locostack.com_managedtools.yaml 283 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097
  1. ---
  2. apiVersion: apiextensions.k8s.io/v1
  3. kind: CustomResourceDefinition
  4. metadata:
  5. annotations:
  6. controller-gen.kubebuilder.io/version: v0.20.1
  7. name: managedtools.locostack.com
  8. spec:
  9. group: locostack.com
  10. names:
  11. kind: ManagedTool
  12. listKind: ManagedToolList
  13. plural: managedtools
  14. shortNames:
  15. - mt
  16. singular: managedtool
  17. scope: Namespaced
  18. versions:
  19. - additionalPrinterColumns:
  20. - jsonPath: .spec.toolName
  21. name: Tool
  22. type: string
  23. - jsonPath: .spec.template.name
  24. name: Runtime
  25. type: string
  26. - jsonPath: .status.conditions[?(@.type=='Ready')].status
  27. name: Ready
  28. type: string
  29. name: v1alpha1
  30. schema:
  31. openAPIV3Schema:
  32. description: ManagedTool is the Schema for the managedtools API
  33. properties:
  34. apiVersion:
  35. description: |-
  36. APIVersion defines the versioned schema of this representation of an object.
  37. Servers should convert recognized schemas to the latest internal value, and
  38. may reject unrecognized values.
  39. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  40. type: string
  41. kind:
  42. description: |-
  43. Kind is a string value representing the REST resource this object represents.
  44. Servers may infer this from the endpoint the client submits requests to.
  45. Cannot be updated.
  46. In CamelCase.
  47. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  48. type: string
  49. metadata:
  50. type: object
  51. spec:
  52. description: spec defines the desired state of ManagedTool
  53. properties:
  54. auth:
  55. description: |-
  56. auth describes how to authenticate to the managed MCP server.
  57. Omit only for unauthenticated endpoints.
  58. properties:
  59. apiKey:
  60. description: apiKeySecretRef references a Secret key holding an
  61. API key and the header name to carry it in.
  62. properties:
  63. headerName:
  64. description: headerName is the HTTP header used to carry the
  65. key.
  66. type: string
  67. secretRef:
  68. description: secretRef references the Secret key holding the
  69. API key value.
  70. properties:
  71. key:
  72. description: The key of the secret to select from. Must
  73. be a valid secret key.
  74. type: string
  75. name:
  76. default: ""
  77. description: |-
  78. Name of the referent.
  79. This field is effectively required, but due to backwards compatibility is
  80. allowed to be empty. Instances of this type with an empty value here are
  81. almost certainly wrong.
  82. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  83. type: string
  84. optional:
  85. description: Specify whether the Secret or its key must
  86. be defined
  87. type: boolean
  88. required:
  89. - key
  90. type: object
  91. x-kubernetes-map-type: atomic
  92. required:
  93. - secretRef
  94. type: object
  95. bearerToken:
  96. description: |-
  97. bearerTokenSecretRef references a Secret key holding a bearer token.
  98. Injected as Authorization: Bearer <token> on every request.
  99. properties:
  100. key:
  101. description: The key of the secret to select from. Must be
  102. a valid secret key.
  103. type: string
  104. name:
  105. default: ""
  106. description: |-
  107. Name of the referent.
  108. This field is effectively required, but due to backwards compatibility is
  109. allowed to be empty. Instances of this type with an empty value here are
  110. almost certainly wrong.
  111. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  112. type: string
  113. optional:
  114. description: Specify whether the Secret or its key must be
  115. defined
  116. type: boolean
  117. required:
  118. - key
  119. type: object
  120. x-kubernetes-map-type: atomic
  121. headers:
  122. description: |-
  123. headers are arbitrary HTTP headers sourced from Secrets.
  124. Use for providers requiring multiple credentials or non-standard auth schemes.
  125. items:
  126. description: |-
  127. HTTPHeaderSpec defines an HTTP header whose value is sourced from a Secret.
  128. Used wherever arbitrary headers must be sent with outbound requests without
  129. inlining credential values into the CR.
  130. properties:
  131. name:
  132. description: name is the HTTP header name (e.g. X-Api-Key,
  133. Authorization).
  134. type: string
  135. valueFrom:
  136. description: valueFrom is the source for the header value
  137. — typically a secretKeyRef.
  138. properties:
  139. configMapKeyRef:
  140. description: Selects a key of a ConfigMap.
  141. properties:
  142. key:
  143. description: The key to select.
  144. type: string
  145. name:
  146. default: ""
  147. description: |-
  148. Name of the referent.
  149. This field is effectively required, but due to backwards compatibility is
  150. allowed to be empty. Instances of this type with an empty value here are
  151. almost certainly wrong.
  152. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  153. type: string
  154. optional:
  155. description: Specify whether the ConfigMap or its
  156. key must be defined
  157. type: boolean
  158. required:
  159. - key
  160. type: object
  161. x-kubernetes-map-type: atomic
  162. fieldRef:
  163. description: |-
  164. Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`,
  165. spec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
  166. properties:
  167. apiVersion:
  168. description: Version of the schema the FieldPath
  169. is written in terms of, defaults to "v1".
  170. type: string
  171. fieldPath:
  172. description: Path of the field to select in the
  173. specified API version.
  174. type: string
  175. required:
  176. - fieldPath
  177. type: object
  178. x-kubernetes-map-type: atomic
  179. fileKeyRef:
  180. description: |-
  181. FileKeyRef selects a key of the env file.
  182. Requires the EnvFiles feature gate to be enabled.
  183. properties:
  184. key:
  185. description: |-
  186. The key within the env file. An invalid key will prevent the pod from starting.
  187. The keys defined within a source may consist of any printable ASCII characters except '='.
  188. During Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.
  189. type: string
  190. optional:
  191. default: false
  192. description: |-
  193. Specify whether the file or its key must be defined. If the file or key
  194. does not exist, then the env var is not published.
  195. If optional is set to true and the specified key does not exist,
  196. the environment variable will not be set in the Pod's containers.
  197. If optional is set to false and the specified key does not exist,
  198. an error will be returned during Pod creation.
  199. type: boolean
  200. path:
  201. description: |-
  202. The path within the volume from which to select the file.
  203. Must be relative and may not contain the '..' path or start with '..'.
  204. type: string
  205. volumeName:
  206. description: The name of the volume mount containing
  207. the env file.
  208. type: string
  209. required:
  210. - key
  211. - path
  212. - volumeName
  213. type: object
  214. x-kubernetes-map-type: atomic
  215. resourceFieldRef:
  216. description: |-
  217. Selects a resource of the container: only resources limits and requests
  218. (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.
  219. properties:
  220. containerName:
  221. description: 'Container name: required for volumes,
  222. optional for env vars'
  223. type: string
  224. divisor:
  225. anyOf:
  226. - type: integer
  227. - type: string
  228. description: Specifies the output format of the
  229. exposed resources, defaults to "1"
  230. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  231. x-kubernetes-int-or-string: true
  232. resource:
  233. description: 'Required: resource to select'
  234. type: string
  235. required:
  236. - resource
  237. type: object
  238. x-kubernetes-map-type: atomic
  239. secretKeyRef:
  240. description: Selects a key of a secret in the pod's
  241. namespace
  242. properties:
  243. key:
  244. description: The key of the secret to select from. Must
  245. be a valid secret key.
  246. type: string
  247. name:
  248. default: ""
  249. description: |-
  250. Name of the referent.
  251. This field is effectively required, but due to backwards compatibility is
  252. allowed to be empty. Instances of this type with an empty value here are
  253. almost certainly wrong.
  254. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  255. type: string
  256. optional:
  257. description: Specify whether the Secret or its key
  258. must be defined
  259. type: boolean
  260. required:
  261. - key
  262. type: object
  263. x-kubernetes-map-type: atomic
  264. type: object
  265. required:
  266. - name
  267. - valueFrom
  268. type: object
  269. type: array
  270. type: object
  271. stackRef:
  272. description: stackRef associates this tool with a stack.
  273. properties:
  274. name:
  275. default: ""
  276. description: |-
  277. Name of the referent.
  278. This field is effectively required, but due to backwards compatibility is
  279. allowed to be empty. Instances of this type with an empty value here are
  280. almost certainly wrong.
  281. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  282. type: string
  283. type: object
  284. x-kubernetes-map-type: atomic
  285. template:
  286. description: template holds the configuration overrides for the component.
  287. properties:
  288. metadata:
  289. description: metadata is a standard object metadata.
  290. type: object
  291. name:
  292. description: name selects a built-in preset.
  293. type: string
  294. spec:
  295. description: spec holds the pod-level configuration for the workload.
  296. properties:
  297. affinity:
  298. description: affinity provides fine-grained node and pod (anti-)affinity
  299. rules.
  300. properties:
  301. nodeAffinity:
  302. description: Describes node affinity scheduling rules
  303. for the pod.
  304. properties:
  305. preferredDuringSchedulingIgnoredDuringExecution:
  306. description: |-
  307. The scheduler will prefer to schedule pods to nodes that satisfy
  308. the affinity expressions specified by this field, but it may choose
  309. a node that violates one or more of the expressions. The node that is
  310. most preferred is the one with the greatest sum of weights, i.e.
  311. for each node that meets all of the scheduling requirements (resource
  312. request, requiredDuringScheduling affinity expressions, etc.),
  313. compute a sum by iterating through the elements of this field and adding
  314. "weight" to the sum if the node matches the corresponding matchExpressions; the
  315. node(s) with the highest sum are the most preferred.
  316. items:
  317. description: |-
  318. An empty preferred scheduling term matches all objects with implicit weight 0
  319. (i.e. it's a no-op). A null preferred scheduling term matches no objects (i.e. is also a no-op).
  320. properties:
  321. preference:
  322. description: A node selector term, associated
  323. with the corresponding weight.
  324. properties:
  325. matchExpressions:
  326. description: A list of node selector requirements
  327. by node's labels.
  328. items:
  329. description: |-
  330. A node selector requirement is a selector that contains values, a key, and an operator
  331. that relates the key and values.
  332. properties:
  333. key:
  334. description: The label key that the
  335. selector applies to.
  336. type: string
  337. operator:
  338. description: |-
  339. Represents a key's relationship to a set of values.
  340. Valid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.
  341. type: string
  342. values:
  343. description: |-
  344. An array of string values. If the operator is In or NotIn,
  345. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  346. the values array must be empty. If the operator is Gt or Lt, the values
  347. array must have a single element, which will be interpreted as an integer.
