this to mean that all
5563	// endpoints are considered "ready" even if the Pods themselves are not. Agents
5564	// which consume only Kubernetes generated endpoints through the Endpoints or
5565	// EndpointSlice resources can safely assume this behavior.
5566	"publishNotReadyAddresses"?: bool
5567
5568	// Route service traffic to pods with label keys and values matching this
5569	// selector. If empty or not present, the service is assumed to have an
5570	// external process managing its endpoints, which Kubernetes will not modify.
5571	// Only applies to types ClusterIP, NodePort, and LoadBalancer. Ignored if type
5572	// is ExternalName. More info:
5573	// https://kubernetes.io/docs/concepts/services-networking/service/
5574	"selector"?: [string]: string
5575
5576	// Supports "ClientIP" and "None". Used to maintain session affinity. Enable
5577	// client IP based session affinity. Must be ClientIP or None. Defaults to
5578	// None. More info:
5579	// https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
5580	"sessionAffinity"?: string
5581
5582	// sessionAffinityConfig contains the configurations of session affinity.
5583	"sessionAffinityConfig"?: #SessionAffinityConfig
5584
5585	// TrafficDistribution offers a way to express preferences for how traffic is
5586	// distributed to Service endpoints. Implementations can use this field as a
5587	// hint, but are not required to guarantee strict adherence. If the field is
5588	// not set, the implementation will apply its default routing strategy. If set
5589	// to "PreferClose", implementations should prioritize endpoints that are in
5590	// the same zone.
5591	"trafficDistribution"?: string
5592
5593	// type determines how the Service is exposed. Defaults to ClusterIP. Valid
5594	// options are ExternalName, ClusterIP, NodePort, and LoadBalancer. "ClusterIP"
5595	// allocates a cluster-internal IP address for load-balancing to endpoints.
5596	// Endpoints are determined by the selector or if that is not specified, by
5597	// manual construction of an Endpoints object or EndpointSlice objects. If
5598	// clusterIP is "None", no virtual IP is allocated and the endpoints are
5599	// published as a set of endpoints rather than a virtual IP. "NodePort" builds
5600	// on ClusterIP and allocates a port on every node which routes to the same
5601	// endpoints as the clusterIP. "LoadBalancer" builds on NodePort and creates an
5602	// external load-balancer (if supported in the current cloud) which routes to
5603	// the same endpoints as the clusterIP. "ExternalName" aliases this service to
5604	// the specified externalName. Several other fields do not apply to
5605	// ExternalName services. More info:
5606	// https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types
5607	"type"?: string
5608}
5609
5610// ServiceStatus represents the current status of a service.
5611#ServiceStatus: {
5612	// Current service state
5613	"conditions"?: [...v1.#Condition]
5614
5615	// LoadBalancer contains the current status of the load-balancer, if one is present.
5616	"loadBalancer"?: #LoadBalancerStatus
5617}
5618
5619// SessionAffinityConfig represents the configurations of session affinity.
5620#SessionAffinityConfig: {
5621	// clientIP contains the configurations of Client IP based session affinity.
5622	"clientIP"?: #ClientIPConfig
5623}
5624
5625// SleepAction describes a "sleep" action.
5626#SleepAction: {
5627	// Seconds is the number of seconds to sleep.
5628	"seconds"!: int64 & int
5629}
5630
5631// Represents a StorageOS persistent volume resource.
5632#StorageOSPersistentVolumeSource: {
5633	// fsType is the filesystem type to mount. Must be a filesystem type supported
5634	// by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
5635	// to be "ext4" if unspecified.
5636	"fsType"?: string
5637
5638	// readOnly defaults to false (read/write). ReadOnly here will force the
5639	// ReadOnly setting in VolumeMounts.
5640	"readOnly"?: bool
5641
5642	// secretRef specifies the secret to use for obtaining the StorageOS API
5643	// credentials. If not specified, default values will be attempted.
5644	"secretRef"?: #ObjectReference
5645
5646	// volumeName is the human-readable name of the StorageOS volume. Volume names
5647	// are only unique within a namespace.
5648	"volumeName"?: string
5649
5650	// volumeNamespace specifies the scope of the volume within StorageOS. If no
5651	// namespace is specified then the Pod's namespace will be used. This allows
5652	// the Kubernetes name scoping to be mirrored within StorageOS for tighter
5653	// integration. Set VolumeName to any name to override the default behaviour.
5654	// Set to "default" if you are not using namespaces within StorageOS.
5655	// Namespaces that do not pre-exist within StorageOS will be created.
5656	"volumeNamespace"?: string
5657}
5658
5659// Represents a StorageOS persistent volume resource.
