1package v1
2
3import (
4 "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
5 "cue.dev/x/k8s.io/apimachinery/pkg/api/resource"
6 v1_9 "cue.dev/x/k8s.io/api/core/v1"
7)
8
9// CSIDriver captures information about a Container Storage Interface (CSI)
10// volume driver deployed on the cluster. Kubernetes attach detach controller
11// uses this object to determine whether attach is required. Kubelet uses this
12// object to determine whether pod information needs to be passed on mount.
13// CSIDriver objects are non-namespaced.
14#CSIDriver: {
15 // APIVersion defines the versioned schema of this representation of an object.
16 // Servers should convert recognized schemas to the latest internal value, and
17 // may reject unrecognized values. More info:
18 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
19 "apiVersion": "storage.k8s.io/v1"
20
21 // Kind is a string value representing the REST resource this object represents.
22 // Servers may infer this from the endpoint the client submits requests to.
23 // Cannot be updated. In CamelCase. More info:
24 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
25 "kind": "CSIDriver"
26
27 // Standard object metadata. metadata.Name indicates the name of the CSI driver
28 // that this object refers to; it MUST be the same name returned by the CSI
29 // GetPluginName() call for that driver. The driver name must be 63 characters
30 // or less, beginning and ending with an alphanumeric character ([a-z0-9A-Z])
31 // with dashes (-), dots (.), and alphanumerics between. More info:
32 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
33 "metadata"?: v1.#ObjectMeta
34
35 // spec represents the specification of the CSI Driver.
36 "spec"!: #CSIDriverSpec
37}
38
39// CSIDriverList is a collection of CSIDriver objects.
40#CSIDriverList: {
41 // APIVersion defines the versioned schema of this representation of an object.
42 // Servers should convert recognized schemas to the latest internal value, and
43 // may reject unrecognized values. More info:
44 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
45 "apiVersion": "storage.k8s.io/v1"
46
47 // items is the list of CSIDriver
48 "items"!: [...#CSIDriver]
49
50 // Kind is a string value representing the REST resource this object represents.
51 // Servers may infer this from the endpoint the client submits requests to.
52 // Cannot be updated. In CamelCase. More info:
53 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
54 "kind": "CSIDriverList"
55
56 // Standard list metadata More info:
57 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
58 "metadata"?: v1.#ListMeta
59}
60
61// CSIDriverSpec is the specification of a CSIDriver.
62#CSIDriverSpec: {
63 // attachRequired indicates this CSI volume driver requires an attach operation
64 // (because it implements the CSI ControllerPublishVolume() method), and that
65 // the Kubernetes attach detach controller should call the attach volume
66 // interface which checks the volumeattachment status and waits until the
67 // volume is attached before proceeding to mounting. The CSI external-attacher
68 // coordinates with CSI volume driver and updates the volumeattachment status
69 // when the attach operation is complete. If the value is specified to false,
70 // the attach operation will be skipped. Otherwise the attach operation will be
71 // called.
72 //
73 // This field is immutable.
74 "attachRequired"?: bool
75
76 // fsGroupPolicy defines if the underlying volume supports changing ownership
77 // and permission of the volume before being mounted. Refer to the specific
78 // FSGroupPolicy values for additional details.
79 //
80 // This field was immutable in Kubernetes < 1.29 and now is mutable.
81 //
82 // Defaults to ReadWriteOnceWithFSType, which will examine each volume to
83 // determine if Kubernetes should modify ownership and permissions of the
84 // volume. With the default policy the defined fsGroup will only be applied if
85 // a fstype is defined and the volume's access mode contains ReadWriteOnce.
86 "fsGroupPolicy"?: string
87
88 // nodeAllocatableUpdatePeriodSeconds specifies the interval between periodic
89 // updates of the CSINode allocatable capacity for this driver. When set, both
90 // periodic updates and updates triggered by capacity-related failures are
91 // enabled. If not set, no updates occur (neither periodic nor upon detecting
92 // capacity-related failures), and the allocatable.count remains static. The
93 // minimum allowed value for this field is 10 seconds.