  348. This array is replaced during a strategic merge patch.
  349. items:
  350. type: string
  351. type: array
  352. x-kubernetes-list-type: atomic
  353. required:
  354. - key
  355. - operator
  356. type: object
  357. type: array
  358. x-kubernetes-list-type: atomic
  359. matchFields:
  360. description: A list of node selector requirements
  361. by node's fields.
  362. items:
  363. description: |-
  364. A node selector requirement is a selector that contains values, a key, and an operator
  365. that relates the key and values.
  366. properties:
  367. key:
  368. description: The label key that the
  369. selector applies to.
  370. type: string
  371. operator:
  372. description: |-
  373. Represents a key's relationship to a set of values.
  374. Valid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.
  375. type: string
  376. values:
  377. description: |-
  378. An array of string values. If the operator is In or NotIn,
  379. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  380. the values array must be empty. If the operator is Gt or Lt, the values
  381. array must have a single element, which will be interpreted as an integer.
  382. This array is replaced during a strategic merge patch.
  383. items:
  384. type: string
  385. type: array
  386. x-kubernetes-list-type: atomic
  387. required:
  388. - key
  389. - operator
  390. type: object
  391. type: array
  392. x-kubernetes-list-type: atomic
  393. type: object
  394. x-kubernetes-map-type: atomic
  395. weight:
  396. description: Weight associated with matching
  397. the corresponding nodeSelectorTerm, in the
  398. range 1-100.
  399. format: int32
  400. type: integer
  401. required:
  402. - preference
  403. - weight
  404. type: object
  405. type: array
  406. x-kubernetes-list-type: atomic
  407. requiredDuringSchedulingIgnoredDuringExecution:
  408. description: |-
  409. If the affinity requirements specified by this field are not met at
  410. scheduling time, the pod will not be scheduled onto the node.
  411. If the affinity requirements specified by this field cease to be met
  412. at some point during pod execution (e.g. due to an update), the system
  413. may or may not try to eventually evict the pod from its node.
  414. properties:
  415. nodeSelectorTerms:
  416. description: Required. A list of node selector
  417. terms. The terms are ORed.
  418. items:
  419. description: |-
  420. A null or empty node selector term matches no objects. The requirements of
  421. them are ANDed.
  422. The TopologySelectorTerm type implements a subset of the NodeSelectorTerm.
  423. properties:
  424. matchExpressions:
  425. description: A list of node selector requirements
  426. by node's labels.
  427. items:
  428. description: |-
  429. A node selector requirement is a selector that contains values, a key, and an operator
  430. that relates the key and values.
  431. properties:
  432. key:
  433. description: The label key that the
  434. selector applies to.
  435. type: string
  436. operator:
  437. description: |-
  438. Represents a key's relationship to a set of values.
  439. Valid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.
  440. type: string
  441. values:
  442. description: |-
  443. An array of string values. If the operator is In or NotIn,
  444. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  445. the values array must be empty. If the operator is Gt or Lt, the values
  446. array must have a single element, which will be interpreted as an integer.
  447. This array is replaced during a strategic merge patch.
  448. items:
  449. type: string
  450. type: array
  451. x-kubernetes-list-type: atomic
  452. required:
  453. - key
  454. - operator
  455. type: object
  456. type: array
  457. x-kubernetes-list-type: atomic
  458. matchFields:
  459. description: A list of node selector requirements
  460. by node's fields.
  461. items:
  462. description: |-
  463. A node selector requirement is a selector that contains values, a key, and an operator
  464. that relates the key and values.
  465. properties:
  466. key:
  467. description: The label key that the
  468. selector applies to.
  469. type: string
  470. operator:
  471. description: |-
  472. Represents a key's relationship to a set of values.
  473. Valid operators are In, NotIn, Exists, DoesNotExist. Gt, and Lt.
  474. type: string
  475. values:
  476. description: |-
  477. An array of string values. If the operator is In or NotIn,
  478. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  479. the values array must be empty. If the operator is Gt or Lt, the values
  480. array must have a single element, which will be interpreted as an integer.
  481. This array is replaced during a strategic merge patch.
  482. items:
  483. type: string
  484. type: array
  485. x-kubernetes-list-type: atomic
  486. required:
  487. - key
  488. - operator
  489. type: object
  490. type: array
  491. x-kubernetes-list-type: atomic
  492. type: object
  493. x-kubernetes-map-type: atomic
  494. type: array
  495. x-kubernetes-list-type: atomic
  496. required:
  497. - nodeSelectorTerms
  498. type: object
  499. x-kubernetes-map-type: atomic
  500. type: object
  501. podAffinity:
  502. description: Describes pod affinity scheduling rules (e.g.
  503. co-locate this pod in the same node, zone, etc. as some
  504. other pod(s)).
  505. properties:
  506. preferredDuringSchedulingIgnoredDuringExecution:
  507. description: |-
  508. The scheduler will prefer to schedule pods to nodes that satisfy
  509. the affinity expressions specified by this field, but it may choose
  510. a node that violates one or more of the expressions. The node that is
  511. most preferred is the one with the greatest sum of weights, i.e.
  512. for each node that meets all of the scheduling requirements (resource
  513. request, requiredDuringScheduling affinity expressions, etc.),
  514. compute a sum by iterating through the elements of this field and adding
  515. "weight" to the sum if the node has pods which matches the corresponding podAffinityTerm; the
  516. node(s) with the highest sum are the most preferred.
  517. items:
  518. description: The weights of all of the matched WeightedPodAffinityTerm
  519. fields are added per-node to find the most preferred
  520. node(s)
  521. properties:
  522. podAffinityTerm:
  523. description: Required. A pod affinity term,
  524. associated with the corresponding weight.
  525. properties:
  526. labelSelector:
  527. description: |-
  528. A label query over a set of resources, in this case pods.
  529. If it's null, this PodAffinityTerm matches with no Pods.
  530. properties:
  531. matchExpressions:
  532. description: matchExpressions is a list
  533. of label selector requirements. The
  534. requirements are ANDed.
  535. items:
  536. description: |-
  537. A label selector requirement is a selector that contains values, a key, and an operator that
  538. relates the key and values.
  539. properties:
  540. key:
  541. description: key is the label
  542. key that the selector applies
  543. to.
  544. type: string
  545. operator:
  546. description: |-
  547. operator represents a key's relationship to a set of values.
  548. Valid operators are In, NotIn, Exists and DoesNotExist.
  549. type: string
  550. values:
  551. description: |-
  552. values is an array of string values. If the operator is In or NotIn,
  553. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  554. the values array must be empty. This array is replaced during a strategic
  555. merge patch.
  556. items:
  557. type: string
  558. type: array
  559. x-kubernetes-list-type: atomic
  560. required:
  561. - key
  562. - operator
  563. type: object
  564. type: array
  565. x-kubernetes-list-type: atomic
  566. matchLabels:
  567. additionalProperties:
  568. type: string
  569. description: |-
  570. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  571. map is equivalent to an element of matchExpressions, whose key field is "key", the
  572. operator is "In", and the values array contains only "value". The requirements are ANDed.
  573. type: object
  574. type: object
  575. x-kubernetes-map-type: atomic
  576. matchLabelKeys:
  577. description: |-
  578. MatchLabelKeys is a set of pod label keys to select which pods will
  579. be taken into consideration. The keys are used to lookup values from the
  580. incoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`
  581. to select the group of existing pods which pods will be taken into consideration
  582. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  583. pod labels will be ignored. The default value is empty.
  584. The same key is forbidden to exist in both matchLabelKeys and labelSelector.
  585. Also, matchLabelKeys cannot be set when labelSelector isn't set.
  586. items:
  587. type: string
  588. type: array
  589. x-kubernetes-list-type: atomic
  590. mismatchLabelKeys:
  591. description: |-
  592. MismatchLabelKeys is a set of pod label keys to select which pods will
  593. be taken into consideration. The keys are used to lookup values from the
  594. incoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`
  595. to select the group of existing pods which pods will be taken into consideration
  596. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  597. pod labels will be ignored. The default value is empty.
  598. The same key is forbidden to exist in both mismatchLabelKeys and labelSelector.
  599. Also, mismatchLabelKeys cannot be set when labelSelector isn't set.
  600. items:
  601. type: string
  602. type: array
  603. x-kubernetes-list-type: atomic
  604. namespaceSelector:
  605. description: |-
  606. A label query over the set of namespaces that the term applies to.
  607. The term is applied to the union of the namespaces selected by this field
  608. and the ones listed in the namespaces field.
  609. null selector and null or empty namespaces list means "this pod's namespace".
  610. An empty selector ({}) matches all namespaces.
  611. properties:
  612. matchExpressions:
  613. description: matchExpressions is a list
  614. of label selector requirements. The
  615. requirements are ANDed.
  616. items:
  617. description: |-
  618. A label selector requirement is a selector that contains values, a key, and an operator that
  619. relates the key and values.
  620. properties:
  621. key:
  622. description: key is the label
  623. key that the selector applies
  624. to.
  625. type: string
  626. operator:
  627. description: |-
  628. operator represents a key's relationship to a set of values.
  629. Valid operators are In, NotIn, Exists and DoesNotExist.
  630. type: string
  631. values:
  632. description: |-
  633. values is an array of string values. If the operator is In or NotIn,
  634. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  635. the values array must be empty. This array is replaced during a strategic
  636. merge patch.
  637. items:
  638. type: string
  639. type: array
  640. x-kubernetes-list-type: atomic
  641. required:
  642. - key
  643. - operator
  644. type: object
  645. type: array
  646. x-kubernetes-list-type: atomic
  647. matchLabels:
  648. additionalProperties:
  649. type: string
  650. description: |-
  651. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  652. map is equivalent to an element of matchExpressions, whose key field is "key", the
  653. operator is "In", and the values array contains only "value". The requirements are ANDed.
  654. type: object
  655. type: object
  656. x-kubernetes-map-type: atomic
  657. namespaces:
  658. description: |-
  659. namespaces specifies a static list of namespace names that the term applies to.
  660. The term is applied to the union of the namespaces listed in this field
  661. and the ones selected by namespaceSelector.
  662. null or empty namespaces list and null namespaceSelector means "this pod's namespace".
  663. items:
  664. type: string
  665. type: array
  666. x-kubernetes-list-type: atomic
  667. topologyKey:
  668. description: |-
  669. This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching
  670. the labelSelector in the specified namespaces, where co-located is defined as running on a node
  671. whose value of the label with key topologyKey matches that of any node on which any of the
  672. selected pods is running.