5660#StorageOSVolumeSource: {
5661	// fsType is the filesystem type to mount. Must be a filesystem type supported
5662	// by the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred
5663	// to be "ext4" if unspecified.
5664	"fsType"?: string
5665
5666	// readOnly defaults to false (read/write). ReadOnly here will force the
5667	// ReadOnly setting in VolumeMounts.
5668	"readOnly"?: bool
5669
5670	// secretRef specifies the secret to use for obtaining the StorageOS API
5671	// credentials. If not specified, default values will be attempted.
5672	"secretRef"?: #LocalObjectReference
5673
5674	// volumeName is the human-readable name of the StorageOS volume. Volume names
5675	// are only unique within a namespace.
5676	"volumeName"?: string
5677
5678	// volumeNamespace specifies the scope of the volume within StorageOS. If no
5679	// namespace is specified then the Pod's namespace will be used. This allows
5680	// the Kubernetes name scoping to be mirrored within StorageOS for tighter
5681	// integration. Set VolumeName to any name to override the default behaviour.
5682	// Set to "default" if you are not using namespaces within StorageOS.
5683	// Namespaces that do not pre-exist within StorageOS will be created.
5684	"volumeNamespace"?: string
5685}
5686
5687// Sysctl defines a kernel parameter to be set
5688#Sysctl: {
5689	// Name of a property to set
5690	"name"!: string
5691
5692	// Value of a property to set
5693	"value"!: string
5694}
5695
5696// TCPSocketAction describes an action based on opening a socket
5697#TCPSocketAction: {
5698	// Optional: Host name to connect to, defaults to the pod IP.
5699	"host"?: string
5700
5701	// Number or name of the port to access on the container. Number must be in the
5702	// range 1 to 65535. Name must be an IANA_SVC_NAME.
5703	"port"!: intstr.#IntOrString
5704}
5705
5706// The node this Taint is attached to has the "effect" on any pod that does not tolerate the Taint.
5707#Taint: {
5708	// Required. The effect of the taint on pods that do not tolerate the taint.
5709	// Valid effects are NoSchedule, PreferNoSchedule and NoExecute.
5710	"effect"!: string
5711
5712	// Required. The taint key to be applied to a node.
5713	"key"!: string
5714
5715	// TimeAdded represents the time at which the taint was added.
5716	"timeAdded"?: v1.#Time
5717
5718	// The taint value corresponding to the taint key.
5719	"value"?: string
5720}
5721
5722// The pod this Toleration is attached to tolerates any taint that matches the
5723// triple <key,value,effect> using the matching operator <operator>.
5724#Toleration: {
5725	// Effect indicates the taint effect to match. Empty means match all taint
5726	// effects. When specified, allowed values are NoSchedule, PreferNoSchedule and
5727	// NoExecute.
5728	"effect"?: string
5729
5730	// Key is the taint key that the toleration applies to. Empty means match all
5731	// taint keys. If the key is empty, operator must be Exists; this combination
5732	// means to match all values and all keys.
5733	"key"?: string
5734
5735	// Operator represents a key's relationship to the value. Valid operators are
5736	// Exists, Equal, Lt, and Gt. Defaults to Equal. Exists is equivalent to
5737	// wildcard for value, so that a pod can tolerate all taints of a particular
5738	// category. Lt and Gt perform numeric comparisons (requires feature gate
5739	// TaintTolerationComparisonOperators).
5740	"operator"?: string
5741
5742	// TolerationSeconds represents the period of time the toleration (which must be
5743	// of effect NoExecute, otherwise this field is ignored) tolerates the taint.
5744	// By default, it is not set, which means tolerate the taint forever (do not
5745	// evict). Zero and negative values will be treated as 0 (evict immediately) by
5746	// the system.
5747	"tolerationSeconds"?: int64 & int
5748
5749	// Value is the taint value the toleration matches to. If the operator is
5750	// Exists, the value should be empty, otherwise just a regular string.
5751	"value"?: string
5752}
5753
5754// A topology selector requirement is a selector that matches given label. This
5755// is an alpha feature and may change in the future.
5756#TopologySelectorLabelRequirement: {
5757	// The label key that the selector applies to.
5758	"key"!: string
5759
5760	// An array of string values. One value must match the label to be selected.
5761	// Each entry in Values is ORed.
5762	"values"!: [...string]
5763}
5764
5765// A topology selector term represents the result of label queries. A null or
5766// empty topology selector term matches no objects. The requirements of them
5767// are ANDed. It provides a subset of functionality as NodeSelectorTerm. This
5768// is an alpha feature and may change in the future.
