cue.dev/x/k8s.io@v0.12.0

api/rbac/v1/schema.cue raw

  1package v1
  2
  3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
  4
  5// AggregationRule describes how to locate ClusterRoles to aggregate into the ClusterRole
  6#AggregationRule: {
  7	// ClusterRoleSelectors holds a list of selectors which will be used to find
  8	// ClusterRoles and create the rules. If any of the selectors match, then the
  9	// ClusterRole's permissions will be added
 10	"clusterRoleSelectors"?: [...v1.#LabelSelector]
 11}
 12
 13// ClusterRole is a cluster level, logical grouping of PolicyRules that can be
 14// referenced as a unit by a RoleBinding or ClusterRoleBinding.
 15#ClusterRole: {
 16	// AggregationRule is an optional field that describes how to build the Rules
 17	// for this ClusterRole. If AggregationRule is set, then the Rules are
 18	// controller managed and direct changes to Rules will be stomped by the
 19	// controller.
 20	"aggregationRule"?: #AggregationRule
 21
 22	// APIVersion defines the versioned schema of this representation of an object.
 23	// Servers should convert recognized schemas to the latest internal value, and
 24	// may reject unrecognized values. More info:
 25	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 26	"apiVersion": "rbac.authorization.k8s.io/v1"
 27
 28	// Kind is a string value representing the REST resource this object represents.
 29	// Servers may infer this from the endpoint the client submits requests to.
 30	// Cannot be updated. In CamelCase. More info:
 31	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 32	"kind": "ClusterRole"
 33
 34	// Standard object's metadata.
 35	"metadata"?: v1.#ObjectMeta
 36
 37	// Rules holds all the PolicyRules for this ClusterRole
 38	"rules"?: [...#PolicyRule]
 39}
 40
 41// ClusterRoleBinding references a ClusterRole, but not contain it. It can
 42// reference a ClusterRole in the global namespace, and adds who information
 43// via Subject.
 44#ClusterRoleBinding: {
 45	// APIVersion defines the versioned schema of this representation of an object.
 46	// Servers should convert recognized schemas to the latest internal value, and
 47	// may reject unrecognized values. More info:
 48	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 49	"apiVersion": "rbac.authorization.k8s.io/v1"
 50
 51	// Kind is a string value representing the REST resource this object represents.
 52	// Servers may infer this from the endpoint the client submits requests to.
 53	// Cannot be updated. In CamelCase. More info:
 54	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 55	"kind": "ClusterRoleBinding"
 56
 57	// Standard object's metadata.
 58	"metadata"?: v1.#ObjectMeta
 59
 60	// RoleRef can only reference a ClusterRole in the global namespace. If the
 61	// RoleRef cannot be resolved, the Authorizer must return an error. This field
 62	// is immutable.
 63	"roleRef"!: #RoleRef
 64
 65	// Subjects holds references to the objects the role applies to.
 66	"subjects"?: [...#Subject]
 67}
 68
 69// ClusterRoleBindingList is a collection of ClusterRoleBindings
 70#ClusterRoleBindingList: {
 71	// APIVersion defines the versioned schema of this representation of an object.
 72	// Servers should convert recognized schemas to the latest internal value, and
 73	// may reject unrecognized values. More info:
 74	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 75	"apiVersion": "rbac.authorization.k8s.io/v1"
 76
 77	// Items is a list of ClusterRoleBindings
 78	"items"!: [...#ClusterRoleBinding]
 79
 80	// Kind is a string value representing the REST resource this object represents.
 81	// Servers may infer this from the endpoint the client submits requests to.
 82	// Cannot be updated. In CamelCase. More info:
 83	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 84	"kind": "ClusterRoleBindingList"
 85
 86	// Standard object's metadata.
 87	"metadata"?: v1.#ListMeta
 88}
 89
 90// ClusterRoleList is a collection of ClusterRoles
 91#ClusterRoleList: {
 92	// APIVersion defines the versioned schema of this representation of an object.
 93	// Servers should convert recognized schemas to the latest internal value, and
 94	// may reject unrecognized values. More info:
 95	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 96	"apiVersion": "rbac.authorization.k8s.io/v1"
 97
 98	// Items is a list of ClusterRoles
 99	"items"!: [...#ClusterRole]
100
101	// Kind is a string value representing the REST resource this object represents.
102	// Servers may infer this from the endpoint the client submits requests to.
103	// Cannot be updated. In CamelCase. More info:
104	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
105	"kind": "ClusterRoleList"
106
107	// Standard object's metadata.
108	"metadata"?: v1.#ListMeta
109}
110
111// PolicyRule holds information that describes a policy rule, but does not
112// contain information about who the rule applies to or which namespace the
113// rule applies to.
114#PolicyRule: {
115	// APIGroups is the name of the APIGroup that contains the resources. If
116	// multiple API groups are specified, any action requested against one of the
117	// enumerated resources in any API group will be allowed. "" represents the
118	// core API group and "*" represents all API groups.
119	"apiGroups"?: [...string]
120
121	// NonResourceURLs is a set of partial urls that a user should have access to.
122	// *s are allowed, but only as the full, final step in the path Since
123	// non-resource URLs are not namespaced, this field is only applicable for
124	// ClusterRoles referenced from a ClusterRoleBinding. Rules can either apply to
125	// API resources (such as "pods" or "secrets") or non-resource URL paths (such
126	// as "/api"), but not both.