  673. Empty topologyKey is not allowed.
  674. type: string
  675. required:
  676. - topologyKey
  677. type: object
  678. weight:
  679. description: |-
  680. weight associated with matching the corresponding podAffinityTerm,
  681. in the range 1-100.
  682. format: int32
  683. type: integer
  684. required:
  685. - podAffinityTerm
  686. - weight
  687. type: object
  688. type: array
  689. x-kubernetes-list-type: atomic
  690. requiredDuringSchedulingIgnoredDuringExecution:
  691. description: |-
  692. If the affinity requirements specified by this field are not met at
  693. scheduling time, the pod will not be scheduled onto the node.
  694. If the affinity requirements specified by this field cease to be met
  695. at some point during pod execution (e.g. due to a pod label update), the
  696. system may or may not try to eventually evict the pod from its node.
  697. When there are multiple elements, the lists of nodes corresponding to each
  698. podAffinityTerm are intersected, i.e. all terms must be satisfied.
  699. items:
  700. description: |-
  701. Defines a set of pods (namely those matching the labelSelector
  702. relative to the given namespace(s)) that this pod should be
  703. co-located (affinity) or not co-located (anti-affinity) with,
  704. where co-located is defined as running on a node whose value of
  705. the label with key <topologyKey> matches that of any node on which
  706. a pod of the set of pods is running
  707. properties:
  708. labelSelector:
  709. description: |-
  710. A label query over a set of resources, in this case pods.
  711. If it's null, this PodAffinityTerm matches with no Pods.
  712. properties:
  713. matchExpressions:
  714. description: matchExpressions is a list
  715. of label selector requirements. The requirements
  716. are ANDed.
  717. items:
  718. description: |-
  719. A label selector requirement is a selector that contains values, a key, and an operator that
  720. relates the key and values.
  721. properties:
  722. key:
  723. description: key is the label key
  724. that the selector applies to.
  725. type: string
  726. operator:
  727. description: |-
  728. operator represents a key's relationship to a set of values.
  729. Valid operators are In, NotIn, Exists and DoesNotExist.
  730. type: string
  731. values:
  732. description: |-
  733. values is an array of string values. If the operator is In or NotIn,
  734. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  735. the values array must be empty. This array is replaced during a strategic
  736. merge patch.
  737. items:
  738. type: string
  739. type: array
  740. x-kubernetes-list-type: atomic
  741. required:
  742. - key
  743. - operator
  744. type: object
  745. type: array
  746. x-kubernetes-list-type: atomic
  747. matchLabels:
  748. additionalProperties:
  749. type: string
  750. description: |-
  751. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  752. map is equivalent to an element of matchExpressions, whose key field is "key", the
  753. operator is "In", and the values array contains only "value". The requirements are ANDed.
  754. type: object
  755. type: object
  756. x-kubernetes-map-type: atomic
  757. matchLabelKeys:
  758. description: |-
  759. MatchLabelKeys is a set of pod label keys to select which pods will
  760. be taken into consideration. The keys are used to lookup values from the
  761. incoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`
  762. to select the group of existing pods which pods will be taken into consideration
  763. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  764. pod labels will be ignored. The default value is empty.
  765. The same key is forbidden to exist in both matchLabelKeys and labelSelector.
  766. Also, matchLabelKeys cannot be set when labelSelector isn't set.
  767. items:
  768. type: string
  769. type: array
  770. x-kubernetes-list-type: atomic
  771. mismatchLabelKeys:
  772. description: |-
  773. MismatchLabelKeys is a set of pod label keys to select which pods will
  774. be taken into consideration. The keys are used to lookup values from the
  775. incoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`
  776. to select the group of existing pods which pods will be taken into consideration
  777. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  778. pod labels will be ignored. The default value is empty.
  779. The same key is forbidden to exist in both mismatchLabelKeys and labelSelector.
  780. Also, mismatchLabelKeys cannot be set when labelSelector isn't set.
  781. items:
  782. type: string
  783. type: array
  784. x-kubernetes-list-type: atomic
  785. namespaceSelector:
  786. description: |-
  787. A label query over the set of namespaces that the term applies to.
  788. The term is applied to the union of the namespaces selected by this field
  789. and the ones listed in the namespaces field.
  790. null selector and null or empty namespaces list means "this pod's namespace".
  791. An empty selector ({}) matches all namespaces.
  792. properties:
  793. matchExpressions:
  794. description: matchExpressions is a list
  795. of label selector requirements. The requirements
  796. are ANDed.
  797. items:
  798. description: |-
  799. A label selector requirement is a selector that contains values, a key, and an operator that
  800. relates the key and values.
  801. properties:
  802. key:
  803. description: key is the label key
  804. that the selector applies to.
  805. type: string
  806. operator:
  807. description: |-
  808. operator represents a key's relationship to a set of values.
  809. Valid operators are In, NotIn, Exists and DoesNotExist.
  810. type: string
  811. values:
  812. description: |-
  813. values is an array of string values. If the operator is In or NotIn,
  814. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  815. the values array must be empty. This array is replaced during a strategic
  816. merge patch.
  817. items:
  818. type: string
  819. type: array
  820. x-kubernetes-list-type: atomic
  821. required:
  822. - key
  823. - operator
  824. type: object
  825. type: array
  826. x-kubernetes-list-type: atomic
  827. matchLabels:
  828. additionalProperties:
  829. type: string
  830. description: |-
  831. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  832. map is equivalent to an element of matchExpressions, whose key field is "key", the
  833. operator is "In", and the values array contains only "value". The requirements are ANDed.
  834. type: object
  835. type: object
  836. x-kubernetes-map-type: atomic
  837. namespaces:
  838. description: |-
  839. namespaces specifies a static list of namespace names that the term applies to.
  840. The term is applied to the union of the namespaces listed in this field
  841. and the ones selected by namespaceSelector.
  842. null or empty namespaces list and null namespaceSelector means "this pod's namespace".
  843. items:
  844. type: string
  845. type: array
  846. x-kubernetes-list-type: atomic
  847. topologyKey:
  848. description: |-
  849. This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching
  850. the labelSelector in the specified namespaces, where co-located is defined as running on a node
  851. whose value of the label with key topologyKey matches that of any node on which any of the
  852. selected pods is running.
  853. Empty topologyKey is not allowed.
  854. type: string
  855. required:
  856. - topologyKey
  857. type: object
  858. type: array
  859. x-kubernetes-list-type: atomic
  860. type: object
  861. podAntiAffinity:
  862. description: Describes pod anti-affinity scheduling rules
  863. (e.g. avoid putting this pod in the same node, zone,
  864. etc. as some other pod(s)).
  865. properties:
  866. preferredDuringSchedulingIgnoredDuringExecution:
  867. description: |-
  868. The scheduler will prefer to schedule pods to nodes that satisfy
  869. the anti-affinity expressions specified by this field, but it may choose
  870. a node that violates one or more of the expressions. The node that is
  871. most preferred is the one with the greatest sum of weights, i.e.
  872. for each node that meets all of the scheduling requirements (resource
  873. request, requiredDuringScheduling anti-affinity expressions, etc.),
  874. compute a sum by iterating through the elements of this field and subtracting
  875. "weight" from the sum if the node has pods which matches the corresponding podAffinityTerm; the
  876. node(s) with the highest sum are the most preferred.
  877. items:
  878. description: The weights of all of the matched WeightedPodAffinityTerm
  879. fields are added per-node to find the most preferred
  880. node(s)
  881. properties:
  882. podAffinityTerm:
  883. description: Required. A pod affinity term,
  884. associated with the corresponding weight.
  885. properties:
  886. labelSelector:
  887. description: |-
  888. A label query over a set of resources, in this case pods.
  889. If it's null, this PodAffinityTerm matches with no Pods.
  890. properties:
  891. matchExpressions:
  892. description: matchExpressions is a list
  893. of label selector requirements. The
  894. requirements are ANDed.
  895. items:
  896. description: |-
  897. A label selector requirement is a selector that contains values, a key, and an operator that
  898. relates the key and values.
  899. properties:
  900. key:
  901. description: key is the label
  902. key that the selector applies
  903. to.
  904. type: string
  905. operator:
  906. description: |-
  907. operator represents a key's relationship to a set of values.
  908. Valid operators are In, NotIn, Exists and DoesNotExist.
  909. type: string
  910. values:
  911. description: |-
  912. values is an array of string values. If the operator is In or NotIn,
  913. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  914. the values array must be empty. This array is replaced during a strategic
  915. merge patch.
  916. items:
  917. type: string
  918. type: array
  919. x-kubernetes-list-type: atomic
  920. required:
  921. - key
  922. - operator
  923. type: object
  924. type: array
  925. x-kubernetes-list-type: atomic
  926. matchLabels:
  927. additionalProperties:
  928. type: string
  929. description: |-
  930. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  931. map is equivalent to an element of matchExpressions, whose key field is "key", the
  932. operator is "In", and the values array contains only "value". The requirements are ANDed.
  933. type: object
  934. type: object
  935. x-kubernetes-map-type: atomic
  936. matchLabelKeys:
  937. description: |-
  938. MatchLabelKeys is a set of pod label keys to select which pods will
  939. be taken into consideration. The keys are used to lookup values from the
  940. incoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`
  941. to select the group of existing pods which pods will be taken into consideration
  942. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  943. pod labels will be ignored. The default value is empty.
  944. The same key is forbidden to exist in both matchLabelKeys and labelSelector.
  945. Also, matchLabelKeys cannot be set when labelSelector isn't set.
  946. items:
  947. type: string
  948. type: array
  949. x-kubernetes-list-type: atomic
  950. mismatchLabelKeys:
  951. description: |-
  952. MismatchLabelKeys is a set of pod label keys to select which pods will
  953. be taken into consideration. The keys are used to lookup values from the
  954. incoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`
  955. to select the group of existing pods which pods will be taken into consideration
  956. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  957. pod labels will be ignored. The default value is empty.
  958. The same key is forbidden to exist in both mismatchLabelKeys and labelSelector.
  959. Also, mismatchLabelKeys cannot be set when labelSelector isn't set.
  960. items:
  961. type: string
  962. type: array
  963. x-kubernetes-list-type: atomic
  964. namespaceSelector:
  965. description: |-
  966. A label query over the set of namespaces that the term applies to.
  967. The term is applied to the union of the namespaces selected by this field
  968. and the ones listed in the namespaces field.
  969. null selector and null or empty namespaces list means "this pod's namespace".