94 //
95 // This feature requires the MutableCSINodeAllocatableCount feature gate to be enabled.
96 //
97 // This field is mutable.
98 "nodeAllocatableUpdatePeriodSeconds"?: int64 & int
99
100 // podInfoOnMount indicates this CSI volume driver requires additional pod
101 // information (like podName, podUID, etc.) during mount operations, if set to
102 // true. If set to false, pod information will not be passed on mount. Default
103 // is false.
104 //
105 // The CSI driver specifies podInfoOnMount as part of driver deployment. If
106 // true, Kubelet will pass pod information as VolumeContext in the CSI
107 // NodePublishVolume() calls. The CSI driver is responsible for parsing and
108 // validating the information passed in as VolumeContext.
109 //
110 // The following VolumeContext will be passed if podInfoOnMount is set to true.
111 // This list might grow, but the prefix will be used.
112 // "csi.storage.k8s.io/pod.name": pod.Name "csi.storage.k8s.io/pod.namespace":
113 // pod.Namespace "csi.storage.k8s.io/pod.uid": string(pod.UID)
114 // "csi.storage.k8s.io/ephemeral": "true" if the volume is an ephemeral inline
115 // volume
116 // defined by a CSIVolumeSource, otherwise "false"
117 //
118 // "csi.storage.k8s.io/ephemeral" is a new feature in Kubernetes 1.16. It is
119 // only required for drivers which support both the "Persistent" and
120 // "Ephemeral" VolumeLifecycleMode. Other drivers can leave pod info disabled
121 // and/or ignore this field. As Kubernetes 1.15 doesn't support this field,
122 // drivers can only support one mode when deployed on such a cluster and the
123 // deployment determines which mode that is, for example via a command line
124 // parameter of the driver.
125 //
126 // This field was immutable in Kubernetes < 1.29 and now is mutable.
127 "podInfoOnMount"?: bool
128
129 // PreventPodSchedulingIfMissing indicates that the CSI driver wants to prevent
130 // pod scheduling if the CSI driver on the node is missing.
131 //
132 // Enabling this option will prevent the scheduler (or any other component which
133 // embeds default scheduler such as cluster-autoscaler) from scheduling pods to
134 // nodes where CSI driver is not installed.
135 //
136 // For components(such as cluster-autoscaler) that embed the scheduler and run
137 // pod placement simulations using scheduler plugins, they MUST be aware of CSI
138 // driver registration information via CSINode object. They must create
139 // simulated CSINode objects in addition to Node objects during scheduling
140 // simulation, otherwise if PreventPodSchedulingIfMissing is enabled globally
141 // for CSIDriver object, any newly created node may be rejected by the
142 // scheduler because of missing CSI driver information from the node.
143 //
144 // This is an alpha feature and requires the VolumeLimitScaling feature gate to
145 // be enabled. Default is "false".
146 "preventPodSchedulingIfMissing"?: bool
147
148 // requiresRepublish indicates the CSI driver wants `NodePublishVolume` being
149 // periodically called to reflect any possible change in the mounted volume.
150 // This field defaults to false.
151 //
152 // Note: After a successful initial NodePublishVolume call, subsequent calls to
153 // NodePublishVolume should only update the contents of the volume. New mount
154 // points will not be seen by a running container.
155 "requiresRepublish"?: bool
156
157 // seLinuxMount specifies if the CSI driver supports "-o context" mount option.
158 //
159 // When "true", the CSI driver must ensure that all volumes provided by this CSI
160 // driver can be mounted separately with different `-o context` options. This
161 // is typical for storage backends that provide volumes as filesystems on block
162 // devices or as independent shared volumes. Kubernetes will call NodeStage /
163 // NodePublish with "-o context=xyz" mount option when mounting a
164 // ReadWriteOncePod volume used in Pod that has explicitly set SELinux context.