127	"nonResourceURLs"?: [...string]
128
129	// ResourceNames is an optional white list of names that the rule applies to. An
130	// empty set means that everything is allowed.
131	"resourceNames"?: [...string]
132
133	// Resources is a list of resources this rule applies to. '*' represents all resources.
134	"resources"?: [...string]
135
136	// Verbs is a list of Verbs that apply to ALL the ResourceKinds contained in
137	// this rule. '*' represents all verbs.
138	"verbs"!: [...string]
139}
140
141// Role is a namespaced, logical grouping of PolicyRules that can be referenced
142// as a unit by a RoleBinding.
143#Role: {
144	// APIVersion defines the versioned schema of this representation of an object.
145	// Servers should convert recognized schemas to the latest internal value, and
146	// may reject unrecognized values. More info:
147	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
148	"apiVersion": "rbac.authorization.k8s.io/v1"
149
150	// Kind is a string value representing the REST resource this object represents.
151	// Servers may infer this from the endpoint the client submits requests to.
152	// Cannot be updated. In CamelCase. More info:
153	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
154	"kind": "Role"
155
156	// Standard object's metadata.
157	"metadata"?: v1.#ObjectMeta
158
159	// Rules holds all the PolicyRules for this Role
160	"rules"?: [...#PolicyRule]
161}
162
163// RoleBinding references a role, but does not contain it. It can reference a
164// Role in the same namespace or a ClusterRole in the global namespace. It adds
165// who information via Subjects and namespace information by which namespace it
166// exists in. RoleBindings in a given namespace only have effect in that
167// namespace.
168#RoleBinding: {
169	// APIVersion defines the versioned schema of this representation of an object.
170	// Servers should convert recognized schemas to the latest internal value, and
171	// may reject unrecognized values. More info:
172	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
173	"apiVersion": "rbac.authorization.k8s.io/v1"
174
175	// Kind is a string value representing the REST resource this object represents.
176	// Servers may infer this from the endpoint the client submits requests to.
177	// Cannot be updated. In CamelCase. More info:
178	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
179	"kind": "RoleBinding"
180
181	// Standard object's metadata.
182	"metadata"?: v1.#ObjectMeta
183
184	// RoleRef can reference a Role in the current namespace or a ClusterRole in the
185	// global namespace. If the RoleRef cannot be resolved, the Authorizer must
186	// return an error. This field is immutable.
187	"roleRef"!: #RoleRef
188
189	// Subjects holds references to the objects the role applies to.
190	"subjects"?: [...#Subject]
191}
192
193// RoleBindingList is a collection of RoleBindings
194#RoleBindingList: {
195	// APIVersion defines the versioned schema of this representation of an object.
196	// Servers should convert recognized schemas to the latest internal value, and
197	// may reject unrecognized values. More info:
198	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
199	"apiVersion": "rbac.authorization.k8s.io/v1"
200
201	// Items is a list of RoleBindings
202	"items"!: [...#RoleBinding]
203
204	// Kind is a string value representing the REST resource this object represents.
205	// Servers may infer this from the endpoint the client submits requests to.
206	// Cannot be updated. In CamelCase. More info:
207	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
208	"kind": "RoleBindingList"
209
210	// Standard object's metadata.
211	"metadata"?: v1.#ListMeta
212}
213
214// RoleList is a collection of Roles
215#RoleList: {
216	// APIVersion defines the versioned schema of this representation of an object.
217	// Servers should convert recognized schemas to the latest internal value, and
218	// may reject unrecognized values. More info:
219	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
220	"apiVersion": "rbac.authorization.k8s.io/v1"
221
222	// Items is a list of Roles
223	"items"!: [...#Role]
224
225	// Kind is a string value representing the REST resource this object represents.
226	// Servers may infer this from the endpoint the client submits requests to.
227	// Cannot be updated. In CamelCase. More info:
228	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
229	"kind": "RoleList"
230
231	// Standard object's metadata.
232	"metadata"?: v1.#ListMeta
233}
234
235// RoleRef contains information that points to the role being used
236#RoleRef: {
237	// APIGroup is the group for the resource being referenced
238	"apiGroup"?: string
239
240	// Kind is the type of resource being referenced
241	"kind"!: string
242
243	// Name is the name of resource being referenced
244	"name"!: string
245}
246
247// Subject contains a reference to the object or user identities a role binding
248// applies to. This can either hold a direct API object reference, or a value
249// for non-objects such as user and group names.
250#Subject: {
251	// APIGroup holds the API group of the referenced subject. Defaults to "" for
252	// ServiceAccount subjects. Defaults to "rbac.authorization.k8s.io" for User
253	// and Group subjects.
254	"apiGroup"?: string
255
256	// Kind of object being referenced. Values defined by this API group are "User",
257	// "Group", and "ServiceAccount". If the Authorizer does not recognized the
258	// kind value, the Authorizer should report an error.
259	"kind"!: string
260
261	// Name of the object being referenced.
262	"name"!: string
263
264	// Namespace of the referenced object. If the object kind is non-namespace, such
265	// as "User" or "Group", and this value is not empty the Authorizer should
266	// report an error.
267	"namespace"?: string
268}