5769#TopologySelectorTerm: {
5770	// A list of topology selector requirements by labels.
5771	"matchLabelExpressions"?: [...#TopologySelectorLabelRequirement]
5772}
5773
5774// TopologySpreadConstraint specifies how to spread matching pods among the given topology.
5775#TopologySpreadConstraint: {
5776	// LabelSelector is used to find matching pods. Pods that match this label
5777	// selector are counted to determine the number of pods in their corresponding
5778	// topology domain.
5779	"labelSelector"?: v1.#LabelSelector
5780
5781	// MatchLabelKeys is a set of pod label keys to select the pods over which
5782	// spreading will be calculated. The keys are used to lookup values from the
5783	// incoming pod labels, those key-value labels are ANDed with labelSelector to
5784	// select the group of existing pods over which spreading will be calculated
5785	// for the incoming pod. The same key is forbidden to exist in both
5786	// MatchLabelKeys and LabelSelector. MatchLabelKeys cannot be set when
5787	// LabelSelector isn't set. Keys that don't exist in the incoming pod labels
5788	// will be ignored. A null or empty list means only match against
5789	// labelSelector.
5790	//
5791	// This is a beta field and requires the MatchLabelKeysInPodTopologySpread
5792	// feature gate to be enabled (enabled by default).
5793	"matchLabelKeys"?: [...string]
5794
5795	// MaxSkew describes the degree to which pods may be unevenly distributed. When
5796	// `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference
5797	// between the number of matching pods in the target topology and the global
5798	// minimum. The global minimum is the minimum number of matching pods in an
5799	// eligible domain or zero if the number of eligible domains is less than
5800	// MinDomains. For example, in a 3-zone cluster, MaxSkew is set to 1, and pods
5801	// with the same labelSelector spread as 2/2/1: In this case, the global
5802	// minimum is 1. | zone1 | zone2 | zone3 | | P P | P P | P | - if MaxSkew is 1,
5803	// incoming pod can only be scheduled to zone3 to become 2/2/2; scheduling it
5804	// onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2) violate
5805	// MaxSkew(1). - if MaxSkew is 2, incoming pod can be scheduled onto any zone.
5806	// When `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher
5807	// precedence to topologies that satisfy it. It's a required field. Default
5808	// value is 1 and 0 is not allowed.
5809	"maxSkew"!: int32 & int
5810
5811	// MinDomains indicates a minimum number of eligible domains. When the number of
5812	// eligible domains with matching topology keys is less than minDomains, Pod
5813	// Topology Spread treats "global minimum" as 0, and then the calculation of
5814	// Skew is performed. And when the number of eligible domains with matching
5815	// topology keys equals or greater than minDomains, this value has no effect on
5816	// scheduling. As a result, when the number of eligible domains is less than
5817	// minDomains, scheduler won't schedule more than maxSkew Pods to those
5818	// domains. If value is nil, the constraint behaves as if MinDomains is equal
5819	// to 1. Valid values are integers greater than 0. When value is not nil,
5820	// WhenUnsatisfiable must be DoNotSchedule.
5821	//
5822	// For example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5
5823	// and pods with the same labelSelector spread as 2/2/2: | zone1 | zone2 |
5824	// zone3 | | P P | P P | P P | The number of domains is less than
5825	// 5(MinDomains), so "global minimum" is treated as 0. In this situation, new
5826	// pod with the same labelSelector cannot be scheduled, because computed skew
5827	// will be 3(3 - 0) if new Pod is scheduled to any of the three zones, it will
5828	// violate MaxSkew.
5829	"minDomains"?: int32 & int
5830
5831	// NodeAffinityPolicy indicates how we will treat Pod's
5832	// nodeAffinity/nodeSelector when calculating pod topology spread skew. Options
5833	// are: - Honor: only nodes matching nodeAffinity/nodeSelector are included in
5834	// the calculations. - Ignore: nodeAffinity/nodeSelector are ignored. All nodes
5835	// are included in the calculations.
5836	//
5837	// If this value is nil, the behavior is equivalent to the Honor policy.
5838	"nodeAffinityPolicy"?: string
5839
5840	// NodeTaintsPolicy indicates how we will treat node taints when calculating pod
5841	// topology spread skew. Options are: - Honor: nodes without taints, along with
5842	// tainted nodes for which the incoming pod has a toleration, are included. -
5843	// Ignore: node taints are ignored. All nodes are included.
5844	//
5845	// If this value is nil, the behavior is equivalent to the Ignore policy.
5846	"nodeTaintsPolicy"?: string
5847
5848	// TopologyKey is the key of node labels. Nodes that have a label with this key
5849	// and identical values are considered to be in the same topology. We consider
5850	// each <key, value> as a "bucket", and try to put balanced number of pods into
5851	// each bucket. We define a domain as a particular instance of a topology.
