1package v1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// CustomResourceColumnDefinition specifies a column for server side printing.
6#CustomResourceColumnDefinition: {
7 // description is a human readable description of this column.
8 "description"?: string
9
10 // format is an optional OpenAPI type definition for this column. The 'name'
11 // format is applied to the primary identifier column to assist in clients
12 // identifying column is the resource name. See
13 // https://github.com/OAI/OpenAPI-Specification/blob/master/versions/2.0.md#data-types
14 // for details.
15 "format"?: string
16
17 // jsonPath is a simple JSON path (i.e. with array notation) which is evaluated
18 // against each custom resource to produce the value for this column.
19 "jsonPath"!: string
20
21 // name is a human readable name for the column.
22 "name"!: string
23
24 // priority is an integer defining the relative importance of this column
25 // compared to others. Lower numbers are considered higher priority. Columns
26 // that may be omitted in limited space scenarios should be given a priority
27 // greater than 0.
28 "priority"?: int32 & int
29
30 // type is an OpenAPI type definition for this column. See
31 // https://github.com/OAI/OpenAPI-Specification/blob/master/versions/2.0.md#data-types
32 // for details.
33 "type"!: string
34}
35
36// CustomResourceConversion describes how to convert different versions of a CR.
37#CustomResourceConversion: {
38 // strategy specifies how custom resources are converted between versions.
39 // Allowed values are: - `"None"`: The converter only change the apiVersion and
40 // would not touch any other field in the custom resource. - `"Webhook"`: API
41 // Server will call to an external webhook to do the conversion. Additional
42 // information
43 // is needed for this option. This requires spec.preserveUnknownFields to be
44 // false, and spec.conversion.webhook to be set.
45 "strategy"!: string
46
47 // webhook describes how to call the conversion webhook. Required when
48 // `strategy` is set to `"Webhook"`.
49 "webhook"?: #WebhookConversion
50}
51
52// CustomResourceDefinition represents a resource that should be exposed on the
53// API server. Its name MUST be in the format <.spec.name>.<.spec.group>.
54#CustomResourceDefinition: {
55 // APIVersion defines the versioned schema of this representation of an object.
56 // Servers should convert recognized schemas to the latest internal value, and
57 // may reject unrecognized values. More info:
58 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
59 "apiVersion": "apiextensions.k8s.io/v1"
60
61 // Kind is a string value representing the REST resource this object represents.
62 // Servers may infer this from the endpoint the client submits requests to.
63 // Cannot be updated. In CamelCase. More info:
64 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
65 "kind": "CustomResourceDefinition"
66
67 // Standard object's metadata More info:
68 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
69 "metadata"?: v1.#ObjectMeta
70
71 // spec describes how the user wants the resources to appear
72 "spec"!: #CustomResourceDefinitionSpec
73
74 // status indicates the actual state of the CustomResourceDefinition
75 "status"?: #CustomResourceDefinitionStatus
76}
77
78// CustomResourceDefinitionCondition contains details for the current condition of this pod.
79#CustomResourceDefinitionCondition: {
80 // lastTransitionTime last time the condition transitioned from one status to another.
81 "lastTransitionTime"?: v1.#Time
82
83 // message is a human-readable message indicating details about last transition.
84 "message"?: string
85
86 // observedGeneration represents the .metadata.generation that the condition was
87 // set based upon. For instance, if .metadata.generation is currently 12, but
88 // the .status.conditions[x].observedGeneration is 9, the condition is out of
89 // date with respect to the current state of the instance.
90 "observedGeneration"?: int64 & int
91
92 // reason is a unique, one-word, CamelCase reason for the condition's last transition.
93 "reason"?: string
94
95 // status is the status of the condition. Can be True, False, Unknown.
96 "status"!: string
97
98 // type is the type of the condition. Types include Established, NamesAccepted and Terminating.
99 "type"!: string
100}
101
102// CustomResourceDefinitionList is a list of CustomResourceDefinition objects.
103#CustomResourceDefinitionList: {
104 // APIVersion defines the versioned schema of this representation of an object.
105 // Servers should convert recognized schemas to the latest internal value, and
106 // may reject unrecognized values. More info:
107 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
108 "apiVersion": "apiextensions.k8s.io/v1"
109
110 // items list individual CustomResourceDefinition objects
111 "items"!: [...#CustomResourceDefinition]
112
113 // Kind is a string value representing the REST resource this object represents.