165 // In the future, it may be expanded to other volume AccessModes. In any case,
166 // Kubernetes will ensure that the volume is mounted only with a single SELinux
167 // context.
168 //
169 // When "false", Kubernetes won't pass any special SELinux mount options to the
170 // driver. This is typical for volumes that represent subdirectories of a
171 // bigger shared filesystem.
172 //
173 // Default is "false".
174 "seLinuxMount"?: bool
175
176 // serviceAccountTokenInSecrets is an opt-in for CSI drivers to indicate that
177 // service account tokens should be passed via the Secrets field in
178 // NodePublishVolumeRequest instead of the VolumeContext field. The CSI
179 // specification provides a dedicated Secrets field for sensitive information
180 // like tokens, which is the appropriate mechanism for handling credentials.
181 // This addresses security concerns where sensitive tokens were being logged as
182 // part of volume context.
183 //
184 // When "true", kubelet will pass the tokens only in the Secrets field with the
185 // key "csi.storage.k8s.io/serviceAccount.tokens". The CSI driver must be
186 // updated to read tokens from the Secrets field instead of VolumeContext.
187 //
188 // When "false" or not set, kubelet will pass the tokens in VolumeContext with
189 // the key "csi.storage.k8s.io/serviceAccount.tokens" (existing behavior). This
190 // maintains backward compatibility with existing CSI drivers.
191 //
192 // This field can only be set when TokenRequests is configured. The API server
193 // will reject CSIDriver specs that set this field without TokenRequests.
194 //
195 // Default behavior if unset is to pass tokens in the VolumeContext field.
196 "serviceAccountTokenInSecrets"?: bool
197
198 // storageCapacity indicates that the CSI volume driver wants pod scheduling to
199 // consider the storage capacity that the driver deployment will report by
200 // creating CSIStorageCapacity objects with capacity information, if set to
201 // true.
202 //
203 // The check can be enabled immediately when deploying a driver. In that case,
204 // provisioning new volumes with late binding will pause until the driver
205 // deployment has published some suitable CSIStorageCapacity object.
206 //
207 // Alternatively, the driver can be deployed with the field unset or false and
208 // it can be flipped later when storage capacity information has been
209 // published.
210 //
211 // This field was immutable in Kubernetes <= 1.22 and now is mutable.
212 "storageCapacity"?: bool
213
214 // tokenRequests indicates the CSI driver needs pods' service account tokens it
215 // is mounting volume for to do necessary authentication. Kubelet will pass the
216 // tokens in VolumeContext in the CSI NodePublishVolume calls. The CSI driver
217 // should parse and validate the following VolumeContext:
218 // "csi.storage.k8s.io/serviceAccount.tokens": {
219 // "<audience>": {
220 // "token": <token>,
221 // "expirationTimestamp": <expiration timestamp in RFC3339>,
222 // },
223 // ...
224 // }
225 //
226 // Note: Audience in each TokenRequest should be different and at most one token
227 // is empty string. To receive a new token after expiry, RequiresRepublish can
228 // be used to trigger NodePublishVolume periodically.
229 "tokenRequests"?: [...#TokenRequest]
230
231 // volumeLifecycleModes defines what kind of volumes this CSI volume driver
232 // supports. The default if the list is empty is "Persistent", which is the
233 // usage defined by the CSI specification and implemented in Kubernetes via the
234 // usual PV/PVC mechanism.
235 //
236 // The other mode is "Ephemeral". In this mode, volumes are defined inline
237 // inside the pod spec with CSIVolumeSource and their lifecycle is tied to the
238 // lifecycle of that pod. A driver has to be aware of this because it is only
239 // going to get a NodePublishVolume call for such a volume.
240 //
241 // For more information about implementing this mode, see
242 // https://kubernetes-csi.github.io/docs/ephemeral-local-volumes.html A driver
243 // can support one or more of these modes and more modes may be added in the
244 // future.
245 //
246 // This field is beta. This field is immutable.