5852	// Also, we define an eligible domain as a domain whose nodes meet the
5853	// requirements of nodeAffinityPolicy and nodeTaintsPolicy. e.g. If TopologyKey
5854	// is "kubernetes.io/hostname", each Node is a domain of that topology. And, if
5855	// TopologyKey is "topology.kubernetes.io/zone", each zone is a domain of that
5856	// topology. It's a required field.
5857	"topologyKey"!: string
5858
5859	// WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy the
5860	// spread constraint. - DoNotSchedule (default) tells the scheduler not to
5861	// schedule it. - ScheduleAnyway tells the scheduler to schedule the pod in any
5862	// location,
5863	// but giving higher precedence to topologies that would help reduce the
5864	// skew.
5865	// A constraint is considered "Unsatisfiable" for an incoming pod if and only if
5866	// every possible node assignment for that pod would violate "MaxSkew" on some
5867	// topology. For example, in a 3-zone cluster, MaxSkew is set to 1, and pods
5868	// with the same labelSelector spread as 3/1/1: | zone1 | zone2 | zone3 | | P P
5869	// P | P | P | If WhenUnsatisfiable is set to DoNotSchedule, incoming pod can
5870	// only be scheduled to zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1)
5871	// on zone2(zone3) satisfies MaxSkew(1). In other words, the cluster can still
5872	// be imbalanced, but scheduler won't make it *more* imbalanced. It's a
5873	// required field.
5874	"whenUnsatisfiable"!: string
5875}
5876
5877// TypedLocalObjectReference contains enough information to let you locate the
5878// typed referenced object inside the same namespace.
5879#TypedLocalObjectReference: {
5880	// APIGroup is the group for the resource being referenced. If APIGroup is not
5881	// specified, the specified Kind must be in the core API group. For any other
5882	// third-party types, APIGroup is required.
5883	"apiGroup"?: string
5884
5885	// Kind is the type of resource being referenced
5886	"kind"!: string
5887
5888	// Name is the name of resource being referenced
5889	"name"!: string
5890}
5891
5892// TypedObjectReference contains enough information to let you locate the typed referenced object
5893#TypedObjectReference: {
5894	// APIGroup is the group for the resource being referenced. If APIGroup is not
5895	// specified, the specified Kind must be in the core API group. For any other
5896	// third-party types, APIGroup is required.
5897	"apiGroup"?: string
5898
5899	// Kind is the type of resource being referenced
5900	"kind"!: string
5901
5902	// Name is the name of resource being referenced
5903	"name"!: string
5904
5905	// Namespace is the namespace of resource being referenced Note that when a
5906	// namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is
5907	// required in the referent namespace to allow that namespace's owner to accept
5908	// the reference. See the ReferenceGrant documentation for details. (Alpha)
5909	// This field requires the CrossNamespaceVolumeDataSource feature gate to be
5910	// enabled.
5911	"namespace"?: string
5912}
5913
5914// Volume represents a named volume in a pod that may be accessed by any container in the pod.
5915#Volume: {
5916	// awsElasticBlockStore represents an AWS Disk resource that is attached to a
5917	// kubelet's host machine and then exposed to the pod. Deprecated:
5918	// AWSElasticBlockStore is deprecated. All operations for the in-tree
5919	// awsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.
5920	// More info:
5921	// https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
5922	"awsElasticBlockStore"?: #AWSElasticBlockStoreVolumeSource
5923
5924	// azureDisk represents an Azure Data Disk mount on the host and bind mount to
5925	// the pod. Deprecated: AzureDisk is deprecated. All operations for the in-tree
5926	// azureDisk type are redirected to the disk.csi.azure.com CSI driver.
5927	"azureDisk"?: #AzureDiskVolumeSource
5928
5929	// azureFile represents an Azure File Service mount on the host and bind mount
5930	// to the pod. Deprecated: AzureFile is deprecated. All operations for the
5931	// in-tree azureFile type are redirected to the file.csi.azure.com CSI driver.
5932	"azureFile"?: #AzureFileVolumeSource
5933
5934	// cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
5935	// Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer
5936	// supported.
5937	"cephfs"?: #CephFSVolumeSource
5938
5939	// cinder represents a cinder volume attached and mounted on kubelets host
5940	// machine. Deprecated: Cinder is deprecated. All operations for the in-tree
5941	// cinder type are redirected to the cinder.csi.openstack.org CSI driver. More
5942	// info: https://examples.k8s.io/mysql-cinder-pd/README.md
5943	"cinder"?: #CinderVolumeSource
5944
5945	// configMap represents a configMap that should populate this volume
5946	"configMap"?: #ConfigMapVolumeSource
5947
5948	// csi (Container Storage Interface) represents ephemeral storage that is
5949	// handled by certain external CSI drivers.