114 // Servers may infer this from the endpoint the client submits requests to.
115 // Cannot be updated. In CamelCase. More info:
116 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
117 "kind": "CustomResourceDefinitionList"
118
119 // Standard object's metadata More info:
120 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
121 "metadata"?: v1.#ListMeta
122}
123
124// CustomResourceDefinitionNames indicates the names to serve this CustomResourceDefinition
125#CustomResourceDefinitionNames: {
126 // categories is a list of grouped resources this custom resource belongs to
127 // (e.g. 'all'). This is published in API discovery documents, and used by
128 // clients to support invocations like `kubectl get all`.
129 "categories"?: [...string]
130
131 // kind is the serialized kind of the resource. It is normally CamelCase and
132 // singular. Custom resource instances will use this value as the `kind`
133 // attribute in API calls.
134 "kind"!: string
135
136 // listKind is the serialized kind of the list for this resource. Defaults to "`kind`List".
137 "listKind"?: string
138
139 // plural is the plural name of the resource to serve. The custom resources are
140 // served under `/apis/<group>/<version>/.../<plural>`. Must match the name of
141 // the CustomResourceDefinition (in the form `<names.plural>.<group>`). Must be
142 // all lowercase.
143 "plural"!: string
144
145 // shortNames are short names for the resource, exposed in API discovery
146 // documents, and used by clients to support invocations like `kubectl get
147 // <shortname>`. It must be all lowercase.
148 "shortNames"?: [...string]
149
150 // singular is the singular name of the resource. It must be all lowercase.
151 // Defaults to lowercased `kind`.
152 "singular"?: string
153}
154
155// CustomResourceDefinitionSpec describes how a user wants their resource to appear
156#CustomResourceDefinitionSpec: {
157 // conversion defines conversion settings for the CRD.
158 "conversion"?: #CustomResourceConversion
159
160 // group is the API group of the defined custom resource. The custom resources
161 // are served under `/apis/<group>/...`. Must match the name of the
162 // CustomResourceDefinition (in the form `<names.plural>.<group>`).
163 "group"!: string
164
165 // names specify the resource and kind names for the custom resource.
166 "names"!: #CustomResourceDefinitionNames
167
168 // preserveUnknownFields indicates that object fields which are not specified in
169 // the OpenAPI schema should be preserved when persisting to storage.
170 // apiVersion, kind, metadata and known fields inside metadata are always
171 // preserved. This field is deprecated in favor of setting
172 // `x-preserve-unknown-fields` to true in
173 // `spec.versions[*].schema.openAPIV3Schema`. See
174 // https://kubernetes.io/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definitions/#field-pruning
175 // for details.
176 "preserveUnknownFields"?: bool
177
178 // scope indicates whether the defined custom resource is cluster- or
179 // namespace-scoped. Allowed values are `Cluster` and `Namespaced`.
180 "scope"!: string
181
182 // versions is the list of all API versions of the defined custom resource.
183 // Version names are used to compute the order in which served versions are
184 // listed in API discovery. If the version string is "kube-like", it will sort
185 // above non "kube-like" version strings, which are ordered lexicographically.
186 // "Kube-like" versions start with a "v", then are followed by a number (the
187 // major version), then optionally the string "alpha" or "beta" and another
188 // number (the minor version). These are sorted first by GA > beta > alpha
189 // (where GA is a version with no suffix such as beta or alpha), and then by
190 // comparing major version, then minor version. An example sorted list of
191 // versions: v10, v2, v1, v11beta2, v10beta3, v3beta1, v12alpha1, v11alpha2,
192 // foo1, foo10.
193 "versions"!: [...#CustomResourceDefinitionVersion]
194}
195
196// CustomResourceDefinitionStatus indicates the state of the CustomResourceDefinition
197#CustomResourceDefinitionStatus: {
198 // acceptedNames are the names that are actually being used to serve discovery.
199 // They may be different than the names in spec.
200 "acceptedNames"?: #CustomResourceDefinitionNames
201
202 // conditions indicate state for particular aspects of a CustomResourceDefinition
203 "conditions"?: [...#CustomResourceDefinitionCondition]
204
205 // The generation observed by the CRD controller.
