1package v1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// AggregationRule describes how to locate ClusterRoles to aggregate into the ClusterRole
6#AggregationRule: {
7 // ClusterRoleSelectors holds a list of selectors which will be used to find
8 // ClusterRoles and create the rules. If any of the selectors match, then the
9 // ClusterRole's permissions will be added
10 "clusterRoleSelectors"?: [...v1.#LabelSelector]
11}
12
13// ClusterRole is a cluster level, logical grouping of PolicyRules that can be
14// referenced as a unit by a RoleBinding or ClusterRoleBinding.
15#ClusterRole: {
16 // AggregationRule is an optional field that describes how to build the Rules
17 // for this ClusterRole. If AggregationRule is set, then the Rules are
18 // controller managed and direct changes to Rules will be stomped by the
19 // controller.
20 "aggregationRule"?: #AggregationRule
21
22 // APIVersion defines the versioned schema of this representation of an object.
23 // Servers should convert recognized schemas to the latest internal value, and
24 // may reject unrecognized values. More info:
25 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
26 "apiVersion": "rbac.authorization.k8s.io/v1"
27
28 // Kind is a string value representing the REST resource this object represents.
29 // Servers may infer this from the endpoint the client submits requests to.
30 // Cannot be updated. In CamelCase. More info:
31 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
32 "kind": "ClusterRole"
33
34 // Standard object's metadata.
35 "metadata"?: v1.#ObjectMeta
36
37 // Rules holds all the PolicyRules for this ClusterRole
38 "rules"?: [...#PolicyRule]
39}
40
41// ClusterRoleBinding references a ClusterRole, but not contain it. It can
42// reference a ClusterRole in the global namespace, and adds who information
43// via Subject.
44#ClusterRoleBinding: {
45 // APIVersion defines the versioned schema of this representation of an object.
46 // Servers should convert recognized schemas to the latest internal value, and
47 // may reject unrecognized values. More info:
48 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
49 "apiVersion": "rbac.authorization.k8s.io/v1"
50
51 // Kind is a string value representing the REST resource this object represents.
52 // Servers may infer this from the endpoint the client submits requests to.
53 // Cannot be updated. In CamelCase. More info:
54 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
55 "kind": "ClusterRoleBinding"
56
57 // Standard object's metadata.
58 "metadata"?: v1.#ObjectMeta
59
60 // RoleRef can only reference a ClusterRole in the global namespace. If the
61 // RoleRef cannot be resolved, the Authorizer must return an error. This field
62 // is immutable.
63 "roleRef"!: #RoleRef
64
65 // Subjects holds references to the objects the role applies to.
66 "subjects"?: [...#Subject]
67}
68
69// ClusterRoleBindingList is a collection of ClusterRoleBindings
70#ClusterRoleBindingList: {
71 // APIVersion defines the versioned schema of this representation of an object.
72 // Servers should convert recognized schemas to the latest internal value, and
73 // may reject unrecognized values. More info:
74 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
75 "apiVersion": "rbac.authorization.k8s.io/v1"
76
77 // Items is a list of ClusterRoleBindings
78 "items"!: [...#ClusterRoleBinding]
79
80 // Kind is a string value representing the REST resource this object represents.
81 // Servers may infer this from the endpoint the client submits requests to.
82 // Cannot be updated. In CamelCase. More info:
83 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
84 "kind": "ClusterRoleBindingList"
85
86 // Standard object's metadata.
87 "metadata"?: v1.#ListMeta
88}
89
90// ClusterRoleList is a collection of ClusterRoles
91#ClusterRoleList: {
92 // APIVersion defines the versioned schema of this representation of an object.
93 // Servers should convert recognized schemas to the latest internal value, and
94 // may reject unrecognized values. More info:
95 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
96 "apiVersion": "rbac.authorization.k8s.io/v1"
97
98 // Items is a list of ClusterRoles
99 "items"!: [...#ClusterRole]
100
101 // Kind is a string value representing the REST resource this object represents.
102 // Servers may infer this from the endpoint the client submits requests to.
103 // Cannot be updated. In CamelCase. More info:
104 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
105 "kind": "ClusterRoleList"
106
107 // Standard object's metadata.
108 "metadata"?: v1.#ListMeta
109}
110
111// PolicyRule holds information that describes a policy rule, but does not
112// contain information about who the rule applies to or which namespace the
113// rule applies to.
114#PolicyRule: {
115 // APIGroups is the name of the APIGroup that contains the resources. If
116 // multiple API groups are specified, any action requested against one of the
117 // enumerated resources in any API group will be allowed. "" represents the
118 // core API group and "*" represents all API groups.
119 "apiGroups"?: [...string]
120
121 // NonResourceURLs is a set of partial urls that a user should have access to.
122 // *s are allowed, but only as the full, final step in the path Since
123 // non-resource URLs are not namespaced, this field is only applicable for
124 // ClusterRoles referenced from a ClusterRoleBinding. Rules can either apply to
125 // API resources (such as "pods" or "secrets") or non-resource URL paths (such
126 // as "/api"), but not both.