5950	"csi"?: #CSIVolumeSource
5951
5952	// downwardAPI represents downward API about the pod that should populate this volume
5953	"downwardAPI"?: #DownwardAPIVolumeSource
5954
5955	// emptyDir represents a temporary directory that shares a pod's lifetime. More
5956	// info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir
5957	"emptyDir"?: #EmptyDirVolumeSource
5958
5959	// ephemeral represents a volume that is handled by a cluster storage driver.
5960	// The volume's lifecycle is tied to the pod that defines it - it will be
5961	// created before the pod starts, and deleted when the pod is removed.
5962	//
5963	// Use this if: a) the volume is only needed while the pod runs, b) features of
5964	// normal volumes like restoring from snapshot or capacity
5965	// tracking are needed,
5966	// c) the storage driver is specified through a storage class, and d) the
5967	// storage driver supports dynamic volume provisioning through
5968	// a PersistentVolumeClaim (see EphemeralVolumeSource for more
5969	// information on the connection between this volume type
5970	// and PersistentVolumeClaim).
5971	//
5972	// Use PersistentVolumeClaim or one of the vendor-specific APIs for volumes that
5973	// persist for longer than the lifecycle of an individual pod.
5974	//
5975	// Use CSI for light-weight local ephemeral volumes if the CSI driver is meant
5976	// to be used that way - see the documentation of the driver for more
5977	// information.
5978	//
5979	// A pod can use both types of ephemeral volumes and persistent volumes at the same time.
5980	"ephemeral"?: #EphemeralVolumeSource
5981
5982	// fc represents a Fibre Channel resource that is attached to a kubelet's host
5983	// machine and then exposed to the pod.
5984	"fc"?: #FCVolumeSource
5985
5986	// flexVolume represents a generic volume resource that is provisioned/attached
5987	// using an exec based plugin. Deprecated: FlexVolume is deprecated. Consider
5988	// using a CSIDriver instead.
5989	"flexVolume"?: #FlexVolumeSource
5990
5991	// flocker represents a Flocker volume attached to a kubelet's host machine.
5992	// This depends on the Flocker control service being running. Deprecated:
5993	// Flocker is deprecated and the in-tree flocker type is no longer supported.
5994	"flocker"?: #FlockerVolumeSource
5995
5996	// gcePersistentDisk represents a GCE Disk resource that is attached to a
5997	// kubelet's host machine and then exposed to the pod. Deprecated:
5998	// GCEPersistentDisk is deprecated. All operations for the in-tree
5999	// gcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI
6000	// driver. More info:
6001	// https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
6002	"gcePersistentDisk"?: #GCEPersistentDiskVolumeSource
6003
6004	// gitRepo represents a git repository at a particular revision. Deprecated:
6005	// GitRepo is deprecated. To provision a container with a git repo, mount an
6006	// EmptyDir into an InitContainer that clones the repo using git, then mount
6007	// the EmptyDir into the Pod's container.
6008	"gitRepo"?: #GitRepoVolumeSource
6009
6010	// glusterfs represents a Glusterfs mount on the host that shares a pod's
6011	// lifetime. Deprecated: Glusterfs is deprecated and the in-tree glusterfs type
6012	// is no longer supported.
6013	"glusterfs"?: #GlusterfsVolumeSource
6014
6015	// hostPath represents a pre-existing file or directory on the host machine that
6016	// is directly exposed to the container. This is generally used for system
6017	// agents or other privileged things that are allowed to see the host machine.
6018	// Most containers will NOT need this. More info:
6019	// https://kubernetes.io/docs/concepts/storage/volumes#hostpath
6020	"hostPath"?: #HostPathVolumeSource
6021
6022	// image represents an OCI object (a container image or artifact) pulled and
6023	// mounted on the kubelet's host machine. The volume is resolved at pod startup
6024	// depending on which PullPolicy value is provided:
6025	//
6026	// - Always: the kubelet always attempts to pull the reference. Container
6027	// creation will fail If the pull fails. - Never: the kubelet never pulls the
6028	// reference and only uses a local image or artifact. Container creation will
6029	// fail if the reference isn't present. - IfNotPresent: the kubelet pulls if
6030	// the reference isn't already present on disk. Container creation will fail if
6031	// the reference isn't present and the pull fails.