206 "observedGeneration"?: int64 & int
207
208 // storedVersions lists all versions of CustomResources that were ever
209 // persisted. Tracking these versions allows a migration path for stored
210 // versions in etcd. The field is mutable so a migration controller can finish
211 // a migration to another version (ensuring no old objects are left in
212 // storage), and then remove the rest of the versions from this list. Versions
213 // may not be removed from `spec.versions` while they exist in this list.
214 "storedVersions"?: [...string]
215}
216
217// CustomResourceDefinitionVersion describes a version for CRD.
218#CustomResourceDefinitionVersion: {
219 // additionalPrinterColumns specifies additional columns returned in Table
220 // output. See
221 // https://kubernetes.io/docs/reference/using-api/api-concepts/#receiving-resources-as-tables
222 // for details. If no columns are specified, a single column displaying the age
223 // of the custom resource is used.
224 "additionalPrinterColumns"?: [...#CustomResourceColumnDefinition]
225
226 // deprecated indicates this version of the custom resource API is deprecated.
227 // When set to true, API requests to this version receive a warning header in
228 // the server response. Defaults to false.
229 "deprecated"?: bool
230
231 // deprecationWarning overrides the default warning returned to API clients. May
232 // only be set when `deprecated` is true. The default warning indicates this
233 // version is deprecated and recommends use of the newest served version of
234 // equal or greater stability, if one exists.
235 "deprecationWarning"?: string
236
237 // name is the version name, e.g. “v1”, “v2beta1”, etc. The custom resources are
238 // served under this version at `/apis/<group>/<version>/...` if `served` is
239 // true.
240 "name"!: string
241
242 // schema describes the schema used for validation, pruning, and defaulting of
243 // this version of the custom resource.
244 "schema"?: #CustomResourceValidation
245
246 // selectableFields specifies paths to fields that may be used as field
247 // selectors. A maximum of 8 selectable fields are allowed. See
248 // https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors
249 "selectableFields"?: [...#SelectableField]
250
251 // served is a flag enabling/disabling this version from being served via REST APIs
252 "served"!: bool
253
254 // storage indicates this version should be used when persisting custom
255 // resources to storage. There must be exactly one version with storage=true.
256 "storage"!: bool
257
258 // subresources specify what subresources this version of the defined custom resource have.
259 "subresources"?: #CustomResourceSubresources
260}
261
262// CustomResourceSubresourceScale defines how to serve the scale subresource for CustomResources.
263#CustomResourceSubresourceScale: {
264 // labelSelectorPath defines the JSON path inside of a custom resource that
265 // corresponds to Scale `status.selector`. Only JSON paths without the array
266 // notation are allowed. Must be a JSON Path under `.status` or `.spec`. Must
267 // be set to work with HorizontalPodAutoscaler. The field pointed by this JSON
268 // path must be a string field (not a complex selector struct) which contains a
269 // serialized label selector in string form. More info:
270 // https://kubernetes.io/docs/tasks/access-kubernetes-api/custom-resources/custom-resource-definitions#scale-subresource
271 // If there is no value under the given path in the custom resource, the
272 // `status.selector` value in the `/scale` subresource will default to the
273 // empty string.
274 "labelSelectorPath"?: string
275
276 // specReplicasPath defines the JSON path inside of a custom resource that
277 // corresponds to Scale `spec.replicas`. Only JSON paths without the array
278 // notation are allowed. Must be a JSON Path under `.spec`. If there is no
279 // value under the given path in the custom resource, the `/scale` subresource
280 // will return an error on GET.
281 "specReplicasPath"!: string
282
283 // statusReplicasPath defines the JSON path inside of a custom resource that
284 // corresponds to Scale `status.replicas`. Only JSON paths without the array
285 // notation are allowed. Must be a JSON Path under `.status`. If there is no
286 // value under the given path in the custom resource, the `status.replicas`
287 // value in the `/scale` subresource will default to 0.
288 "statusReplicasPath"!: string
289}
290
291// CustomResourceSubresourceStatus defines how to serve the status subresource
292// for CustomResources. Status is represented by the `.status` JSON path inside
293// of a CustomResource. When set, * exposes a /status subresource for the
294// custom resource * PUT requests to the /status subresource take a custom
295// resource object, and ignore changes to anything except the status stanza *
296// PUT/POST/PATCH requests to the custom resource ignore changes to the status
297// stanza
298#CustomResourceSubresourceStatus: {}
299
300// CustomResourceSubresources defines the status and scale subresources for CustomResources.