  970. An empty selector ({}) matches all namespaces.
  971. properties:
  972. matchExpressions:
  973. description: matchExpressions is a list
  974. of label selector requirements. The
  975. requirements are ANDed.
  976. items:
  977. description: |-
  978. A label selector requirement is a selector that contains values, a key, and an operator that
  979. relates the key and values.
  980. properties:
  981. key:
  982. description: key is the label
  983. key that the selector applies
  984. to.
  985. type: string
  986. operator:
  987. description: |-
  988. operator represents a key's relationship to a set of values.
  989. Valid operators are In, NotIn, Exists and DoesNotExist.
  990. type: string
  991. values:
  992. description: |-
  993. values is an array of string values. If the operator is In or NotIn,
  994. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  995. the values array must be empty. This array is replaced during a strategic
  996. merge patch.
  997. items:
  998. type: string
  999. type: array
  1000. x-kubernetes-list-type: atomic
  1001. required:
  1002. - key
  1003. - operator
  1004. type: object
  1005. type: array
  1006. x-kubernetes-list-type: atomic
  1007. matchLabels:
  1008. additionalProperties:
  1009. type: string
  1010. description: |-
  1011. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1012. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1013. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1014. type: object
  1015. type: object
  1016. x-kubernetes-map-type: atomic
  1017. namespaces:
  1018. description: |-
  1019. namespaces specifies a static list of namespace names that the term applies to.
  1020. The term is applied to the union of the namespaces listed in this field
  1021. and the ones selected by namespaceSelector.
  1022. null or empty namespaces list and null namespaceSelector means "this pod's namespace".
  1023. items:
  1024. type: string
  1025. type: array
  1026. x-kubernetes-list-type: atomic
  1027. topologyKey:
  1028. description: |-
  1029. This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching
  1030. the labelSelector in the specified namespaces, where co-located is defined as running on a node
  1031. whose value of the label with key topologyKey matches that of any node on which any of the
  1032. selected pods is running.
  1033. Empty topologyKey is not allowed.
  1034. type: string
  1035. required:
  1036. - topologyKey
  1037. type: object
  1038. weight:
  1039. description: |-
  1040. weight associated with matching the corresponding podAffinityTerm,
  1041. in the range 1-100.
  1042. format: int32
  1043. type: integer
  1044. required:
  1045. - podAffinityTerm
  1046. - weight
  1047. type: object
  1048. type: array
  1049. x-kubernetes-list-type: atomic
  1050. requiredDuringSchedulingIgnoredDuringExecution:
  1051. description: |-
  1052. If the anti-affinity requirements specified by this field are not met at
  1053. scheduling time, the pod will not be scheduled onto the node.
  1054. If the anti-affinity requirements specified by this field cease to be met
  1055. at some point during pod execution (e.g. due to a pod label update), the
  1056. system may or may not try to eventually evict the pod from its node.
  1057. When there are multiple elements, the lists of nodes corresponding to each
  1058. podAffinityTerm are intersected, i.e. all terms must be satisfied.
  1059. items:
  1060. description: |-
  1061. Defines a set of pods (namely those matching the labelSelector
  1062. relative to the given namespace(s)) that this pod should be
  1063. co-located (affinity) or not co-located (anti-affinity) with,
  1064. where co-located is defined as running on a node whose value of
  1065. the label with key <topologyKey> matches that of any node on which
  1066. a pod of the set of pods is running
  1067. properties:
  1068. labelSelector:
  1069. description: |-
  1070. A label query over a set of resources, in this case pods.
  1071. If it's null, this PodAffinityTerm matches with no Pods.
  1072. properties:
  1073. matchExpressions:
  1074. description: matchExpressions is a list
  1075. of label selector requirements. The requirements
  1076. are ANDed.
  1077. items:
  1078. description: |-
  1079. A label selector requirement is a selector that contains values, a key, and an operator that
  1080. relates the key and values.
  1081. properties:
  1082. key:
  1083. description: key is the label key
  1084. that the selector applies to.
  1085. type: string
  1086. operator:
  1087. description: |-
  1088. operator represents a key's relationship to a set of values.
  1089. Valid operators are In, NotIn, Exists and DoesNotExist.
  1090. type: string
  1091. values:
  1092. description: |-
  1093. values is an array of string values. If the operator is In or NotIn,
  1094. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1095. the values array must be empty. This array is replaced during a strategic
  1096. merge patch.
  1097. items:
  1098. type: string
  1099. type: array
  1100. x-kubernetes-list-type: atomic
  1101. required:
  1102. - key
  1103. - operator
  1104. type: object
  1105. type: array
  1106. x-kubernetes-list-type: atomic
  1107. matchLabels:
  1108. additionalProperties:
  1109. type: string
  1110. description: |-
  1111. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1112. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1113. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1114. type: object
  1115. type: object
  1116. x-kubernetes-map-type: atomic
  1117. matchLabelKeys:
  1118. description: |-
  1119. MatchLabelKeys is a set of pod label keys to select which pods will
  1120. be taken into consideration. The keys are used to lookup values from the
  1121. incoming pod labels, those key-value labels are merged with `labelSelector` as `key in (value)`
  1122. to select the group of existing pods which pods will be taken into consideration
  1123. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  1124. pod labels will be ignored. The default value is empty.
  1125. The same key is forbidden to exist in both matchLabelKeys and labelSelector.
  1126. Also, matchLabelKeys cannot be set when labelSelector isn't set.
  1127. items:
  1128. type: string
  1129. type: array
  1130. x-kubernetes-list-type: atomic
  1131. mismatchLabelKeys:
  1132. description: |-
  1133. MismatchLabelKeys is a set of pod label keys to select which pods will
  1134. be taken into consideration. The keys are used to lookup values from the
  1135. incoming pod labels, those key-value labels are merged with `labelSelector` as `key notin (value)`
  1136. to select the group of existing pods which pods will be taken into consideration
  1137. for the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming
  1138. pod labels will be ignored. The default value is empty.
  1139. The same key is forbidden to exist in both mismatchLabelKeys and labelSelector.
  1140. Also, mismatchLabelKeys cannot be set when labelSelector isn't set.
  1141. items:
  1142. type: string
  1143. type: array
  1144. x-kubernetes-list-type: atomic
  1145. namespaceSelector:
  1146. description: |-
  1147. A label query over the set of namespaces that the term applies to.
  1148. The term is applied to the union of the namespaces selected by this field
  1149. and the ones listed in the namespaces field.
  1150. null selector and null or empty namespaces list means "this pod's namespace".
  1151. An empty selector ({}) matches all namespaces.
  1152. properties:
  1153. matchExpressions:
  1154. description: matchExpressions is a list
  1155. of label selector requirements. The requirements
  1156. are ANDed.
  1157. items:
  1158. description: |-
  1159. A label selector requirement is a selector that contains values, a key, and an operator that
  1160. relates the key and values.
  1161. properties:
  1162. key:
  1163. description: key is the label key
  1164. that the selector applies to.
  1165. type: string
  1166. operator:
  1167. description: |-
  1168. operator represents a key's relationship to a set of values.
  1169. Valid operators are In, NotIn, Exists and DoesNotExist.
  1170. type: string
  1171. values:
  1172. description: |-
  1173. values is an array of string values. If the operator is In or NotIn,
  1174. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1175. the values array must be empty. This array is replaced during a strategic
  1176. merge patch.
  1177. items:
  1178. type: string
  1179. type: array
  1180. x-kubernetes-list-type: atomic
  1181. required:
  1182. - key
  1183. - operator
  1184. type: object
  1185. type: array
  1186. x-kubernetes-list-type: atomic
  1187. matchLabels:
  1188. additionalProperties:
  1189. type: string
  1190. description: |-
  1191. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1192. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1193. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1194. type: object
  1195. type: object
  1196. x-kubernetes-map-type: atomic
  1197. namespaces:
  1198. description: |-
  1199. namespaces specifies a static list of namespace names that the term applies to.
  1200. The term is applied to the union of the namespaces listed in this field
  1201. and the ones selected by namespaceSelector.
  1202. null or empty namespaces list and null namespaceSelector means "this pod's namespace".
  1203. items:
  1204. type: string
  1205. type: array
  1206. x-kubernetes-list-type: atomic
  1207. topologyKey:
  1208. description: |-
  1209. This pod should be co-located (affinity) or not co-located (anti-affinity) with the pods matching
  1210. the labelSelector in the specified namespaces, where co-located is defined as running on a node
  1211. whose value of the label with key topologyKey matches that of any node on which any of the
  1212. selected pods is running.
  1213. Empty topologyKey is not allowed.
  1214. type: string
  1215. required:
  1216. - topologyKey
  1217. type: object
  1218. type: array
  1219. x-kubernetes-list-type: atomic
  1220. type: object
  1221. type: object
  1222. nodeSelector:
  1223. additionalProperties:
  1224. type: string
  1225. description: nodeSelector pins pods to nodes that match all
  1226. the specified labels.
  1227. type: object
  1228. resources:
  1229. description: resources sets per-container resource requests
  1230. and limits.
  1231. properties:
  1232. claims:
  1233. description: |-
  1234. Claims lists the names of resources, defined in spec.resourceClaims,
  1235. that are used by this container.
  1236. This field depends on the
  1237. DynamicResourceAllocation feature gate.
  1238. This field is immutable. It can only be set for containers.
  1239. items:
  1240. description: ResourceClaim references one entry in PodSpec.ResourceClaims.
  1241. properties:
  1242. name:
  1243. description: |-
  1244. Name must match the name of one entry in pod.spec.resourceClaims of
  1245. the Pod where this field is used. It makes that resource available
  1246. inside a container.
  1247. type: string
  1248. request:
  1249. description: |-
  1250. Request is the name chosen for a request in the referenced claim.
  1251. If empty, everything from the claim is made available, otherwise
  1252. only the result of this request.
  1253. type: string
  1254. required:
  1255. - name
  1256. type: object
  1257. type: array
  1258. x-kubernetes-list-map-keys:
  1259. - name
  1260. x-kubernetes-list-type: map
  1261. limits:
  1262. additionalProperties:
  1263. anyOf:
  1264. - type: integer
  1265. - type: string
  1266. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  1267. x-kubernetes-int-or-string: true
  1268. description: |-
  1269. Limits describes the maximum amount of compute resources allowed.
  1270. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
  1271. type: object
  1272. requests:
  1273. additionalProperties:
  1274. anyOf:
  1275. - type: integer
  1276. - type: string
  1277. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  1278. x-kubernetes-int-or-string: true
  1279. description: |-
  1280. Requests describes the minimum amount of compute resources required.
  1281. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified,
  1282. otherwise to an implementation-defined value. Requests cannot exceed Limits.