247 "volumeLifecycleModes"?: [...string]
248}
249
250// CSINode holds information about all CSI drivers installed on a node. CSI
251// drivers do not need to create the CSINode object directly. As long as they
252// use the node-driver-registrar sidecar container, the kubelet will
253// automatically populate the CSINode object for the CSI driver as part of
254// kubelet plugin registration. CSINode has the same name as a node. If the
255// object is missing, it means either there are no CSI Drivers available on the
256// node, or the Kubelet version is low enough that it doesn't create this
257// object. CSINode has an OwnerReference that points to the corresponding node
258// object.
259#CSINode: {
260 // APIVersion defines the versioned schema of this representation of an object.
261 // Servers should convert recognized schemas to the latest internal value, and
262 // may reject unrecognized values. More info:
263 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
264 "apiVersion": "storage.k8s.io/v1"
265
266 // Kind is a string value representing the REST resource this object represents.
267 // Servers may infer this from the endpoint the client submits requests to.
268 // Cannot be updated. In CamelCase. More info:
269 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
270 "kind": "CSINode"
271
272 // Standard object's metadata. metadata.name must be the Kubernetes node name.
273 "metadata"?: v1.#ObjectMeta
274
275 // spec is the specification of CSINode
276 "spec"!: #CSINodeSpec
277}
278
279// CSINodeDriver holds information about the specification of one CSI driver installed on a node
280#CSINodeDriver: {
281 // allocatable represents the volume resources of a node that are available for
282 // scheduling. This field is beta.
283 "allocatable"?: #VolumeNodeResources
284
285 // name represents the name of the CSI driver that this object refers to. This
286 // MUST be the same name returned by the CSI GetPluginName() call for that
287 // driver.
288 "name"!: string
289
290 // nodeID of the node from the driver point of view. This field enables
291 // Kubernetes to communicate with storage systems that do not share the same
292 // nomenclature for nodes. For example, Kubernetes may refer to a given node as
293 // "node1", but the storage system may refer to the same node as "nodeA". When
294 // Kubernetes issues a command to the storage system to attach a volume to a
295 // specific node, it can use this field to refer to the node name using the ID
296 // that the storage system will understand, e.g. "nodeA" instead of "node1".
297 // This field is required.
298 "nodeID"!: string
299
300 // topologyKeys is the list of keys supported by the driver. When a driver is
301 // initialized on a cluster, it provides a set of topology keys that it
302 // understands (e.g. "company.com/zone", "company.com/region"). When a driver
303 // is initialized on a node, it provides the same topology keys along with
304 // values. Kubelet will expose these topology keys as labels on its own node
305 // object. When Kubernetes does topology aware provisioning, it can use this
306 // list to determine which labels it should retrieve from the node object and
307 // pass back to the driver. It is possible for different nodes to use different
308 // topology keys. This can be empty if driver does not support topology.
309 "topologyKeys"?: [...string]
310}
311
312// CSINodeList is a collection of CSINode objects.
313#CSINodeList: {
314 // APIVersion defines the versioned schema of this representation of an object.
315 // Servers should convert recognized schemas to the latest internal value, and
316 // may reject unrecognized values. More info:
317 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
318 "apiVersion": "storage.k8s.io/v1"
319
320 // items is the list of CSINode
321 "items"!: [...#CSINode]
322
323 // Kind is a string value representing the REST resource this object represents.
324 // Servers may infer this from the endpoint the client submits requests to.
325 // Cannot be updated. In CamelCase. More info:
326 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
327 "kind": "CSINodeList"
328
329 // Standard list metadata More info:
330 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
331 "metadata"?: v1.#ListMeta
332}
333
334// CSINodeSpec holds information about the specification of all CSI drivers installed on a node
335#CSINodeSpec: {
336 // drivers is a list of information of all CSI Drivers existing on a node. If
337 // all drivers in the list are uninstalled, this can become empty.
338 "drivers"!: [...#CSINodeDriver]
339}
340
341// CSIStorageCapacity stores the result of one CSI GetCapacity call. For a given
342// StorageClass, this describes the available capacity in a particular topology
343// segment. This can be used when considering where to instantiate new
344// PersistentVolumes.
