-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcrd.yml
More file actions
225 lines (222 loc) · 9.34 KB
/
Copy pathcrd.yml
File metadata and controls
225 lines (222 loc) · 9.34 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: resourcesyncs.sinker.influxdata.io
spec:
group: sinker.influxdata.io
names:
kind: ResourceSync
plural: resourcesyncs
singular: resourcesync
scope: Namespaced
versions:
- name: v1alpha1
schema:
openAPIV3Schema:
description: Auto-generated derived type for ResourceSyncSpec via `CustomResource`
properties:
spec:
properties:
mappings:
items:
properties:
fromFieldPath:
description: If `None` then to_field_path cannot be `None`.
nullable: true
type: string
toFieldPath:
description: If `None` then from_field_path cannot be `None`.
nullable: true
type: string
type: object
type: array
source:
properties:
cluster:
description: |-
A missing clusterRef means "this (local) cluster" and the namespace where resourceRef will be searched in
is the namespace of the ResourceSync resource itself. A user cannot thus violate RBAC by referencing secrets
in a namespace they don't have rights to by leveraging sinker.
If a remote cluster reference is provided, then the namespace is taken from the cluster connection parameters.
RBAC is still honoured because sinker can only access resources for which the provided token has rights to.
nullable: true
properties:
kubeConfig:
properties:
secretRef:
properties:
key:
type: string
name:
type: string
namespace:
nullable: true
type: string
required:
- key
- name
type: object
required:
- secretRef
type: object
namespace:
description: If present, overrides the default namespace defined in the provided kubeConfig
nullable: true
type: string
required:
- kubeConfig
type: object
resourceRef:
description: |-
This is a reference to a resource that lives in the cluster specified by the sister cluster field.
The resourceRef GVKN doesn't define the namespace explicitly. Instead, the namespace defends on the
cluster reference.
properties:
apiVersion:
type: string
kind:
type: string
name:
type: string
required:
- apiVersion
- kind
- name
type: object
required:
- resourceRef
type: object
target:
properties:
cluster:
description: |-
A missing clusterRef means "this (local) cluster" and the namespace where resourceRef will be searched in
is the namespace of the ResourceSync resource itself. A user cannot thus violate RBAC by referencing secrets
in a namespace they don't have rights to by leveraging sinker.
If a remote cluster reference is provided, then the namespace is taken from the cluster connection parameters.
RBAC is still honoured because sinker can only access resources for which the provided token has rights to.
nullable: true
properties:
kubeConfig:
properties:
secretRef:
properties:
key:
type: string
name:
type: string
namespace:
nullable: true
type: string
required:
- key
- name
type: object
required:
- secretRef
type: object
namespace:
description: If present, overrides the default namespace defined in the provided kubeConfig
nullable: true
type: string
required:
- kubeConfig
type: object
resourceRef:
description: |-
This is a reference to a resource that lives in the cluster specified by the sister cluster field.
The resourceRef GVKN doesn't define the namespace explicitly. Instead, the namespace defends on the
cluster reference.
properties:
apiVersion:
type: string
kind:
type: string
name:
type: string
required:
- apiVersion
- kind
- name
type: object
required:
- resourceRef
type: object
required:
- source
- target
type: object
x-kubernetes-validations:
- rule: self == oldSelf
status:
nullable: true
properties:
conditions:
items:
description: Condition contains details for one aspect of the current state of this API Resource.
properties:
lastTransitionTime:
description: lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: message is a human readable message indicating details about the transition. This may be an empty string.
type: string
observedGeneration:
description: observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
type: integer
reason:
description: reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
type: string
status:
description: status of the condition, one of True, False, Unknown.
type: string
type:
description: type of condition in CamelCase or in foo.example.com/CamelCase.
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
nullable: true
type: array
type: object
required:
- spec
title: ResourceSync
type: object
served: true
storage: true
subresources:
status: {}
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: sinkercontainers.sinker.influxdata.io
spec:
group: sinker.influxdata.io
names:
kind: SinkerContainer
plural: sinkercontainers
singular: sinkercontainer
scope: Namespaced
versions:
- name: v1alpha1
schema:
openAPIV3Schema:
description: This is a handy generic resource container for use as ResourceSync sources or targets
properties:
spec:
description: This is an arbitrary object
type: object
x-kubernetes-preserve-unknown-fields: true
required:
- spec
type: object
served: true
storage: true