6032	//
6033	// The volume gets re-resolved if the pod gets deleted and recreated, which
6034	// means that new remote content will become available on pod recreation. A
6035	// failure to resolve or pull the image during pod startup will block
6036	// containers from starting and may add significant latency. Failures will be
6037	// retried using normal volume backoff and will be reported on the pod reason
6038	// and message. The types of objects that may be mounted by this volume are
6039	// defined by the container runtime implementation on a host machine and at
6040	// minimum must include all valid types supported by the container image field.
6041	// The OCI object gets mounted in a single directory
6042	// (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers
6043	// in the same way as for container images. The volume will be mounted
6044	// read-only (ro). Sub path mounts for containers are not supported
6045	// (spec.containers[*].volumeMounts.subpath) before 1.33. The field
6046	// spec.securityContext.fsGroupChangePolicy has no effect on this volume type.
6047	"image"?: #ImageVolumeSource
6048
6049	// iscsi represents an ISCSI Disk resource that is attached to a kubelet's host
6050	// machine and then exposed to the pod. More info:
6051	// https://kubernetes.io/docs/concepts/storage/volumes/#iscsi
6052	"iscsi"?: #ISCSIVolumeSource
6053
6054	// name of the volume. Must be a DNS_LABEL and unique within the pod. More info:
6055	// https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
6056	"name"!: string
6057
6058	// nfs represents an NFS mount on the host that shares a pod's lifetime More
6059	// info: https://kubernetes.io/docs/concepts/storage/volumes#nfs
6060	"nfs"?: #NFSVolumeSource
6061
6062	// persistentVolumeClaimVolumeSource represents a reference to a
6063	// PersistentVolumeClaim in the same namespace. More info:
6064	// https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
6065	"persistentVolumeClaim"?: #PersistentVolumeClaimVolumeSource
6066
6067	// photonPersistentDisk represents a PhotonController persistent disk attached
6068	// and mounted on kubelets host machine. Deprecated: PhotonPersistentDisk is
6069	// deprecated and the in-tree photonPersistentDisk type is no longer supported.
6070	"photonPersistentDisk"?: #PhotonPersistentDiskVolumeSource
6071
6072	// portworxVolume represents a portworx volume attached and mounted on kubelets
6073	// host machine. Deprecated: PortworxVolume is deprecated. All operations for
6074	// the in-tree portworxVolume type are redirected to the pxd.portworx.com CSI
6075	// driver.
6076	"portworxVolume"?: #PortworxVolumeSource
6077
6078	// projected items for all in one resources secrets, configmaps, and downward API
6079	"projected"?: #ProjectedVolumeSource
6080
6081	// quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
6082	// Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer
6083	// supported.
6084	"quobyte"?: #QuobyteVolumeSource
6085
6086	// rbd represents a Rados Block Device mount on the host that shares a pod's
6087	// lifetime. Deprecated: RBD is deprecated and the in-tree rbd type is no
6088	// longer supported.
6089	"rbd"?: #RBDVolumeSource
6090
6091	// scaleIO represents a ScaleIO persistent volume attached and mounted on
6092	// Kubernetes nodes. Deprecated: ScaleIO is deprecated and the in-tree scaleIO
6093	// type is no longer supported.
6094	"scaleIO"?: #ScaleIOVolumeSource
6095
6096	// secret represents a secret that should populate this volume. More info:
6097	// https://kubernetes.io/docs/concepts/storage/volumes#secret
6098	"secret"?: #SecretVolumeSource
6099
6100	// storageOS represents a StorageOS volume attached and mounted on Kubernetes
6101	// nodes. Deprecated: StorageOS is deprecated and the in-tree storageos type is
6102	// no longer supported.
6103	"storageos"?: #StorageOSVolumeSource
6104
6105	// vsphereVolume represents a vSphere volume attached and mounted on kubelets
6106	// host machine. Deprecated: VsphereVolume is deprecated. All operations for
6107	// the in-tree vsphereVolume type are redirected to the csi.vsphere.vmware.com
6108	// CSI driver.
6109	"vsphereVolume"?: #VsphereVirtualDiskVolumeSource
6110}
6111
6112// volumeDevice describes a mapping of a raw block device within a container.
6113#VolumeDevice: {
6114	// devicePath is the path inside of the container that the device will be mapped to.
6115	"devicePath"!: string
6116
6117	// name must match the name of a persistentVolumeClaim in the pod
6118	"name"!: string
6119}
6120
6121// VolumeMount describes a mounting of a Volume within a container.
6122#VolumeMount: {
6123	// Path within the container at which the volume should be mounted. Must not contain ':'.