345//
346// For example this can express things like: - StorageClass "standard" has "1234
347// GiB" available in "topology.kubernetes.io/zone=us-east1" - StorageClass
348// "localssd" has "10 GiB" available in "kubernetes.io/hostname=knode-abc123"
349//
350// The following three cases all imply that no capacity is available for a
351// certain combination: - no object exists with suitable topology and storage
352// class name - such an object exists, but the capacity is unset - such an
353// object exists, but the capacity is zero
354//
355// The producer of these objects can decide which approach is more suitable.
356//
357// They are consumed by the kube-scheduler when a CSI driver opts into
358// capacity-aware scheduling with CSIDriverSpec.StorageCapacity. The scheduler
359// compares the MaximumVolumeSize against the requested size of pending volumes
360// to filter out unsuitable nodes. If MaximumVolumeSize is unset, it falls back
361// to a comparison against the less precise Capacity. If that is also unset,
362// the scheduler assumes that capacity is insufficient and tries some other
363// node.
364#CSIStorageCapacity: {
365 // APIVersion defines the versioned schema of this representation of an object.
366 // Servers should convert recognized schemas to the latest internal value, and
367 // may reject unrecognized values. More info:
368 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
369 "apiVersion": "storage.k8s.io/v1"
370
371 // capacity is the value reported by the CSI driver in its GetCapacityResponse
372 // for a GetCapacityRequest with topology and parameters that match the
373 // previous fields.
374 //
375 // The semantic is currently (CSI spec 1.2) defined as: The available capacity,
376 // in bytes, of the storage that can be used to provision volumes. If not set,
377 // that information is currently unavailable.
378 "capacity"?: resource.#Quantity
379
380 // Kind is a string value representing the REST resource this object represents.
381 // Servers may infer this from the endpoint the client submits requests to.
382 // Cannot be updated. In CamelCase. More info:
383 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
384 "kind": "CSIStorageCapacity"
385
386 // maximumVolumeSize is the value reported by the CSI driver in its
387 // GetCapacityResponse for a GetCapacityRequest with topology and parameters
388 // that match the previous fields.
389 //
390 // This is defined since CSI spec 1.4.0 as the largest size that may be used in
391 // a CreateVolumeRequest.capacity_range.required_bytes field to create a volume
392 // with the same parameters as those in GetCapacityRequest. The corresponding
393 // value in the Kubernetes API is ResourceRequirements.Requests in a volume
394 // claim.
395 "maximumVolumeSize"?: resource.#Quantity
396
397 // Standard object's metadata. The name has no particular meaning. It must be a
398 // DNS subdomain (dots allowed, 253 characters). To ensure that there are no
399 // conflicts with other CSI drivers on the cluster, the recommendation is to
400 // use csisc-<uuid>, a generated name, or a reverse-domain name which ends with
401 // the unique CSI driver name.
402 //
403 // Objects are namespaced.
404 //
405 // More info:
406 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
407 "metadata"?: v1.#ObjectMeta
408
409 // nodeTopology defines which nodes have access to the storage for which
410 // capacity was reported. If not set, the storage is not accessible from any
411 // node in the cluster. If empty, the storage is accessible from all nodes.
412 // This field is immutable.
413 "nodeTopology"?: v1.#LabelSelector
414
415 // storageClassName represents the name of the StorageClass that the reported
416 // capacity applies to. It must meet the same requirements as the name of a
417 // StorageClass object (non-empty, DNS subdomain). If that object no longer
418 // exists, the CSIStorageCapacity object is obsolete and should be removed by
419 // its creator. This field is immutable.
420 "storageClassName"!: string
421}
422
423// CSIStorageCapacityList is a collection of CSIStorageCapacity objects.
424#CSIStorageCapacityList: {
425 // APIVersion defines the versioned schema of this representation of an object.
