PocketIDAPI
pocketid.internal / v1alpha1
apiVersion: pocketid.internal/v1alpha1
kind: PocketIDAPI
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object
spec defines the desired state of PocketIDAPI
cimdAccess
boolean
CIMDAccess grants every client registered through an OAuth Client ID Metadata
Document access to this API, so dynamically-registered clients do not each need an
explicit grant. Defaults to true when any permission sets cimdAccess. Set it to true
explicitly to grant access with no permissions, which is what a client requesting a
resource without any scopes needs, or to false to revoke access while keeping the
per-permission marks.
instanceSelector object
InstanceSelector selects the PocketIDInstance to reconcile against.
If omitted, the controller expects exactly one instance in the cluster.
matchExpressions []object
matchExpressions is a list of label selector requirements. The requirements are ANDed.
key
string required
key is the label key that the selector applies to.
operator
string required
operator represents a key's relationship to a set of values.
Valid operators are In, NotIn, Exists and DoesNotExist.
values
[]string
values is an array of string values. If the operator is In or NotIn,
the values array must be non-empty. If the operator is Exists or DoesNotExist,
the values array must be empty. This array is replaced during a strategic
merge patch.
matchLabels
object
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
map is equivalent to an element of matchExpressions, whose key field is "key", the
operator is "In", and the values array contains only "value". The requirements are ANDed.
name
string
Name of the API to create in Pocket ID.
If omitted, defaults to metadata.name of the API resource.
minLength:
2maxLength:
255permissions []object
Permissions are the scoped permissions offered by this API. The operator is
the sole owner of the API: the permission set in Pocket-ID is reconciled to
exactly this list, so permissions added out-of-band are removed.
maxItems:
100
cimdAccess
boolean
CIMDAccess lets clients registered through a Client ID Metadata Document request
this permission. Only takes effect while spec.cimdAccess is true.
description
string
Description optionally explains what the permission grants.
maxLength:
500
key
string required
Key is the permission identifier requested as a token scope, e.g. "read:orders".
It must be a valid RFC 6749 scope token: printable ASCII with no space, double
quote, or backslash. Reserved OIDC scope/claim names are rejected at the spec level.
pattern:
^[\x21\x23-\x5B\x5D-\x7E]+$minLength:
1maxLength:
255
name
string required
Name is a human-friendly label for the permission.
minLength:
1maxLength:
255
resource
string required
Resource is the audience identifier for tokens issued against this API
(typically a URI). It is the permanent identifier used to adopt an existing
API and is immutable once set.
minLength:
1maxLength:
255status object
status defines the observed state of PocketIDAPI
apiID
string
APIID is the ID assigned by Pocket-ID.
cimdAccess
boolean
CIMDAccess reports whether CIMD clients may reach this API.
conditions []object
Conditions represent the current state of the PocketIDAPI resource.
lastTransitionTime
string required
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format:
date-time
message
string required
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength:
32768
observedGeneration
integer
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64minimum:
0
reason
string required
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
pattern:
^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$minLength:
1maxLength:
1024
status
string required
status of the condition, one of True, False, Unknown.
enum:
True, False, Unknown
type
string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern:
^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$maxLength:
316
createdAt
string
CreatedAt is the creation timestamp from Pocket-ID.
name
string
Name is the resolved name from Pocket-ID.
permissions []object
Permissions are the permissions resolved from Pocket-ID, including their IDs.
This is the lookup table PocketIDOIDCClients use to resolve permission keys.
cimdAccess
boolean
CIMDAccess reports whether CIMD clients may request this permission.
id
string required
ID is the Pocket-ID identifier for the permission.
key
string required
Key is the permission identifier requested as a token scope.
name
string
Name is the human-friendly label from Pocket-ID.
resource
string
Resource is the resolved audience identifier from Pocket-ID.
No matches. Try .spec.cimdAccess for an exact path