301#CustomResourceSubresources: {
302 // scale indicates the custom resource should serve a `/scale` subresource that
303 // returns an `autoscaling/v1` Scale object.
304 "scale"?: #CustomResourceSubresourceScale
305
306 // status indicates the custom resource should serve a `/status` subresource.
307 // When enabled: 1. requests to the custom resource primary endpoint ignore
308 // changes to the `status` stanza of the object. 2. requests to the custom
309 // resource `/status` subresource ignore changes to anything other than the
310 // `status` stanza of the object.
311 "status"?: #CustomResourceSubresourceStatus
312}
313
314// CustomResourceValidation is a list of validation methods for CustomResources.
315#CustomResourceValidation: {
316 // openAPIV3Schema is the OpenAPI v3 schema to use for validation and pruning.
317 "openAPIV3Schema"?: #JSONSchemaProps
318}
319
320// ExternalDocumentation allows referencing an external resource for extended documentation.
321#ExternalDocumentation: {
322 "description"?: string
323 "url"?: string
324}
325
326// JSON represents any valid JSON value. These types are supported: bool, int64,
327// float64, string, []interface{}, map[string]interface{} and nil.
328#JSON: _
329
330// JSONSchemaProps is a JSON-Schema following Specification Draft 4 (http://json-schema.org/).
331#JSONSchemaProps: {
332 "$ref"?: string
333 "$schema"?: string
334 "additionalItems"?: #JSONSchemaPropsOrBool
335 "additionalProperties"?: #JSONSchemaPropsOrBool
336 "allOf"?: [...#JSONSchemaProps]
337 "anyOf"?: [...#JSONSchemaProps]
338
339 // default is a default value for undefined object fields. Defaulting is a beta
340 // feature under the CustomResourceDefaulting feature gate. Defaulting requires
341 // spec.preserveUnknownFields to be false.
342 "default"?: #JSON
343 "definitions"?: [string]: #JSONSchemaProps
344 "dependencies"?: [string]: #JSONSchemaPropsOrStringArray
345 "description"?: string
346 "enum"?: [...#JSON]
347 "example"?: #JSON
348 "exclusiveMaximum"?: bool
349 "exclusiveMinimum"?: bool
350 "externalDocs"?: #ExternalDocumentation
351
352 // format is an OpenAPI v3 format string. Unknown formats are ignored. The
353 // following formats are validated:
354 //
355 // - bsonobjectid: a bson object ID, i.e. a 24 characters hex string - uri: an
356 // URI as parsed by Golang net/url.ParseRequestURI - email: an email address as
357 // parsed by Golang net/mail.ParseAddress - hostname: a valid representation
358 // for an Internet host name, as defined by RFC 1034, section 3.1 [RFC1034]. -
359 // ipv4: an IPv4 IP as parsed by Golang net.ParseIP - ipv6: an IPv6 IP as
360 // parsed by Golang net.ParseIP - cidr: a CIDR as parsed by Golang
361 // net.ParseCIDR - mac: a MAC address as parsed by Golang net.ParseMAC - uuid:
362 // an UUID that allows uppercase defined by the regex
363 // (?i)^[0-9a-f]{8}-?[0-9a-f]{4}-?[0-9a-f]{4}-?[0-9a-f]{4}-?[0-9a-f]{12}$ -
364 // uuid3: an UUID3 that allows uppercase defined by the regex
365 // (?i)^[0-9a-f]{8}-?[0-9a-f]{4}-?3[0-9a-f]{3}-?[0-9a-f]{4}-?[0-9a-f]{12}$ -
366 // uuid4: an UUID4 that allows uppercase defined by the regex
367 // (?i)^[0-9a-f]{8}-?[0-9a-f]{4}-?4[0-9a-f]{3}-?[89ab][0-9a-f]{3}-?[0-9a-f]{12}$
368 // - uuid5: an UUID5 that allows uppercase defined by the regex
369 // (?i)^[0-9a-f]{8}-?[0-9a-f]{4}-?5[0-9a-f]{3}-?[89ab][0-9a-f]{3}-?[0-9a-f]{12}$
370 // - isbn: an ISBN10 or ISBN13 number string like "0321751043" or
371 // "978-0321751041" - isbn10: an ISBN10 number string like "0321751043" -
372 // isbn13: an ISBN13 number string like "978-0321751041" - creditcard: a credit
373 // card number defined by the regex
374 // ^(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14}|6(?:011|5[0-9][0-9])[0-9]{12}|3[47][0-9]{13}|3(?:0[0-5]|[68][0-9])[0-9]{11}|(?:2131|1800|35\\d{3})\\d{11})$
375 // with any non digit characters mixed in - ssn: a U.S. social security number
376 // following the regex ^\\d{3}[- ]?\\d{2}[- ]?\\d{4}$ - hexcolor: an
377 // hexadecimal color code like "#FFFFFF: following the regex
378 // ^#?([0-9a-fA-F]{3}|[0-9a-fA-F]{6})$ - rgbcolor: an RGB color code like rgb
379 // like "rgb(255,255,2559" - byte: base64 encoded binary data - password: any
380 // kind of string - date: a date string like "2006-01-02" as defined by
381 // full-date in RFC3339 - duration: a duration string like "22 ns" as parsed by
382 // Golang time.ParseDuration or compatible with Scala duration format -
383 // datetime: a date time string like "2014-12-15T19:30:20.000Z" as defined by
384 // date-time in RFC3339.