  1283. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
  1284. type: object
  1285. type: object
  1286. runtime:
  1287. description: runtime describes the container runtime to use
  1288. for the workload.
  1289. properties:
  1290. args:
  1291. description: args specifies or overrides the preset's
  1292. container command.
  1293. items:
  1294. type: string
  1295. type: array
  1296. command:
  1297. description: command specifies or overrides the preset's
  1298. container entrypoint.
  1299. items:
  1300. type: string
  1301. type: array
  1302. conditionalArgs:
  1303. description: conditionalArgs are appended to the preset
  1304. command conditionally.
  1305. items:
  1306. properties:
  1307. args:
  1308. description: args are appended to the preset args.
  1309. items:
  1310. type: string
  1311. type: array
  1312. when:
  1313. description: when the value is not empty after variable
  1314. substitution, the args are appended to the preset
  1315. args.
  1316. type: string
  1317. required:
  1318. - args
  1319. - when
  1320. type: object
  1321. type: array
  1322. env:
  1323. description: env holds environment variables injected
  1324. into the container.
  1325. items:
  1326. description: EnvVar represents an environment variable
  1327. present in a Container.
  1328. properties:
  1329. name:
  1330. description: |-
  1331. Name of the environment variable.
  1332. May consist of any printable ASCII characters except '='.
  1333. type: string
  1334. value:
  1335. description: |-
  1336. Variable references $(VAR_NAME) are expanded
  1337. using the previously defined environment variables in the container and
  1338. any service environment variables. If a variable cannot be resolved,
  1339. the reference in the input string will be unchanged. Double $$ are reduced
  1340. to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.
  1341. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)".
  1342. Escaped references will never be expanded, regardless of whether the variable
  1343. exists or not.
  1344. Defaults to "".
  1345. type: string
  1346. valueFrom:
  1347. description: Source for the environment variable's
  1348. value. Cannot be used if value is not empty.
  1349. properties:
  1350. configMapKeyRef:
  1351. description: Selects a key of a ConfigMap.
  1352. properties:
  1353. key:
  1354. description: The key to select.
  1355. type: string
  1356. name:
  1357. default: ""
  1358. description: |-
  1359. Name of the referent.
  1360. This field is effectively required, but due to backwards compatibility is
  1361. allowed to be empty. Instances of this type with an empty value here are
  1362. almost certainly wrong.
  1363. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  1364. type: string
  1365. optional:
  1366. description: Specify whether the ConfigMap
  1367. or its key must be defined
  1368. type: boolean
  1369. required:
  1370. - key
  1371. type: object
  1372. x-kubernetes-map-type: atomic
  1373. fieldRef:
  1374. description: |-
  1375. Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`,
  1376. spec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
  1377. properties:
  1378. apiVersion:
  1379. description: Version of the schema the FieldPath
  1380. is written in terms of, defaults to "v1".
  1381. type: string
  1382. fieldPath:
  1383. description: Path of the field to select
  1384. in the specified API version.
  1385. type: string
  1386. required:
  1387. - fieldPath
  1388. type: object
  1389. x-kubernetes-map-type: atomic
  1390. fileKeyRef:
  1391. description: |-
  1392. FileKeyRef selects a key of the env file.
  1393. Requires the EnvFiles feature gate to be enabled.
  1394. properties:
  1395. key:
  1396. description: |-
  1397. The key within the env file. An invalid key will prevent the pod from starting.
  1398. The keys defined within a source may consist of any printable ASCII characters except '='.
  1399. During Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.
  1400. type: string
  1401. optional:
  1402. default: false
  1403. description: |-
  1404. Specify whether the file or its key must be defined. If the file or key
  1405. does not exist, then the env var is not published.
  1406. If optional is set to true and the specified key does not exist,
  1407. the environment variable will not be set in the Pod's containers.
  1408. If optional is set to false and the specified key does not exist,
  1409. an error will be returned during Pod creation.
  1410. type: boolean
  1411. path:
  1412. description: |-
  1413. The path within the volume from which to select the file.
  1414. Must be relative and may not contain the '..' path or start with '..'.
  1415. type: string
  1416. volumeName:
  1417. description: The name of the volume mount
  1418. containing the env file.
  1419. type: string
  1420. required:
  1421. - key
  1422. - path
  1423. - volumeName
  1424. type: object
  1425. x-kubernetes-map-type: atomic
  1426. resourceFieldRef:
  1427. description: |-
  1428. Selects a resource of the container: only resources limits and requests
  1429. (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.
  1430. properties:
  1431. containerName:
  1432. description: 'Container name: required for
  1433. volumes, optional for env vars'
  1434. type: string
  1435. divisor:
  1436. anyOf:
  1437. - type: integer
  1438. - type: string
  1439. description: Specifies the output format
  1440. of the exposed resources, defaults to
  1441. "1"
  1442. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  1443. x-kubernetes-int-or-string: true
  1444. resource:
  1445. description: 'Required: resource to select'
  1446. type: string
  1447. required:
  1448. - resource
  1449. type: object
  1450. x-kubernetes-map-type: atomic
  1451. secretKeyRef:
  1452. description: Selects a key of a secret in the
  1453. pod's namespace
  1454. properties:
  1455. key:
  1456. description: The key of the secret to select
  1457. from. Must be a valid secret key.
  1458. type: string
  1459. name:
  1460. default: ""
  1461. description: |-
  1462. Name of the referent.
  1463. This field is effectively required, but due to backwards compatibility is
  1464. allowed to be empty. Instances of this type with an empty value here are
  1465. almost certainly wrong.
  1466. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  1467. type: string
  1468. optional:
  1469. description: Specify whether the Secret
  1470. or its key must be defined
  1471. type: boolean
  1472. required:
  1473. - key
  1474. type: object
  1475. x-kubernetes-map-type: atomic
  1476. type: object
  1477. required:
  1478. - name
  1479. type: object
  1480. type: array
  1481. envFrom:
  1482. description: envFrom references ConfigMaps or Secrets
  1483. whose key-value pairs are injected as environment variables.
  1484. items:
  1485. description: EnvFromSource represents the source of
  1486. a set of ConfigMaps or Secrets
  1487. properties:
  1488. configMapRef:
  1489. description: The ConfigMap to select from
  1490. properties:
  1491. name:
  1492. default: ""
  1493. description: |-
  1494. Name of the referent.
  1495. This field is effectively required, but due to backwards compatibility is
  1496. allowed to be empty. Instances of this type with an empty value here are
  1497. almost certainly wrong.
  1498. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  1499. type: string
  1500. optional:
  1501. description: Specify whether the ConfigMap must
  1502. be defined
  1503. type: boolean
  1504. type: object
  1505. x-kubernetes-map-type: atomic
  1506. prefix:
  1507. description: |-
  1508. Optional text to prepend to the name of each environment variable.
  1509. May consist of any printable ASCII characters except '='.
  1510. type: string
  1511. secretRef:
  1512. description: The Secret to select from
  1513. properties:
  1514. name:
  1515. default: ""
  1516. description: |-
  1517. Name of the referent.
  1518. This field is effectively required, but due to backwards compatibility is
  1519. allowed to be empty. Instances of this type with an empty value here are
  1520. almost certainly wrong.
  1521. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  1522. type: string
  1523. optional:
  1524. description: Specify whether the Secret must
  1525. be defined
  1526. type: boolean
  1527. type: object
  1528. x-kubernetes-map-type: atomic
  1529. type: object
  1530. type: array
  1531. extraArgs:
  1532. description: extraArgs are appended to the preset command.
  1533. items:
  1534. type: string
  1535. type: array
  1536. image:
  1537. description: |-
  1538. image specifies or overrides the preset's container image, e.g. to pin a specific tag
  1539. or pull from a private registry mirror.
  1540. type: string
  1541. name:
  1542. description: name selects a built-in runtime preset.
  1543. type: string
  1544. port:
  1545. description: port specifies or overrides the container
  1546. port the runtime listens on.
  1547. format: int32
  1548. type: integer
  1549. volumeMounts:
  1550. description: volumeMounts defines where pod volumes are
  1551. mounted inside the container.
  1552. items:
  1553. description: VolumeMount describes a mounting of a Volume
  1554. within a container.
  1555. properties:
  1556. mountPath:
  1557. description: |-
  1558. Path within the container at which the volume should be mounted. Must
  1559. not contain ':'.
  1560. type: string
  1561. mountPropagation:
  1562. description: |-
  1563. mountPropagation determines how mounts are propagated from the host
  1564. to container and the other way around.
  1565. When not set, MountPropagationNone is used.
  1566. This field is beta in 1.10.
  1567. When RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation must be None or unspecified
  1568. (which defaults to None).
  1569. type: string
  1570. name:
  1571. description: This must match the Name of a Volume.
  1572. type: string
  1573. readOnly:
  1574. description: |-
  1575. Mounted read-only if true, read-write otherwise (false or unspecified).
  1576. Defaults to false.
  1577. type: boolean
  1578. recursiveReadOnly:
  1579. description: |-
  1580. RecursiveReadOnly specifies whether read-only mounts should be handled
  1581. recursively.
  1582. If ReadOnly is false, this field has no meaning and must be unspecified.
  1583. If ReadOnly is true, and this field is set to Disabled, the mount is not made
  1584. recursively read-only. If this field is set to IfPossible, the mount is made
  1585. recursively read-only, if it is supported by the container runtime. If this
  1586. field is set to Enabled, the mount is made recursively read-only if it is
  1587. supported by the container runtime, otherwise the pod will not be started and
  1588. an error will be generated to indicate the reason.
  1589. If this field is set to IfPossible or Enabled, MountPropagation must be set to
  1590. None (or be unspecified, which defaults to None).
  1591. If this field is not specified, it is treated as an equivalent of Disabled.
  1592. type: string
  1593. subPath:
  1594. description: |-
  1595. Path within the volume from which the container's volume should be mounted.
  1596. Defaults to "" (volume's root).
  1597. type: string
  1598. subPathExpr:
  1599. description: |-
  1600. Expanded path within the volume from which the container's volume should be mounted.
  1601. Behaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment.
  1602. Defaults to "" (volume's root).
  1603. SubPathExpr and SubPath are mutually exclusive.
  1604. type: string
  1605. required:
  1606. - mountPath
  1607. - name
  1608. type: object
  1609. type: array
  1610. type: object
  1611. securityContext:
  1612. description: |-
  1613. securityContext sets pod-level security attributes such as runAsUser,
  1614. runAsGroup, fsGroup, and sysctls.