426 // Servers should convert recognized schemas to the latest internal value, and
427 // may reject unrecognized values. More info:
428 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
429 "apiVersion": "storage.k8s.io/v1"
430
431 // items is the list of CSIStorageCapacity objects.
432 "items"!: [...#CSIStorageCapacity]
433
434 // Kind is a string value representing the REST resource this object represents.
435 // Servers may infer this from the endpoint the client submits requests to.
436 // Cannot be updated. In CamelCase. More info:
437 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
438 "kind": "CSIStorageCapacityList"
439
440 // Standard list metadata More info:
441 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
442 "metadata"?: v1.#ListMeta
443}
444
445// StorageClass describes the parameters for a class of storage for which
446// PersistentVolumes can be dynamically provisioned.
447//
448// StorageClasses are non-namespaced; the name of the storage class according to
449// etcd is in ObjectMeta.Name.
450#StorageClass: {
451 // allowVolumeExpansion shows whether the storage class allow volume expand.
452 "allowVolumeExpansion"?: bool
453
454 // allowedTopologies restrict the node topologies where volumes can be
455 // dynamically provisioned. Each volume plugin defines its own supported
456 // topology specifications. An empty TopologySelectorTerm list means there is
457 // no topology restriction. This field is only honored by servers that enable
458 // the VolumeScheduling feature.
459 "allowedTopologies"?: [...v1_9.#TopologySelectorTerm]
460
461 // APIVersion defines the versioned schema of this representation of an object.
462 // Servers should convert recognized schemas to the latest internal value, and
463 // may reject unrecognized values. More info:
464 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
465 "apiVersion": "storage.k8s.io/v1"
466
467 // Kind is a string value representing the REST resource this object represents.
468 // Servers may infer this from the endpoint the client submits requests to.
469 // Cannot be updated. In CamelCase. More info:
470 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
471 "kind": "StorageClass"
472
473 // Standard object's metadata. More info:
474 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
475 "metadata"?: v1.#ObjectMeta
476
477 // mountOptions controls the mountOptions for dynamically provisioned
478 // PersistentVolumes of this storage class. e.g. ["ro", "soft"]. Not validated
479 // - mount of the PVs will simply fail if one is invalid.
480 "mountOptions"?: [...string]
481
482 // parameters holds the parameters for the provisioner that should create
483 // volumes of this storage class.
484 "parameters"?: [string]: string
485
486 // provisioner indicates the type of the provisioner.
487 "provisioner"!: string
488
489 // reclaimPolicy controls the reclaimPolicy for dynamically provisioned
490 // PersistentVolumes of this storage class. Defaults to Delete.
491 "reclaimPolicy"?: string
492
493 // volumeBindingMode indicates how PersistentVolumeClaims should be provisioned
494 // and bound. When unset, VolumeBindingImmediate is used. This field is only
495 // honored by servers that enable the VolumeScheduling feature.
496 "volumeBindingMode"?: string
497}
498
499// StorageClassList is a collection of storage classes.
500#StorageClassList: {
501 // APIVersion defines the versioned schema of this representation of an object.
502 // Servers should convert recognized schemas to the latest internal value, and
503 // may reject unrecognized values. More info:
504 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
505 "apiVersion": "storage.k8s.io/v1"
506
507 // items is the list of StorageClasses
508 "items"!: [...#StorageClass]
509
510 // Kind is a string value representing the REST resource this object represents.
511 // Servers may infer this from the endpoint the client submits requests to.
512 // Cannot be updated. In CamelCase. More info:
513 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
514 "kind": "StorageClassList"
515
516 // Standard list metadata More info:
517 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
518 "metadata"?: v1.#ListMeta
519}
520
521// TokenRequest contains parameters of a service account token.
522#TokenRequest: {
523 // audience is the intended audience of the token in "TokenRequestSpec". It will
524 // default to the audiences of kube apiserver.
525 "audience"!: string
526
527 // expirationSeconds is the duration of validity of the token in
528 // "TokenRequestSpec". It has the same default value of "ExpirationSeconds" in
529 // "TokenRequestSpec".