385 "format"?: string
386 "id"?: string
387 "items"?: #JSONSchemaPropsOrArray
388 "maxItems"?: int64 & int
389 "maxLength"?: int64 & int
390 "maxProperties"?: int64 & int
391 "maximum"?: float64
392 "minItems"?: int64 & int
393 "minLength"?: int64 & int
394 "minProperties"?: int64 & int
395 "minimum"?: float64
396 "multipleOf"?: float64
397 "not"?: #JSONSchemaProps
398 "nullable"?: bool
399 "oneOf"?: [...#JSONSchemaProps]
400 "pattern"?: string
401 "patternProperties"?: [string]: #JSONSchemaProps
402 "properties"?: [string]: #JSONSchemaProps
403 "required"?: [...string]
404 "title"?: string
405 "type"?: string
406 "uniqueItems"?: bool
407
408 // x-kubernetes-embedded-resource defines that the value is an embedded
409 // Kubernetes runtime.Object, with TypeMeta and ObjectMeta. The type must be
410 // object. It is allowed to further restrict the embedded object. kind,
411 // apiVersion and metadata are validated automatically.
412 // x-kubernetes-preserve-unknown-fields is allowed to be true, but does not
413 // have to be if the object is fully specified (up to kind, apiVersion,
414 // metadata).
415 "x-kubernetes-embedded-resource"?: bool
416
417 // x-kubernetes-int-or-string specifies that this value is either an integer or
418 // a string. If this is true, an empty type is allowed and type as child of
419 // anyOf is permitted if following one of the following patterns:
420 //
421 // 1) anyOf:
422 // - type: integer
423 // - type: string
424 // 2) allOf:
425 // - anyOf:
426 // - type: integer
427 // - type: string
428 // - ... zero or more
429 "x-kubernetes-int-or-string"?: bool
430
431 // x-kubernetes-list-map-keys annotates an array with the x-kubernetes-list-type
432 // `map` by specifying the keys used as the index of the map.
433 //
434 // This tag MUST only be used on lists that have the "x-kubernetes-list-type"
435 // extension set to "map". Also, the values specified for this attribute must
436 // be a scalar typed field of the child structure (no nesting is supported).
437 //
438 // The properties specified must either be required or have a default value, to
439 // ensure those properties are present for all list items.
440 "x-kubernetes-list-map-keys"?: [...string]
441
442 // x-kubernetes-list-type annotates an array to further describe its topology.
443 // This extension must only be used on lists and may have 3 possible values:
444 //
445 // 1) `atomic`: the list is treated as a single entity, like a scalar.
446 // Atomic lists will be entirely replaced when updated. This extension
447 // may be used on any type of list (struct, scalar, ...).
448 // 2) `set`:
449 // Sets are lists that must not have multiple items with the same value. Each
450 // value must be a scalar, an object with x-kubernetes-map-type `atomic` or an
451 // array with x-kubernetes-list-type `atomic`.
452 // 3) `map`:
453 // These lists are like maps in that their elements have a non-index key
454 // used to identify them. Order is preserved upon merge. The map tag
455 // must only be used on a list with elements of type object.
456 // Defaults to atomic for arrays.
457 "x-kubernetes-list-type"?: string
458
459 // x-kubernetes-map-type annotates an object to further describe its topology.