127 "nonResourceURLs"?: [...string]
128
129 // ResourceNames is an optional white list of names that the rule applies to. An
130 // empty set means that everything is allowed.
131 "resourceNames"?: [...string]
132
133 // Resources is a list of resources this rule applies to. '*' represents all resources.
134 "resources"?: [...string]
135
136 // Verbs is a list of Verbs that apply to ALL the ResourceKinds contained in
137 // this rule. '*' represents all verbs.
138 "verbs"!: [...string]
139}
140
141// Role is a namespaced, logical grouping of PolicyRules that can be referenced
142// as a unit by a RoleBinding.
143#Role: {
144 // APIVersion defines the versioned schema of this representation of an object.
145 // Servers should convert recognized schemas to the latest internal value, and
146 // may reject unrecognized values. More info:
147 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
148 "apiVersion": "rbac.authorization.k8s.io/v1"
149
150 // Kind is a string value representing the REST resource this object represents.
151 // Servers may infer this from the endpoint the client submits requests to.
152 // Cannot be updated. In CamelCase. More info:
153 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
154 "kind": "Role"
155
156 // Standard object's metadata.
157 "metadata"?: v1.#ObjectMeta
158
159 // Rules holds all the PolicyRules for this Role
160 "rules"?: [...#PolicyRule]
161}
162
163// RoleBinding references a role, but does not contain it. It can reference a
164// Role in the same namespace or a ClusterRole in the global namespace. It adds
165// who information via Subjects and namespace information by which namespace it
166// exists in. RoleBindings in a given namespace only have effect in that
167// namespace.
168#RoleBinding: {
169 // APIVersion defines the versioned schema of this representation of an object.
170 // Servers should convert recognized schemas to the latest internal value, and
171 // may reject unrecognized values. More info:
172 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
173 "apiVersion": "rbac.authorization.k8s.io/v1"
174
175 // Kind is a string value representing the REST resource this object represents.
176 // Servers may infer this from the endpoint the client submits requests to.
177 // Cannot be updated. In CamelCase. More info:
178 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
179 "kind": "RoleBinding"
180
181 // Standard object's metadata.
182 "metadata"?: v1.#ObjectMeta
183
184 // RoleRef can reference a Role in the current namespace or a ClusterRole in the
185 // global namespace. If the RoleRef cannot be resolved, the Authorizer must
186 // return an error. This field is immutable.
187 "roleRef"!: #RoleRef
188
189 // Subjects holds references to the objects the role applies to.
190 "subjects"?: [...#Subject]
191}
192
193// RoleBindingList is a collection of RoleBindings
194#RoleBindingList: {
195 // APIVersion defines the versioned schema of this representation of an object.
196 // Servers should convert recognized schemas to the latest internal value, and
197 // may reject unrecognized values. More info:
198 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
199 "apiVersion": "rbac.authorization.k8s.io/v1"
200
201 // Items is a list of RoleBindings
202 "items"!: [...#RoleBinding]
203
204 // Kind is a string value representing the REST resource this object represents.
205 // Servers may infer this from the endpoint the client submits requests to.
206 // Cannot be updated. In CamelCase. More info:
207 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
208 "kind": "RoleBindingList"
209
210 // Standard object's metadata.
211 "metadata"?: v1.#ListMeta
212}
213
214// RoleList is a collection of Roles
215#RoleList: {
216 // APIVersion defines the versioned schema of this representation of an object.
217 // Servers should convert recognized schemas to the latest internal value, and
218 // may reject unrecognized values. More info:
219 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
220 "apiVersion": "rbac.authorization.k8s.io/v1"
221
222 // Items is a list of Roles
223 "items"!: [...#Role]
224
225 // Kind is a string value representing the REST resource this object represents.
226 // Servers may infer this from the endpoint the client submits requests to.
227 // Cannot be updated. In CamelCase. More info:
228 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
229 "kind": "RoleList"
230
231 // Standard object's metadata.
232 "metadata"?: v1.#ListMeta
233}
234
235// RoleRef contains information that points to the role being used
236#RoleRef: {
237 // APIGroup is the group for the resource being referenced
238 "apiGroup"?: string
239
240 // Kind is the type of resource being referenced
241 "kind"!: string
242
243 // Name is the name of resource being referenced
244 "name"!: string
245}
246
247// Subject contains a reference to the object or user identities a role binding
248// applies to. This can either hold a direct API object reference, or a value
249// for non-objects such as user and group names.
250#Subject: {
251 // APIGroup holds the API group of the referenced subject. Defaults to "" for
252 // ServiceAccount subjects. Defaults to "rbac.authorization.k8s.io" for User
253 // and Group subjects.
254 "apiGroup"?: string
255
256 // Kind of object being referenced. Values defined by this API group are "User",
257 // "Group", and "ServiceAccount". If the Authorizer does not recognized the
258 // kind value, the Authorizer should report an error.
259 "kind"!: string
260
261 // Name of the object being referenced.
262 "name"!: string
263
264 // Namespace of the referenced object. If the object kind is non-namespace, such
265 // as "User" or "Group", and this value is not empty the Authorizer should
266 // report an error.
267 "namespace"?: string
268}