530 "expirationSeconds"?: int64 & int
531}
532
533// VolumeAttachment captures the intent to attach or detach the specified volume
534// to/from the specified node.
535//
536// VolumeAttachment objects are non-namespaced.
537#VolumeAttachment: {
538 // APIVersion defines the versioned schema of this representation of an object.
539 // Servers should convert recognized schemas to the latest internal value, and
540 // may reject unrecognized values. More info:
541 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
542 "apiVersion": "storage.k8s.io/v1"
543
544 // Kind is a string value representing the REST resource this object represents.
545 // Servers may infer this from the endpoint the client submits requests to.
546 // Cannot be updated. In CamelCase. More info:
547 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
548 "kind": "VolumeAttachment"
549
550 // Standard object metadata. More info:
551 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
552 "metadata"?: v1.#ObjectMeta
553
554 // spec represents specification of the desired attach/detach volume behavior.
555 // Populated by the Kubernetes system.
556 "spec"!: #VolumeAttachmentSpec
557
558 // status represents status of the VolumeAttachment request. Populated by the
559 // entity completing the attach or detach operation, i.e. the
560 // external-attacher.
561 "status"?: #VolumeAttachmentStatus
562}
563
564// VolumeAttachmentList is a collection of VolumeAttachment objects.
565#VolumeAttachmentList: {
566 // APIVersion defines the versioned schema of this representation of an object.
567 // Servers should convert recognized schemas to the latest internal value, and
568 // may reject unrecognized values. More info:
569 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
570 "apiVersion": "storage.k8s.io/v1"
571
572 // items is the list of VolumeAttachments
573 "items"!: [...#VolumeAttachment]
574
575 // Kind is a string value representing the REST resource this object represents.
576 // Servers may infer this from the endpoint the client submits requests to.
577 // Cannot be updated. In CamelCase. More info:
578 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
579 "kind": "VolumeAttachmentList"
580
581 // Standard list metadata More info:
582 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
583 "metadata"?: v1.#ListMeta
584}
585
586// VolumeAttachmentSource represents a volume that should be attached. Right now
587// only PersistentVolumes can be attached via external attacher, in the future
588// we may allow also inline volumes in pods. Exactly one member can be set.
589#VolumeAttachmentSource: {
590 // inlineVolumeSpec contains all the information necessary to attach a
591 // persistent volume defined by a pod's inline VolumeSource. This field is
592 // populated only for the CSIMigration feature. It contains translated fields
593 // from a pod's inline VolumeSource to a PersistentVolumeSpec. This field is
594 // beta-level and is only honored by servers that enabled the CSIMigration
595 // feature.
596 "inlineVolumeSpec"?: v1_9.#PersistentVolumeSpec
597
598 // persistentVolumeName represents the name of the persistent volume to attach.
599 "persistentVolumeName"?: string
600}
601
602// VolumeAttachmentSpec is the specification of a VolumeAttachment request.
603#VolumeAttachmentSpec: {
604 // attacher indicates the name of the volume driver that MUST handle this
605 // request. This is the name returned by GetPluginName().
606 "attacher"!: string
607
608 // nodeName represents the node that the volume should be attached to.
609 "nodeName"!: string
610
611 // source represents the volume that should be attached.
612 "source"!: #VolumeAttachmentSource
613}
614
615// VolumeAttachmentStatus is the status of a VolumeAttachment request.
616#VolumeAttachmentStatus: {
617 // attachError represents the last error encountered during attach operation, if
618 // any. This field must only be set by the entity completing the attach
619 // operation, i.e. the external-attacher.
620 "attachError"?: #VolumeError
621
622 // attached indicates the volume is successfully attached. This field must only
623 // be set by the entity completing the attach operation, i.e. the
624 // external-attacher.
625 "attached"!: bool
626
627 // attachmentMetadata is populated with any information returned by the attach
628 // operation, upon successful attach, that must be passed into subsequent
629 // WaitForAttach or Mount calls. This field must only be set by the entity
630 // completing the attach operation, i.e. the external-attacher.