460 // This extension must only be used when type is object and may have 2 possible
461 // values:
462 //
463 // 1) `granular`:
464 // These maps are actual maps (key-value pairs) and each fields are independent
465 // from each other (they can each be manipulated by separate actors). This is
466 // the default behaviour for all maps.
467 // 2) `atomic`: the list is treated as a single entity, like a scalar.
468 // Atomic maps will be entirely replaced when updated.
469 "x-kubernetes-map-type"?: string
470
471 // x-kubernetes-preserve-unknown-fields stops the API server decoding step from
472 // pruning fields which are not specified in the validation schema. This
473 // affects fields recursively, but switches back to normal pruning behaviour if
474 // nested properties or additionalProperties are specified in the schema. This
475 // can either be true or undefined. False is forbidden.
476 "x-kubernetes-preserve-unknown-fields"?: bool
477
478 // x-kubernetes-validations describes a list of validation rules written in the
479 // CEL expression language.
480 "x-kubernetes-validations"?: [...#ValidationRule]
481}
482
483// JSONSchemaPropsOrArray represents a value that can either be a
484// JSONSchemaProps or an array of JSONSchemaProps. Mainly here for
485// serialization purposes.
486#JSONSchemaPropsOrArray: _
487
488// JSONSchemaPropsOrBool represents JSONSchemaProps or a boolean value. Defaults
489// to true for the boolean property.
490#JSONSchemaPropsOrBool: _
491
492// JSONSchemaPropsOrStringArray represents a JSONSchemaProps or a string array.
493#JSONSchemaPropsOrStringArray: _
494
495// SelectableField specifies the JSON path of a field that may be used with field selectors.
496#SelectableField: {
497 // jsonPath is a simple JSON path which is evaluated against each custom
498 // resource to produce a field selector value. Only JSON paths without the
499 // array notation are allowed. Must point to a field of type string, boolean or
500 // integer. Types with enum values and strings with formats are allowed. If
501 // jsonPath refers to absent field in a resource, the jsonPath evaluates to an
502 // empty string. Must not point to metdata fields. Required.
503 "jsonPath"!: string
504}
505
506// ServiceReference holds a reference to Service.legacy.k8s.io
507#ServiceReference: {
508 // name is the name of the service. Required
509 "name"!: string
510
511 // namespace is the namespace of the service. Required
512 "namespace"!: string
513
514 // path is an optional URL path at which the webhook will be contacted.
515 "path"?: string
516
517 // port is an optional service port at which the webhook will be contacted.
518 // `port` should be a valid port number (1-65535, inclusive). Defaults to 443
519 // for backward compatibility.
520 "port"?: int32 & int
521}
522
523// ValidationRule describes a validation rule written in the CEL expression language.
524#ValidationRule: {
525 // fieldPath represents the field path returned when the validation fails. It
526 // must be a relative JSON path (i.e. with array notation) scoped to the
527 // location of this x-kubernetes-validations extension in the schema and refer
528 // to an existing field. e.g. when validation checks if a specific attribute
529 // `foo` under a map `testMap`, the fieldPath could be set to `.testMap.foo` If
530 // the validation checks two lists must have unique attributes, the fieldPath
531 // could be set to either of the list: e.g. `.testList` It does not support
532 // list numeric index. It supports child operation to refer to an existing
533 // field currently. Refer to [JSONPath support in
534 // Kubernetes](https://kubernetes.io/docs/reference/kubectl/jsonpath/) for more
535 // info. Numeric index of array is not supported. For field name which contains
536 // special characters, use `['specialName']` to refer the field name. e.g. for
537 // attribute `foo.34$` appears in a list `testList`, the fieldPath could be set
538 // to `.testList['foo.34$']`
539 "fieldPath"?: string
540
541 // Message represents the message displayed when validation fails. The message
542 // is required if the Rule contains line breaks. The message must not contain
543 // line breaks. If unset, the message is "failed rule: {Rule}". e.g. "must be a
544 // URL with the host matching spec.host"
545 "message"?: string
546
547 // MessageExpression declares a CEL expression that evaluates to the validation
548 // failure message that is returned when this rule fails. Since
549 // messageExpression is used as a failure message, it must evaluate to a
550 // string. If both message and messageExpression are present on a rule, then
551 // messageExpression will be used if validation fails. If messageExpression
552 // results in a runtime error, the runtime error is logged, and the validation
553 // failure message is produced as if the messageExpression field were unset. If
554 // messageExpression evaluates to an empty string, a string with only spaces,
555 // or a string that contains line breaks, then the validation failure message
556 // will also be produced as if the messageExpression field were unset, and the
557 // fact that messageExpression produced an empty string/string with only
558 // spaces/string with line breaks will be logged. messageExpression has access
559 // to all the same variables as the rule; the only difference is the return
560 // type. Example: "x must be less than max ("+string(self.max)+")"
561 "messageExpression"?: string
562
563 // optionalOldSelf is used to opt a transition rule into evaluation even when
564 // the object is first created, or if the old object is missing the value.