  1615. properties:
  1616. appArmorProfile:
  1617. description: |-
  1618. appArmorProfile is the AppArmor options to use by the containers in this pod.
  1619. Note that this field cannot be set when spec.os.name is windows.
  1620. properties:
  1621. localhostProfile:
  1622. description: |-
  1623. localhostProfile indicates a profile loaded on the node that should be used.
  1624. The profile must be preconfigured on the node to work.
  1625. Must match the loaded name of the profile.
  1626. Must be set if and only if type is "Localhost".
  1627. type: string
  1628. type:
  1629. description: |-
  1630. type indicates which kind of AppArmor profile will be applied.
  1631. Valid options are:
  1632. Localhost - a profile pre-loaded on the node.
  1633. RuntimeDefault - the container runtime's default profile.
  1634. Unconfined - no AppArmor enforcement.
  1635. type: string
  1636. required:
  1637. - type
  1638. type: object
  1639. fsGroup:
  1640. description: |-
  1641. A special supplemental group that applies to all containers in a pod.
  1642. Some volume types allow the Kubelet to change the ownership of that volume
  1643. to be owned by the pod:
  1644. 1. The owning GID will be the FSGroup
  1645. 2. The setgid bit is set (new files created in the volume will be owned by FSGroup)
  1646. 3. The permission bits are OR'd with rw-rw----
  1647. If unset, the Kubelet will not modify the ownership and permissions of any volume.
  1648. Note that this field cannot be set when spec.os.name is windows.
  1649. format: int64
  1650. type: integer
  1651. fsGroupChangePolicy:
  1652. description: |-
  1653. fsGroupChangePolicy defines behavior of changing ownership and permission of the volume
  1654. before being exposed inside Pod. This field will only apply to
  1655. volume types which support fsGroup based ownership(and permissions).
  1656. It will have no effect on ephemeral volume types such as: secret, configmaps
  1657. and emptydir.
  1658. Valid values are "OnRootMismatch" and "Always". If not specified, "Always" is used.
  1659. Note that this field cannot be set when spec.os.name is windows.
  1660. type: string
  1661. runAsGroup:
  1662. description: |-
  1663. The GID to run the entrypoint of the container process.
  1664. Uses runtime default if unset.
  1665. May also be set in SecurityContext. If set in both SecurityContext and
  1666. PodSecurityContext, the value specified in SecurityContext takes precedence
  1667. for that container.
  1668. Note that this field cannot be set when spec.os.name is windows.
  1669. format: int64
  1670. type: integer
  1671. runAsNonRoot:
  1672. description: |-
  1673. Indicates that the container must run as a non-root user.
  1674. If true, the Kubelet will validate the image at runtime to ensure that it
  1675. does not run as UID 0 (root) and fail to start the container if it does.
  1676. If unset or false, no such validation will be performed.
  1677. May also be set in SecurityContext. If set in both SecurityContext and
  1678. PodSecurityContext, the value specified in SecurityContext takes precedence.
  1679. type: boolean
  1680. runAsUser:
  1681. description: |-
  1682. The UID to run the entrypoint of the container process.
  1683. Defaults to user specified in image metadata if unspecified.
  1684. May also be set in SecurityContext. If set in both SecurityContext and
  1685. PodSecurityContext, the value specified in SecurityContext takes precedence
  1686. for that container.
  1687. Note that this field cannot be set when spec.os.name is windows.
  1688. format: int64
  1689. type: integer
  1690. seLinuxChangePolicy:
  1691. description: |-
  1692. seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod.
  1693. It has no effect on nodes that do not support SELinux or to volumes does not support SELinux.
  1694. Valid values are "MountOption" and "Recursive".
  1695. "Recursive" means relabeling of all files on all Pod volumes by the container runtime.
  1696. This may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node.
  1697. "MountOption" mounts all eligible Pod volumes with `-o context` mount option.
  1698. This requires all Pods that share the same volume to use the same SELinux label.
  1699. It is not possible to share the same volume among privileged and unprivileged Pods.
  1700. Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes
  1701. whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their
  1702. CSIDriver instance. Other volumes are always re-labelled recursively.
  1703. "MountOption" value is allowed only when SELinuxMount feature gate is enabled.
  1704. If not specified and SELinuxMount feature gate is enabled, "MountOption" is used.
  1705. If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes
  1706. and "Recursive" for all other volumes.
  1707. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers.
  1708. All Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state.
  1709. Note that this field cannot be set when spec.os.name is windows.
  1710. type: string
  1711. seLinuxOptions:
  1712. description: |-
  1713. The SELinux context to be applied to all containers.
  1714. If unspecified, the container runtime will allocate a random SELinux context for each
  1715. container. May also be set in SecurityContext. If set in
  1716. both SecurityContext and PodSecurityContext, the value specified in SecurityContext
  1717. takes precedence for that container.
  1718. Note that this field cannot be set when spec.os.name is windows.
  1719. properties:
  1720. level:
  1721. description: Level is SELinux level label that applies
  1722. to the container.
  1723. type: string
  1724. role:
  1725. description: Role is a SELinux role label that applies
  1726. to the container.
  1727. type: string
  1728. type:
  1729. description: Type is a SELinux type label that applies
  1730. to the container.
  1731. type: string
  1732. user:
  1733. description: User is a SELinux user label that applies
  1734. to the container.
  1735. type: string
  1736. type: object
  1737. seccompProfile:
  1738. description: |-
  1739. The seccomp options to use by the containers in this pod.
  1740. Note that this field cannot be set when spec.os.name is windows.
  1741. properties:
  1742. localhostProfile:
  1743. description: |-
  1744. localhostProfile indicates a profile defined in a file on the node should be used.
  1745. The profile must be preconfigured on the node to work.
  1746. Must be a descending path, relative to the kubelet's configured seccomp profile location.
  1747. Must be set if type is "Localhost". Must NOT be set for any other type.
  1748. type: string
  1749. type:
  1750. description: |-
  1751. type indicates which kind of seccomp profile will be applied.
  1752. Valid options are:
  1753. Localhost - a profile defined in a file on the node should be used.
  1754. RuntimeDefault - the container runtime default profile should be used.
  1755. Unconfined - no profile should be applied.
  1756. type: string
  1757. required:
  1758. - type
  1759. type: object
  1760. supplementalGroups:
  1761. description: |-
  1762. A list of groups applied to the first process run in each container, in
  1763. addition to the container's primary GID and fsGroup (if specified). If
  1764. the SupplementalGroupsPolicy feature is enabled, the
  1765. supplementalGroupsPolicy field determines whether these are in addition
  1766. to or instead of any group memberships defined in the container image.
  1767. If unspecified, no additional groups are added, though group memberships
  1768. defined in the container image may still be used, depending on the
  1769. supplementalGroupsPolicy field.
  1770. Note that this field cannot be set when spec.os.name is windows.
  1771. items:
  1772. format: int64
  1773. type: integer
  1774. type: array
  1775. x-kubernetes-list-type: atomic
  1776. supplementalGroupsPolicy:
  1777. description: |-
  1778. Defines how supplemental groups of the first container processes are calculated.
  1779. Valid values are "Merge" and "Strict". If not specified, "Merge" is used.
  1780. (Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled
  1781. and the container runtime must implement support for this feature.
  1782. Note that this field cannot be set when spec.os.name is windows.
  1783. type: string
  1784. sysctls:
  1785. description: |-
  1786. Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported
  1787. sysctls (by the container runtime) might fail to launch.
  1788. Note that this field cannot be set when spec.os.name is windows.
  1789. items:
  1790. description: Sysctl defines a kernel parameter to be
  1791. set
  1792. properties:
  1793. name:
  1794. description: Name of a property to set
  1795. type: string
  1796. value:
  1797. description: Value of a property to set
  1798. type: string
  1799. required:
  1800. - name
  1801. - value
  1802. type: object
  1803. type: array
  1804. x-kubernetes-list-type: atomic
  1805. windowsOptions:
  1806. description: |-
  1807. The Windows specific settings applied to all containers.
  1808. If unspecified, the options within a container's SecurityContext will be used.
  1809. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.
  1810. Note that this field cannot be set when spec.os.name is linux.
  1811. properties:
  1812. gmsaCredentialSpec:
  1813. description: |-
  1814. GMSACredentialSpec is where the GMSA admission webhook
  1815. (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the
  1816. GMSA credential spec named by the GMSACredentialSpecName field.
  1817. type: string
  1818. gmsaCredentialSpecName:
  1819. description: GMSACredentialSpecName is the name of
  1820. the GMSA credential spec to use.
  1821. type: string
  1822. hostProcess:
  1823. description: |-
  1824. HostProcess determines if a container should be run as a 'Host Process' container.
  1825. All of a Pod's containers must have the same effective HostProcess value
  1826. (it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).
  1827. In addition, if HostProcess is true then HostNetwork must also be set to true.
  1828. type: boolean
  1829. runAsUserName:
  1830. description: |-
  1831. The UserName in Windows to run the entrypoint of the container process.
  1832. Defaults to the user specified in image metadata if unspecified.
  1833. May also be set in PodSecurityContext. If set in both SecurityContext and
  1834. PodSecurityContext, the value specified in SecurityContext takes precedence.
  1835. type: string
  1836. type: object
  1837. type: object
  1838. tolerations:
  1839. description: tolerations allow pods to be scheduled onto nodes
  1840. with matching taints.
  1841. items:
  1842. description: |-
  1843. The pod this Toleration is attached to tolerates any taint that matches
  1844. the triple <key,value,effect> using the matching operator <operator>.
  1845. properties:
  1846. effect:
  1847. description: |-
  1848. Effect indicates the taint effect to match. Empty means match all taint effects.
  1849. When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.
  1850. type: string
  1851. key:
  1852. description: |-
  1853. Key is the taint key that the toleration applies to. Empty means match all taint keys.
  1854. If the key is empty, operator must be Exists; this combination means to match all values and all keys.
  1855. type: string
  1856. operator:
  1857. description: |-
  1858. Operator represents a key's relationship to the value.
  1859. Valid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.
  1860. Exists is equivalent to wildcard for value, so that a pod can
  1861. tolerate all taints of a particular category.
