Skip to search

PocketIDAPI

pocketid.internal / v1alpha1

apiVersion: pocketid.internal/v1alpha1 kind: PocketIDAPI metadata: name: example
View raw schema
apiVersion string
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string
Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata object
spec object
spec defines the desired state of PocketIDAPI
cimdAccess boolean
CIMDAccess grants every client registered through an OAuth Client ID Metadata Document access to this API, so dynamically-registered clients do not each need an explicit grant. Defaults to true when any permission sets cimdAccess. Set it to true explicitly to grant access with no permissions, which is what a client requesting a resource without any scopes needs, or to false to revoke access while keeping the per-permission marks.
instanceSelector object
InstanceSelector selects the PocketIDInstance to reconcile against. If omitted, the controller expects exactly one instance in the cluster.
matchExpressions []object
matchExpressions is a list of label selector requirements. The requirements are ANDed.
key string required
key is the label key that the selector applies to.
operator string required
operator represents a key's relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
values []string
values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.
matchLabels object
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.
name string
Name of the API to create in Pocket ID. If omitted, defaults to metadata.name of the API resource.
minLength: 2
maxLength: 255
permissions []object
Permissions are the scoped permissions offered by this API. The operator is the sole owner of the API: the permission set in Pocket-ID is reconciled to exactly this list, so permissions added out-of-band are removed.
maxItems: 100
cimdAccess boolean
CIMDAccess lets clients registered through a Client ID Metadata Document request this permission. Only takes effect while spec.cimdAccess is true.
description string
Description optionally explains what the permission grants.
maxLength: 500
key string required
Key is the permission identifier requested as a token scope, e.g. "read:orders". It must be a valid RFC 6749 scope token: printable ASCII with no space, double quote, or backslash. Reserved OIDC scope/claim names are rejected at the spec level.
pattern: ^[\x21\x23-\x5B\x5D-\x7E]+$
minLength: 1
maxLength: 255
name string required
Name is a human-friendly label for the permission.
minLength: 1
maxLength: 255
resource string required
Resource is the audience identifier for tokens issued against this API (typically a URI). It is the permanent identifier used to adopt an existing API and is immutable once set.
minLength: 1
maxLength: 255
status object
status defines the observed state of PocketIDAPI
apiID string
APIID is the ID assigned by Pocket-ID.
cimdAccess boolean
CIMDAccess reports whether CIMD clients may reach this API.
conditions []object
Conditions represent the current state of the PocketIDAPI resource.
lastTransitionTime string required
lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
message string required
message is a human readable message indicating details about the transition. This may be an empty string.
maxLength: 32768
observedGeneration integer
observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
minimum: 0
reason string required
reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
minLength: 1
maxLength: 1024
status string required
status of the condition, one of True, False, Unknown.
enum: True, False, Unknown
type string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
maxLength: 316
createdAt string
CreatedAt is the creation timestamp from Pocket-ID.
name string
Name is the resolved name from Pocket-ID.
permissions []object
Permissions are the permissions resolved from Pocket-ID, including their IDs. This is the lookup table PocketIDOIDCClients use to resolve permission keys.
cimdAccess boolean
CIMDAccess reports whether CIMD clients may request this permission.
id string required
ID is the Pocket-ID identifier for the permission.
key string required
Key is the permission identifier requested as a token scope.
name string
Name is the human-friendly label from Pocket-ID.
resource string
Resource is the resolved audience identifier from Pocket-ID.

No matches. Try .spec.cimdAccess for an exact path