565 //
566 // When enabled `oldSelf` will be a CEL optional whose value will be `None` if
567 // there is no old value, or when the object is initially created.
568 //
569 // You may check for presence of oldSelf using `oldSelf.hasValue()` and unwrap
570 // it after checking using `oldSelf.value()`. Check the CEL documentation for
571 // Optional types for more information:
572 // https://pkg.go.dev/github.com/google/cel-go/cel#OptionalTypes
573 //
574 // May not be set unless `oldSelf` is used in `rule`.
575 "optionalOldSelf"?: bool
576
577 // reason provides a machine-readable validation failure reason that is returned
578 // to the caller when a request fails this validation rule. The HTTP status
579 // code returned to the caller will match the reason of the reason of the first
580 // failed validation rule. The currently supported reasons are:
581 // "FieldValueInvalid", "FieldValueForbidden", "FieldValueRequired",
582 // "FieldValueDuplicate". If not set, default to use "FieldValueInvalid". All
583 // future added reasons must be accepted by clients when reading this value and
584 // unknown reasons should be treated as FieldValueInvalid.
585 "reason"?: string
586
587 // Rule represents the expression which will be evaluated by CEL. ref:
588 // https://github.com/google/cel-spec The Rule is scoped to the location of the
589 // x-kubernetes-validations extension in the schema. The `self` variable in the
590 // CEL expression is bound to the scoped value. Example: - Rule scoped to the
591 // root of a resource with a status subresource: {"rule": "self.status.actual
592 // <= self.spec.maxDesired"}
593 //
594 // If the Rule is scoped to an object with properties, the accessible properties
595 // of the object are field selectable via `self.field` and field presence can
596 // be checked via `has(self.field)`. Null valued fields are treated as absent
597 // fields in CEL expressions. If the Rule is scoped to an object with
598 // additionalProperties (i.e. a map) the value of the map are accessible via
599 // `self[mapKey]`, map containment can be checked via `mapKey in self` and all
600 // entries of the map are accessible via CEL macros and functions such as
601 // `self.all(...)`. If the Rule is scoped to an array, the elements of the
602 // array are accessible via `self[i]` and also by macros and functions. If the
603 // Rule is scoped to a scalar, `self` is bound to the scalar value. Examples: -
604 // Rule scoped to a map of objects: {"rule":
605 // "self.components['Widget'].priority < 10"} - Rule scoped to a list of
606 // integers: {"rule": "self.values.all(value, value >= 0 && value < 100)"} -
607 // Rule scoped to a string value: {"rule": "self.startsWith('kube')"}
608 //
609 // The `apiVersion`, `kind`, `metadata.name` and `metadata.generateName` are
610 // always accessible from the root of the object and from any
611 // x-kubernetes-embedded-resource annotated objects. No other metadata
612 // properties are accessible.
613 //
614 // Unknown data preserved in custom resources via
615 // x-kubernetes-preserve-unknown-fields is not accessible in CEL expressions.
616 // This includes: - Unknown field values that are preserved by object schemas
617 // with x-kubernetes-preserve-unknown-fields. - Object properties where the
618 // property schema is of an "unknown type". An "unknown type" is recursively
619 // defined as:
620 // - A schema with no type and x-kubernetes-preserve-unknown-fields set to true
621 // - An array where the items schema is of an "unknown type"
622 // - An object where the additionalProperties schema is of an "unknown type"
623 //
624 // Only property names of the form `[a-zA-Z_.-/][a-zA-Z0-9_.-/]*` are
625 // accessible. Accessible property names are escaped according to the following
626 // rules when accessed in the expression: - '__' escapes to '__underscores__' -
627 // '.' escapes to '__dot__' - '-' escapes to '__dash__' - '/' escapes to
628 // '__slash__' - Property names that exactly match a CEL RESERVED keyword
629 // escape to '__{keyword}__'. The keywords are:
630 // "true", "false", "null", "in", "as", "break", "const", "continue", "else",
631 // "for", "function", "if",
632 // "import", "let", "loop", "package", "namespace", "return".