  1862. Lt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).
  1863. type: string
  1864. tolerationSeconds:
  1865. description: |-
  1866. TolerationSeconds represents the period of time the toleration (which must be
  1867. of effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,
  1868. it is not set, which means tolerate the taint forever (do not evict). Zero and
  1869. negative values will be treated as 0 (evict immediately) by the system.
  1870. format: int64
  1871. type: integer
  1872. value:
  1873. description: |-
  1874. Value is the taint value the toleration matches to.
  1875. If the operator is Exists, the value should be empty, otherwise just a regular string.
  1876. type: string
  1877. type: object
  1878. type: array
  1879. topologySpreadConstraints:
  1880. description: |-
  1881. topologySpreadConstraints controls how pods are spread across failure
  1882. domains (zones, nodes). Prefer this over pod anti-affinity for HA spread.
  1883. items:
  1884. description: TopologySpreadConstraint specifies how to spread
  1885. matching pods among the given topology.
  1886. properties:
  1887. labelSelector:
  1888. description: |-
  1889. LabelSelector is used to find matching pods.
  1890. Pods that match this label selector are counted to determine the number of pods
  1891. in their corresponding topology domain.
  1892. properties:
  1893. matchExpressions:
  1894. description: matchExpressions is a list of label
  1895. selector requirements. The requirements are ANDed.
  1896. items:
  1897. description: |-
  1898. A label selector requirement is a selector that contains values, a key, and an operator that
  1899. relates the key and values.
  1900. properties:
  1901. key:
  1902. description: key is the label key that the
  1903. selector applies to.
  1904. type: string
  1905. operator:
  1906. description: |-
  1907. operator represents a key's relationship to a set of values.
  1908. Valid operators are In, NotIn, Exists and DoesNotExist.
  1909. type: string
  1910. values:
  1911. description: |-
  1912. values is an array of string values. If the operator is In or NotIn,
  1913. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1914. the values array must be empty. This array is replaced during a strategic
  1915. merge patch.
  1916. items:
  1917. type: string
  1918. type: array
  1919. x-kubernetes-list-type: atomic
  1920. required:
  1921. - key
  1922. - operator
  1923. type: object
  1924. type: array
  1925. x-kubernetes-list-type: atomic
  1926. matchLabels:
  1927. additionalProperties:
  1928. type: string
  1929. description: |-
  1930. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1931. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1932. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1933. type: object
  1934. type: object
  1935. x-kubernetes-map-type: atomic
  1936. matchLabelKeys:
  1937. description: |-
  1938. MatchLabelKeys is a set of pod label keys to select the pods over which
  1939. spreading will be calculated. The keys are used to lookup values from the
  1940. incoming pod labels, those key-value labels are ANDed with labelSelector
  1941. to select the group of existing pods over which spreading will be calculated
  1942. for the incoming pod. The same key is forbidden to exist in both MatchLabelKeys and LabelSelector.
  1943. MatchLabelKeys cannot be set when LabelSelector isn't set.
  1944. Keys that don't exist in the incoming pod labels will
  1945. be ignored. A null or empty list means only match against labelSelector.
  1946. This is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate to be enabled (enabled by default).
  1947. items:
  1948. type: string
  1949. type: array
  1950. x-kubernetes-list-type: atomic
  1951. maxSkew:
  1952. description: |-
  1953. MaxSkew describes the degree to which pods may be unevenly distributed.
  1954. When `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference
  1955. between the number of matching pods in the target topology and the global minimum.
  1956. The global minimum is the minimum number of matching pods in an eligible domain
  1957. or zero if the number of eligible domains is less than MinDomains.
  1958. For example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same
  1959. labelSelector spread as 2/2/1:
  1960. In this case, the global minimum is 1.
  1961. | zone1 | zone2 | zone3 |
  1962. | P P | P P | P |
  1963. - if MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2;
  1964. scheduling it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2)
  1965. violate MaxSkew(1).
  1966. - if MaxSkew is 2, incoming pod can be scheduled onto any zone.
  1967. When `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence
  1968. to topologies that satisfy it.
  1969. It's a required field. Default value is 1 and 0 is not allowed.
  1970. format: int32
  1971. type: integer
  1972. minDomains:
  1973. description: |-
  1974. MinDomains indicates a minimum number of eligible domains.
  1975. When the number of eligible domains with matching topology keys is less than minDomains,
  1976. Pod Topology Spread treats "global minimum" as 0, and then the calculation of Skew is performed.
  1977. And when the number of eligible domains with matching topology keys equals or greater than minDomains,
  1978. this value has no effect on scheduling.
  1979. As a result, when the number of eligible domains is less than minDomains,
  1980. scheduler won't schedule more than maxSkew Pods to those domains.
  1981. If value is nil, the constraint behaves as if MinDomains is equal to 1.
  1982. Valid values are integers greater than 0.
  1983. When value is not nil, WhenUnsatisfiable must be DoNotSchedule.
  1984. For example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and pods with the same
  1985. labelSelector spread as 2/2/2:
  1986. | zone1 | zone2 | zone3 |
  1987. | P P | P P | P P |
  1988. The number of domains is less than 5(MinDomains), so "global minimum" is treated as 0.
  1989. In this situation, new pod with the same labelSelector cannot be scheduled,
  1990. because computed skew will be 3(3 - 0) if new Pod is scheduled to any of the three zones,
  1991. it will violate MaxSkew.
  1992. format: int32
  1993. type: integer
  1994. nodeAffinityPolicy:
  1995. description: |-
  1996. NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector
  1997. when calculating pod topology spread skew. Options are:
  1998. - Honor: only nodes matching nodeAffinity/nodeSelector are included in the calculations.
  1999. - Ignore: nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.
  2000. If this value is nil, the behavior is equivalent to the Honor policy.
  2001. type: string
  2002. nodeTaintsPolicy:
  2003. description: |-
  2004. NodeTaintsPolicy indicates how we will treat node taints when calculating
  2005. pod topology spread skew. Options are:
  2006. - Honor: nodes without taints, along with tainted nodes for which the incoming pod
  2007. has a toleration, are included.
  2008. - Ignore: node taints are ignored. All nodes are included.
  2009. If this value is nil, the behavior is equivalent to the Ignore policy.
  2010. type: string
  2011. topologyKey:
  2012. description: |-
  2013. TopologyKey is the key of node labels. Nodes that have a label with this key
  2014. and identical values are considered to be in the same topology.
  2015. We consider each <key, value> as a "bucket", and try to put balanced number
  2016. of pods into each bucket.
  2017. We define a domain as a particular instance of a topology.
  2018. Also, we define an eligible domain as a domain whose nodes meet the requirements of
  2019. nodeAffinityPolicy and nodeTaintsPolicy.
  2020. e.g. If TopologyKey is "kubernetes.io/hostname", each Node is a domain of that topology.
  2021. And, if TopologyKey is "topology.kubernetes.io/zone", each zone is a domain of that topology.
  2022. It's a required field.
  2023. type: string
  2024. whenUnsatisfiable:
  2025. description: |-
  2026. WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy
  2027. the spread constraint.
  2028. - DoNotSchedule (default) tells the scheduler not to schedule it.
  2029. - ScheduleAnyway tells the scheduler to schedule the pod in any location,
  2030. but giving higher precedence to topologies that would help reduce the
  2031. skew.
  2032. A constraint is considered "Unsatisfiable" for an incoming pod
  2033. if and only if every possible node assignment for that pod would violate
  2034. "MaxSkew" on some topology.
  2035. For example, in a 3-zone cluster, MaxSkew is set to 1, and pods with the same
  2036. labelSelector spread as 3/1/1:
  2037. | zone1 | zone2 | zone3 |
  2038. | P P P | P | P |
  2039. If WhenUnsatisfiable is set to DoNotSchedule, incoming pod can only be scheduled
  2040. to zone2(zone3) to become 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies
  2041. MaxSkew(1). In other words, the cluster can still be imbalanced, but scheduler
  2042. won't make it *more* imbalanced.
  2043. It's a required field.
  2044. type: string
  2045. required:
  2046. - maxSkew
  2047. - topologyKey
  2048. - whenUnsatisfiable
  2049. type: object
  2050. type: array
  2051. volumes:
  2052. description: volumes defines additional pod volumes available
  2053. to the runtime container.
  2054. items:
  2055. description: Volume represents a named volume in a pod that
  2056. may be accessed by any container in the pod.
  2057. properties:
  2058. awsElasticBlockStore:
  2059. description: |-
  2060. awsElasticBlockStore represents an AWS Disk resource that is attached to a
  2061. kubelet's host machine and then exposed to the pod.
  2062. Deprecated: AWSElasticBlockStore is deprecated. All operations for the in-tree
  2063. awsElasticBlockStore type are redirected to the ebs.csi.aws.com CSI driver.
  2064. More info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  2065. properties:
  2066. fsType:
  2067. description: |-
  2068. fsType is the filesystem type of the volume that you want to mount.
  2069. Tip: Ensure that the filesystem type is supported by the host operating system.
  2070. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  2071. More info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  2072. type: string
  2073. partition:
  2074. description: |-
  2075. partition is the partition in the volume that you want to mount.
  2076. If omitted, the default is to mount by volume name.
  2077. Examples: For volume /dev/sda1, you specify the partition as "1".
  2078. Similarly, the volume partition for /dev/sda is "0" (or you can leave the property empty).
  2079. format: int32
  2080. type: integer
  2081. readOnly:
  2082. description: |-
  2083. readOnly value true will force the readOnly setting in VolumeMounts.
  2084. More info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  2085. type: boolean
  2086. volumeID:
  2087. description: |-
  2088. volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).
  2089. More info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
  2090. type: string
  2091. required:
  2092. - volumeID
  2093. type: object
  2094. azureDisk:
  2095. description: |-
  2096. azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.
  2097. Deprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type
  2098. are redirected to the disk.csi.azure.com CSI driver.
  2099. properties:
  2100. cachingMode:
  2101. description: 'cachingMode is the Host Caching mode:
  2102. None, Read Only, Read Write.'
  2103. type: string
  2104. diskName:
  2105. description: diskName is the Name of the data disk
  2106. in the blob storage
  2107. type: string
  2108. diskURI:
  2109. description: diskURI is the URI of data disk in
  2110. the blob storage
  2111. type: string
  2112. fsType:
  2113. default: ext4
  2114. description: |-
  2115. fsType is Filesystem type to mount.
