GarageReferenceGrant
garage.rajsingh.info / v1beta1
apiVersion: garage.rajsingh.info/v1beta1
kind: GarageReferenceGrant
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object required
GarageReferenceGrantSpec defines which namespaces and resource kinds are
permitted to make cross-namespace references to resources in this namespace.
from []object required
From lists the permitted sources of cross-namespace references.
minItems:
1
kind
string required
Kind is the resource kind allowed to make cross-namespace references.
GarageAdminToken remains in the schema for compatibility, but the static
credential path is namespace-local and does not accept cross-namespace grants.
enum:
GarageKey, GarageBucket, GarageAdminToken
namespace
string
Namespace is the exact namespace from which cross-namespace references are
allowed. Exactly one of Namespace or NamespaceSelector must be set.
minLength:
1namespaceSelector object
NamespaceSelector selects source namespaces by their Kubernetes labels.
Exactly one of Namespace or NamespaceSelector must be set. An empty
selector matches every namespace.
matchExpressions []object
matchExpressions is a list of label selector requirements. The requirements are ANDed.
key
string required
key is the label key that the selector applies to.
operator
string required
operator represents a key's relationship to a set of values.
Valid operators are In, NotIn, Exists and DoesNotExist.
values
[]string
values is an array of string values. If the operator is In or NotIn,
the values array must be non-empty. If the operator is Exists or DoesNotExist,
the values array must be empty. This array is replaced during a strategic
merge patch.
matchLabels
object
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
map is equivalent to an element of matchExpressions, whose key field is "key", the
operator is "In", and the values array contains only "value". The requirements are ANDed.
to []object
To lists the target resource kinds (and optionally specific names) that
may be referenced. If omitted, all GarageCluster and GarageBucket resources
in this namespace are accessible. This preserves the original grant
behavior; newer target kinds such as GarageKey require an explicit entry.
kind
string required
Kind is the target resource kind.
enum:
GarageCluster, GarageBucket, GarageKey
name
string
Name restricts access to a specific resource. If omitted, all resources of
the given kind in this namespace are accessible.
minLength:
1status object
GarageReferenceGrantStatus reflects which resources are currently using this grant.
conditions []object
Conditions represent the current state.
lastTransitionTime
string required
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format:
date-time
message
string required
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength:
32768
observedGeneration
integer
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64minimum:
0
reason
string required
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
pattern:
^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$minLength:
1maxLength:
1024
status
string required
status of the condition, one of True, False, Unknown.
enum:
True, False, Unknown
type
string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern:
^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$maxLength:
316inUseBy []object
InUseBy lists resources currently referencing through this grant.
Rebuilt on every reconcile — safe to delete when this is empty.
kind
string
Kind of the referencing resource.
name
string
Name of the referencing resource.
namespace
string
Namespace of the referencing resource.
No matches. Try .spec.from for an exact path