6124	"mountPath"!: string
6125
6126	// mountPropagation determines how mounts are propagated from the host to
6127	// container and the other way around. When not set, MountPropagationNone is
6128	// used. This field is beta in 1.10. When RecursiveReadOnly is set to
6129	// IfPossible or to Enabled, MountPropagation must be None or unspecified
6130	// (which defaults to None).
6131	"mountPropagation"?: string
6132
6133	// This must match the Name of a Volume.
6134	"name"!: string
6135
6136	// Mounted read-only if true, read-write otherwise (false or unspecified). Defaults to false.
6137	"readOnly"?: bool
6138
6139	// RecursiveReadOnly specifies whether read-only mounts should be handled recursively.
6140	//
6141	// If ReadOnly is false, this field has no meaning and must be unspecified.
6142	//
6143	// If ReadOnly is true, and this field is set to Disabled, the mount is not made
6144	// recursively read-only. If this field is set to IfPossible, the mount is made
6145	// recursively read-only, if it is supported by the container runtime. If this
6146	// field is set to Enabled, the mount is made recursively read-only if it is
6147	// supported by the container runtime, otherwise the pod will not be started
6148	// and an error will be generated to indicate the reason.
6149	//
6150	// If this field is set to IfPossible or Enabled, MountPropagation must be set
6151	// to None (or be unspecified, which defaults to None).
6152	//
6153	// If this field is not specified, it is treated as an equivalent of Disabled.
6154	"recursiveReadOnly"?: string
6155
6156	// Path within the volume from which the container's volume should be mounted.
6157	// Defaults to "" (volume's root).
6158	"subPath"?: string
6159
6160	// Expanded path within the volume from which the container's volume should be
6161	// mounted. Behaves similarly to SubPath but environment variable references
6162	// $(VAR_NAME) are expanded using the container's environment. Defaults to ""
6163	// (volume's root). SubPathExpr and SubPath are mutually exclusive.
6164	"subPathExpr"?: string
6165}
6166
6167// VolumeMountStatus shows status of volume mounts.
6168#VolumeMountStatus: {
6169	// MountPath corresponds to the original VolumeMount.
6170	"mountPath"!: string
6171
6172	// Name corresponds to the name of the original VolumeMount.
6173	"name"!: string
6174
6175	// ReadOnly corresponds to the original VolumeMount.
6176	"readOnly"?: bool
6177
6178	// RecursiveReadOnly must be set to Disabled, Enabled, or unspecified (for
6179	// non-readonly mounts). An IfPossible value in the original VolumeMount must
6180	// be translated to Disabled or Enabled, depending on the mount result.
6181	"recursiveReadOnly"?: string
6182
6183	// volumeStatus represents volume-type-specific status about the mounted volume.
6184	"volumeStatus"?: #VolumeStatus
6185}
6186
6187// VolumeNodeAffinity defines constraints that limit what nodes this volume can be accessed from.
6188#VolumeNodeAffinity: {
6189	// required specifies hard node constraints that must be met.
6190	"required"?: #NodeSelector
6191}
6192
6193// Projection that may be projected along with other supported volume types.
6194// Exactly one of these fields must be set.
6195#VolumeProjection: {
6196	// ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field of
6197	// ClusterTrustBundle objects in an auto-updating file.
6198	//
6199	// Alpha, gated by the ClusterTrustBundleProjection feature gate.
6200	//
6201	// ClusterTrustBundle objects can either be selected by name, or by the
6202	// combination of signer name and a label selector.
6203	//
6204	// Kubelet performs aggressive normalization of the PEM contents written into
6205	// the pod filesystem. Esoteric PEM features such as inter-block comments and
6206	// block headers are stripped. Certificates are deduplicated. The ordering of
6207	// certificates within the file is arbitrary, and Kubelet may change the order
6208	// over time.
6209	"clusterTrustBundle"?: #ClusterTrustBundleProjection
6210
6211	// configMap information about the configMap data to project
6212	"configMap"?: #ConfigMapProjection
6213
6214	// downwardAPI information about the downwardAPI data to project
6215	"downwardAPI"?: #DownwardAPIProjection
6216
6217	// Projects an auto-rotating credential bundle (private key and certificate
6218	// chain) that the pod can use either as a TLS client or server.
6219	//
6220	// Kubelet generates a private key and uses it to send a PodCertificateRequest
6221	// to the named signer. Once the signer approves the request and issues a
6222	// certificate chain, Kubelet writes the key and certificate chain to the pod
6223	// filesystem. The pod does not start until certificates have been issued for
6224	// each podCertificate projected volume source in its spec.
6225	//
6226	// Kubelet will begin trying to rotate the certificate at the time indicated by
6227	// the signer using the PodCertificateRequest.Status.BeginRefreshAt timestamp.