633 // Examples:
634 // - Rule accessing a property named "namespace": {"rule": "self.__namespace__ > 0"}
635 // - Rule accessing a property named "x-prop": {"rule": "self.x__dash__prop > 0"}
636 // - Rule accessing a property named "redact__d": {"rule": "self.redact__underscores__d > 0"}
637 //
638 // Equality on arrays with x-kubernetes-list-type of 'set' or 'map' ignores
639 // element order, i.e. [1, 2] == [2, 1]. Concatenation on arrays with
640 // x-kubernetes-list-type use the semantics of the list type:
641 // - 'set': `X + Y` performs a union where the array positions of all elements
642 // in `X` are preserved and
643 // non-intersecting elements in `Y` are appended, retaining their partial order.
644 // - 'map': `X + Y` performs a merge where the array positions of all keys in
645 // `X` are preserved but the values
646 // are overwritten by values in `Y` when the key sets of `X` and `Y` intersect. Elements in `Y` with
647 // non-intersecting keys are appended, retaining their partial order.
648 //
649 // If `rule` makes use of the `oldSelf` variable it is implicitly a `transition rule`.
650 //
651 // By default, the `oldSelf` variable is the same type as `self`. When
652 // `optionalOldSelf` is true, the `oldSelf` variable is a CEL optional
653 // variable whose value() is the same type as `self`.
654 // See the documentation for the `optionalOldSelf` field for details.
655 //
656 // Transition rules by default are applied only on UPDATE requests and are
657 // skipped if an old value could not be found. You can opt a transition rule
658 // into unconditional evaluation by setting `optionalOldSelf` to true.
659 "rule"!: string
660}
661
662// WebhookClientConfig contains the information to make a TLS connection with the webhook.
663#WebhookClientConfig: {
664 // caBundle is a PEM encoded CA bundle which will be used to validate the
665 // webhook's server certificate. If unspecified, system trust roots on the
666 // apiserver are used.
667 "caBundle"?: string
668
669 // service is a reference to the service for this webhook. Either service or url must be specified.
670 //
671 // If the webhook is running within the cluster, then you should use `service`.
672 "service"?: #ServiceReference
673
674 // url gives the location of the webhook, in standard URL form
675 // (`scheme://host:port/path`). Exactly one of `url` or `service` must be
676 // specified.
677 //
678 // The `host` should not refer to a service running in the cluster; use the
679 // `service` field instead. The host might be resolved via external DNS in some
680 // apiservers (e.g., `kube-apiserver` cannot resolve in-cluster DNS as that
681 // would be a layering violation). `host` may also be an IP address.
682 //
683 // Please note that using `localhost` or `127.0.0.1` as a `host` is risky unless
684 // you take great care to run this webhook on all hosts which run an apiserver
685 // which might need to make calls to this webhook. Such installs are likely to
686 // be non-portable, i.e., not easy to turn up in a new cluster.
687 //
688 // The scheme must be "https"; the URL must begin with "https://".
689 //
690 // A path is optional, and if present may be any string permissible in a URL.
691 // You may use the path to pass an arbitrary string to the webhook, for
692 // example, a cluster identifier.
693 //
694 // Attempting to use a user or basic auth e.g. "user:password@" is not allowed.
695 // Fragments ("#...") and query parameters ("?...") are not allowed, either.
696 "url"?: string
697}
698
699// WebhookConversion describes how to call a conversion webhook
700#WebhookConversion: {
701 // clientConfig is the instructions for how to call the webhook if strategy is `Webhook`.
702 "clientConfig"?: #WebhookClientConfig
703
704 // conversionReviewVersions is an ordered list of preferred `ConversionReview`
705 // versions the Webhook expects. The API server will use the first version in
706 // the list which it supports. If none of the versions specified in this list
707 // are supported by API server, conversion will fail for the custom resource.
708 // If a persisted Webhook configuration specifies allowed versions and does not
709 // include any versions known to the API Server, calls to the webhook will
710 // fail.
711 "conversionReviewVersions"!: [...string]
712}