--- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.22.0 name: terdutservers.terdut.ryuvia.com spec: group: terdut.ryuvia.com names: kind: TerdutServer listKind: TerdutServerList plural: terdutservers singular: terdutserver scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.endpoint name: Endpoint type: string - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].reason name: Reason type: string name: v1alpha1 schema: openAPIV3Schema: description: TerdutServer is the Schema for the terdutservers API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: spec defines the desired state of TerdutServer properties: allowedTeams: description: |- allowedTeams gates cross-namespace TerdutTeams (DESIGN.md §4.6). Unused until TerdutTeam exists (Stage 2); present now so this CRD's schema doesn't need a breaking change to grow it later. properties: namespaces: description: |- AllowedTeamsNamespaces gates which namespaces a TerdutTeam may resolve a cross-namespace serverRef into this TerdutServer from (DESIGN.md §4.6). Same-namespace TerdutTeams are always allowed, regardless of this field. Modeled on Gateway API's Gateway.spec.allowedListeners.namespaces. properties: from: default: None description: |- from selects which namespaces may attach. Same is equivalent to None in effect (same-namespace is unrestricted either way) but kept for parity with the upstream enum this mirrors, and to make the policy self-documenting in a diff. enum: - None - Same - All - Selector type: string selector: description: |- selector is required, and only meaningful, when from is Selector: a standard label selector over Namespace objects. properties: matchExpressions: description: matchExpressions is a list of label selector requirements. The requirements are ANDed. items: description: |- A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values. properties: key: description: key is the label key that the selector applies to. type: string operator: description: |- operator represents a key's relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist. type: string values: description: |- values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch. items: type: string type: array x-kubernetes-list-type: atomic required: - key - operator type: object type: array x-kubernetes-list-type: atomic matchLabels: additionalProperties: type: string description: |- matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed. type: object type: object x-kubernetes-map-type: atomic type: object type: object credentialsSecretRef: description: |- credentialsSecretRef names a Secret, in the operator's own namespace, that a human has already created by minting an instance-scoped service account with their own admin session (POST /api/service-accounts, DESIGN.md §6) and placing its raw key under the given key. Set, and the Secret found: the controller adopts it outright and skips bootstrap entirely — this is the expected path for Stage 1, not a fallback (DESIGN.md §6 explains why self-registration cannot complete unauthenticated in the setup this stage actually exercises). Unset: the controller has no way to acquire a credential in this stage (self-registration lands in Stage 5) and reports Ready: False, reason: CredentialsSecretRefRequired. properties: key: description: key is the data key inside the Secret holding the raw value. minLength: 1 type: string name: description: name is the Secret's name. minLength: 1 type: string required: - key - name type: object endpoint: description: |- endpoint is the base URL of an already-running terdut-server this TerdutServer represents, e.g. "http://terdut.oncall.svc:8080". This stage never creates or manages a Deployment/Service for it — the server is expected to already exist, deployed some other way (its own Helm chart, by hand). minLength: 1 type: string required: - endpoint type: object status: description: status defines the observed state of TerdutServer properties: conditions: description: conditions represent the current state of the TerdutServer resource. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array x-kubernetes-list-map-keys: - type x-kubernetes-list-type: map credentialsSecretRef: description: |- credentialsSecretRef mirrors spec.credentialsSecretRef once adopted — same Secret, same key, always in the operator's own namespace. Set only once Bootstrapped is True. properties: key: description: key is the data key inside the Secret holding the raw value. minLength: 1 type: string name: description: name is the Secret's name. minLength: 1 type: string required: - key - name type: object observedGeneration: description: |- observedGeneration is the .metadata.generation this status was last computed against — the standard way a client (or `kubectl wait`) tells "applied" from "seen" (DESIGN.md §7). format: int64 type: integer type: object required: - spec type: object served: true storage: true subresources: status: {}