6228	//
6229	// Kubelet can write a single file, indicated by the credentialBundlePath field,
6230	// or separate files, indicated by the keyPath and certificateChainPath fields.
6231	//
6232	// The credential bundle is a single file in PEM format. The first PEM entry is
6233	// the private key (in PKCS#8 format), and the remaining PEM entries are the
6234	// certificate chain issued by the signer (typically, signers will return their
6235	// certificate chain in leaf-to-root order).
6236	//
6237	// Prefer using the credential bundle format, since your application code can
6238	// read it atomically. If you use keyPath and certificateChainPath, your
6239	// application must make two separate file reads. If these coincide with a
6240	// certificate rotation, it is possible that the private key and leaf
6241	// certificate you read may not correspond to each other. Your application will
6242	// need to check for this condition, and re-read until they are consistent.
6243	//
6244	// The named signer controls chooses the format of the certificate it issues;
6245	// consult the signer implementation's documentation to learn how to use the
6246	// certificates it issues.
6247	"podCertificate"?: #PodCertificateProjection
6248
6249	// secret information about the secret data to project
6250	"secret"?: #SecretProjection
6251
6252	// serviceAccountToken is information about the serviceAccountToken data to project
6253	"serviceAccountToken"?: #ServiceAccountTokenProjection
6254}
6255
6256// VolumeResourceRequirements describes the storage resource requirements for a volume.
6257#VolumeResourceRequirements: {
6258	// Limits describes the maximum amount of compute resources allowed. More info:
6259	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
6260	"limits"?: [string]: resource.#Quantity
6261
6262	// Requests describes the minimum amount of compute resources required. If
6263	// Requests is omitted for a container, it defaults to Limits if that is
6264	// explicitly specified, otherwise to an implementation-defined value. Requests
6265	// cannot exceed Limits. More info:
6266	// https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
6267	"requests"?: [string]: resource.#Quantity
6268}
6269
6270// VolumeStatus represents the status of a mounted volume. At most one of its
6271// members must be specified.
6272#VolumeStatus: {
6273	// image represents an OCI object (a container image or artifact) pulled and
6274	// mounted on the kubelet's host machine.
6275	"image"?: #ImageVolumeStatus
6276}
6277
6278// Represents a vSphere volume resource.
6279#VsphereVirtualDiskVolumeSource: {
6280	// fsType is filesystem type to mount. Must be a filesystem type supported by
6281	// the host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to
6282	// be "ext4" if unspecified.
6283	"fsType"?: string
6284
6285	// storagePolicyID is the storage Policy Based Management (SPBM) profile ID
6286	// associated with the StoragePolicyName.
6287	"storagePolicyID"?: string
6288
6289	// storagePolicyName is the storage Policy Based Management (SPBM) profile name.
6290	"storagePolicyName"?: string
6291
6292	// volumePath is the path that identifies vSphere volume vmdk
6293	"volumePath"!: string
6294}
6295
6296// The weights of all of the matched WeightedPodAffinityTerm fields are added
6297// per-node to find the most preferred node(s)
6298#WeightedPodAffinityTerm: {
6299	// Required. A pod affinity term, associated with the corresponding weight.
6300	"podAffinityTerm"!: #PodAffinityTerm
6301
6302	// weight associated with matching the corresponding podAffinityTerm, in the range 1-100.
6303	"weight"!: int32 & int
6304}
6305
6306// WindowsSecurityContextOptions contain Windows-specific options and credentials.
6307#WindowsSecurityContextOptions: {
6308	// GMSACredentialSpec is where the GMSA admission webhook
6309	// (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of
6310	// the GMSA credential spec named by the GMSACredentialSpecName field.
6311	"gmsaCredentialSpec"?: string
6312
6313	// GMSACredentialSpecName is the name of the GMSA credential spec to use.
6314	"gmsaCredentialSpecName"?: string
6315
6316	// HostProcess determines if a container should be run as a 'Host Process'
6317	// container. All of a Pod's containers must have the same effective
6318	// HostProcess value (it is not allowed to have a mix of HostProcess containers
6319	// and non-HostProcess containers). In addition, if HostProcess is true then
6320	// HostNetwork must also be set to true.
6321	"hostProcess"?: bool
6322
6323	// The UserName in Windows to run the entrypoint of the container process.
6324	// Defaults to the user specified in image metadata if unspecified. May also be
6325	// set in PodSecurityContext. If set in both SecurityContext and
6326	// PodSecurityContext, the value specified in SecurityContext takes precedence.
6327	"runAsUserName"?: string
6328}