631 "attachmentMetadata"?: [string]: string
632
633 // detachError represents the last error encountered during detach operation, if
634 // any. This field must only be set by the entity completing the detach
635 // operation, i.e. the external-attacher.
636 "detachError"?: #VolumeError
637}
638
639// VolumeAttributesClass represents a specification of mutable volume attributes
640// defined by the CSI driver. The class can be specified during dynamic
641// provisioning of PersistentVolumeClaims, and changed in the
642// PersistentVolumeClaim spec after provisioning.
643#VolumeAttributesClass: {
644 // APIVersion defines the versioned schema of this representation of an object.
645 // Servers should convert recognized schemas to the latest internal value, and
646 // may reject unrecognized values. More info:
647 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
648 "apiVersion": "storage.k8s.io/v1"
649
650 // Name of the CSI driver This field is immutable.
651 "driverName"!: string
652
653 // Kind is a string value representing the REST resource this object represents.
654 // Servers may infer this from the endpoint the client submits requests to.
655 // Cannot be updated. In CamelCase. More info:
656 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
657 "kind": "VolumeAttributesClass"
658
659 // Standard object's metadata. More info:
660 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
661 "metadata"?: v1.#ObjectMeta
662
663 // parameters hold volume attributes defined by the CSI driver. These values are
664 // opaque to the Kubernetes and are passed directly to the CSI driver. The
665 // underlying storage provider supports changing these attributes on an
666 // existing volume, however the parameters field itself is immutable. To invoke
667 // a volume update, a new VolumeAttributesClass should be created with new
668 // parameters, and the PersistentVolumeClaim should be updated to reference the
669 // new VolumeAttributesClass.
670 //
671 // This field is required and must contain at least one key/value pair. The keys
672 // cannot be empty, and the maximum number of parameters is 512, with a
673 // cumulative max size of 256K. If the CSI driver rejects invalid parameters,
674 // the target PersistentVolumeClaim will be set to an "Infeasible" state in the
675 // modifyVolumeStatus field.
676 "parameters"?: [string]: string
677}
678
679// VolumeAttributesClassList is a collection of VolumeAttributesClass objects.
680#VolumeAttributesClassList: {
681 // APIVersion defines the versioned schema of this representation of an object.
682 // Servers should convert recognized schemas to the latest internal value, and
683 // may reject unrecognized values. More info:
684 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
685 "apiVersion": "storage.k8s.io/v1"
686
687 // items is the list of VolumeAttributesClass objects.
688 "items"!: [...#VolumeAttributesClass]
689
690 // Kind is a string value representing the REST resource this object represents.
691 // Servers may infer this from the endpoint the client submits requests to.
692 // Cannot be updated. In CamelCase. More info:
693 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
694 "kind": "VolumeAttributesClassList"
695
696 // Standard list metadata More info:
697 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
698 "metadata"?: v1.#ListMeta
699}
700
701// VolumeError captures an error encountered during a volume operation.
702#VolumeError: {
703 // errorCode is a numeric gRPC code representing the error encountered during
704 // Attach or Detach operations.
705 //
706 // This field requires the MutableCSINodeAllocatableCount feature gate being enabled to be set.
707 "errorCode"?: int32 & int
708
709 // message represents the error encountered during Attach or Detach operation.
710 // This string may be logged, so it should not contain sensitive information.
711 "message"?: string
712
713 // time represents the time the error was encountered.
714 "time"?: v1.#Time
715}
716
717// VolumeNodeResources is a set of resource limits for scheduling of volumes.
718#VolumeNodeResources: {
719 // count indicates the maximum number of unique volumes managed by the CSI
720 // driver that can be used on a node. A volume that is both attached and
721 // mounted on a node is considered to be used once, not twice. The same rule
722 // applies for a unique volume that is shared among multiple pods on the same
723 // node. If this field is not specified, then the supported number of volumes
724 // on this node is unbounded.
725 "count"?: int32 & int
726}