  2116. Must be a filesystem type supported by the host operating system.
  2117. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  2118. type: string
  2119. kind:
  2120. description: 'kind expected values are Shared: multiple
  2121. blob disks per storage account Dedicated: single
  2122. blob disk per storage account Managed: azure
  2123. managed data disk (only in managed availability
  2124. set). defaults to shared'
  2125. type: string
  2126. readOnly:
  2127. default: false
  2128. description: |-
  2129. readOnly Defaults to false (read/write). ReadOnly here will force
  2130. the ReadOnly setting in VolumeMounts.
  2131. type: boolean
  2132. required:
  2133. - diskName
  2134. - diskURI
  2135. type: object
  2136. azureFile:
  2137. description: |-
  2138. azureFile represents an Azure File Service mount on the host and bind mount to the pod.
  2139. Deprecated: AzureFile is deprecated. All operations for the in-tree azureFile type
  2140. are redirected to the file.csi.azure.com CSI driver.
  2141. properties:
  2142. readOnly:
  2143. description: |-
  2144. readOnly defaults to false (read/write). ReadOnly here will force
  2145. the ReadOnly setting in VolumeMounts.
  2146. type: boolean
  2147. secretName:
  2148. description: secretName is the name of secret that
  2149. contains Azure Storage Account Name and Key
  2150. type: string
  2151. shareName:
  2152. description: shareName is the azure share Name
  2153. type: string
  2154. required:
  2155. - secretName
  2156. - shareName
  2157. type: object
  2158. cephfs:
  2159. description: |-
  2160. cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
  2161. Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.
  2162. properties:
  2163. monitors:
  2164. description: |-
  2165. monitors is Required: Monitors is a collection of Ceph monitors
  2166. More info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
  2167. items:
  2168. type: string
  2169. type: array
  2170. x-kubernetes-list-type: atomic
  2171. path:
  2172. description: 'path is Optional: Used as the mounted
  2173. root, rather than the full Ceph tree, default
  2174. is /'
  2175. type: string
  2176. readOnly:
  2177. description: |-
  2178. readOnly is Optional: Defaults to false (read/write). ReadOnly here will force
  2179. the ReadOnly setting in VolumeMounts.
  2180. More info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
  2181. type: boolean
  2182. secretFile:
  2183. description: |-
  2184. secretFile is Optional: SecretFile is the path to key ring for User, default is /etc/ceph/user.secret
  2185. More info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
  2186. type: string
  2187. secretRef:
  2188. description: |-
  2189. secretRef is Optional: SecretRef is reference to the authentication secret for User, default is empty.
  2190. More info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
  2191. properties:
  2192. name:
  2193. default: ""
  2194. description: |-
  2195. Name of the referent.
  2196. This field is effectively required, but due to backwards compatibility is
  2197. allowed to be empty. Instances of this type with an empty value here are
  2198. almost certainly wrong.
  2199. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  2200. type: string
  2201. type: object
  2202. x-kubernetes-map-type: atomic
  2203. user:
  2204. description: |-
  2205. user is optional: User is the rados user name, default is admin
  2206. More info: https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
  2207. type: string
  2208. required:
  2209. - monitors
  2210. type: object
  2211. cinder:
  2212. description: |-
  2213. cinder represents a cinder volume attached and mounted on kubelets host machine.
  2214. Deprecated: Cinder is deprecated. All operations for the in-tree cinder type
  2215. are redirected to the cinder.csi.openstack.org CSI driver.
  2216. More info: https://examples.k8s.io/mysql-cinder-pd/README.md
  2217. properties:
  2218. fsType:
  2219. description: |-
  2220. fsType is the filesystem type to mount.
  2221. Must be a filesystem type supported by the host operating system.
  2222. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  2223. More info: https://examples.k8s.io/mysql-cinder-pd/README.md
  2224. type: string
  2225. readOnly:
  2226. description: |-
  2227. readOnly defaults to false (read/write). ReadOnly here will force
  2228. the ReadOnly setting in VolumeMounts.
  2229. More info: https://examples.k8s.io/mysql-cinder-pd/README.md
  2230. type: boolean
  2231. secretRef:
  2232. description: |-
  2233. secretRef is optional: points to a secret object containing parameters used to connect
  2234. to OpenStack.
  2235. properties:
  2236. name:
  2237. default: ""
  2238. description: |-
  2239. Name of the referent.
  2240. This field is effectively required, but due to backwards compatibility is
  2241. allowed to be empty. Instances of this type with an empty value here are
  2242. almost certainly wrong.
  2243. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  2244. type: string
  2245. type: object
  2246. x-kubernetes-map-type: atomic
  2247. volumeID:
  2248. description: |-
  2249. volumeID used to identify the volume in cinder.
  2250. More info: https://examples.k8s.io/mysql-cinder-pd/README.md
  2251. type: string
  2252. required:
  2253. - volumeID
  2254. type: object
  2255. configMap:
  2256. description: configMap represents a configMap that should
  2257. populate this volume
  2258. properties:
  2259. defaultMode:
  2260. description: |-
  2261. defaultMode is optional: mode bits used to set permissions on created files by default.
  2262. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  2263. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  2264. Defaults to 0644.
  2265. Directories within the path are not affected by this setting.
  2266. This might be in conflict with other options that affect the file
  2267. mode, like fsGroup, and the result can be other mode bits set.
  2268. format: int32
  2269. type: integer
  2270. items:
  2271. description: |-
  2272. items if unspecified, each key-value pair in the Data field of the referenced
  2273. ConfigMap will be projected into the volume as a file whose name is the
  2274. key and content is the value. If specified, the listed keys will be
  2275. projected into the specified paths, and unlisted keys will not be
  2276. present. If a key is specified which is not present in the ConfigMap,
  2277. the volume setup will error unless it is marked optional. Paths must be
  2278. relative and may not contain the '..' path or start with '..'.
  2279. items:
  2280. description: Maps a string key to a path within
  2281. a volume.
  2282. properties:
  2283. key:
  2284. description: key is the key to project.
  2285. type: string
  2286. mode:
  2287. description: |-
  2288. mode is Optional: mode bits used to set permissions on this file.
  2289. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  2290. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  2291. If not specified, the volume defaultMode will be used.
  2292. This might be in conflict with other options that affect the file
  2293. mode, like fsGroup, and the result can be other mode bits set.
  2294. format: int32
  2295. type: integer
  2296. path:
  2297. description: |-
  2298. path is the relative path of the file to map the key to.
  2299. May not be an absolute path.
  2300. May not contain the path element '..'.
  2301. May not start with the string '..'.
  2302. type: string
  2303. required:
  2304. - key
  2305. - path
  2306. type: object
  2307. type: array
  2308. x-kubernetes-list-type: atomic
  2309. name:
  2310. default: ""
  2311. description: |-
  2312. Name of the referent.
  2313. This field is effectively required, but due to backwards compatibility is
  2314. allowed to be empty. Instances of this type with an empty value here are
  2315. almost certainly wrong.
  2316. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  2317. type: string
  2318. optional:
  2319. description: optional specify whether the ConfigMap
  2320. or its keys must be defined
  2321. type: boolean
  2322. type: object
  2323. x-kubernetes-map-type: atomic
  2324. csi:
  2325. description: csi (Container Storage Interface) represents
  2326. ephemeral storage that is handled by certain external
  2327. CSI drivers.
  2328. properties:
  2329. driver:
  2330. description: |-
  2331. driver is the name of the CSI driver that handles this volume.
  2332. Consult with your admin for the correct name as registered in the cluster.
  2333. type: string
  2334. fsType:
  2335. description: |-
  2336. fsType to mount. Ex. "ext4", "xfs", "ntfs".
  2337. If not provided, the empty value is passed to the associated CSI driver
  2338. which will determine the default filesystem to apply.
  2339. type: string
  2340. nodePublishSecretRef:
  2341. description: |-
  2342. nodePublishSecretRef is a reference to the secret object containing
  2343. sensitive information to pass to the CSI driver to complete the CSI
  2344. NodePublishVolume and NodeUnpublishVolume calls.
  2345. This field is optional, and may be empty if no secret is required. If the
  2346. secret object contains more than one secret, all secret references are passed.
  2347. properties:
  2348. name:
  2349. default: ""
  2350. description: |-
  2351. Name of the referent.
  2352. This field is effectively required, but due to backwards compatibility is
  2353. allowed to be empty. Instances of this type with an empty value here are
  2354. almost certainly wrong.
  2355. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  2356. type: string
  2357. type: object
  2358. x-kubernetes-map-type: atomic
  2359. readOnly:
  2360. description: |-
  2361. readOnly specifies a read-only configuration for the volume.
  2362. Defaults to false (read/write).
  2363. type: boolean
  2364. volumeAttributes:
  2365. additionalProperties:
  2366. type: string
  2367. description: |-
  2368. volumeAttributes stores driver-specific properties that are passed to the CSI
  2369. driver. Consult your driver's documentation for supported values.
  2370. type: object
  2371. required:
  2372. - driver
  2373. type: object
  2374. downwardAPI:
  2375. description: downwardAPI represents downward API about
  2376. the pod that should populate this volume
  2377. properties:
  2378. defaultMode:
  2379. description: |-
  2380. Optional: mode bits to use on created files by default. Must be a
  2381. Optional: mode bits used to set permissions on created files by default.
  2382. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  2383. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  2384. Defaults to 0644.
  2385. Directories within the path are not affected by this setting.
  2386. This might be in conflict with other options that affect the file
  2387. mode, like fsGroup, and the result can be other mode bits set.
  2388. format: int32
  2389. type: integer
  2390. items:
  2391. description: Items is a list of downward API volume
  2392. file
  2393. items:
  2394. description: DownwardAPIVolumeFile represents
  2395. information to create the file containing the
  2396. pod field
  2397. properties:
  2398. fieldRef:
  2399. description: 'Required: Selects a field of
  2400. the pod: only annotations, labels, name,
  2401. namespace and uid are supported.'
  2402. properties:
  2403. apiVersion:
  2404. description: Version of the schema the
  2405. FieldPath is written in terms of, defaults
  2406. to "v1".
  2407. type: string
  2408. fieldPath:
  2409. description: Path of the field to select
  2410. in the specified API version.
  2411. type: string
  2412. required:
  2413. - fieldPath
  2414. type: object
  2415. x-kubernetes-map-type: atomic
  2416. mode:
  2417. description: |-
  2418. Optional: mode bits used to set permissions on this file, must be an octal value
  2419. between 0000 and 0777 or a decimal value between 0 and 511.
  2420. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  2421. If not specified, the volume defaultMode will be used.
  2422. This might be in conflict with other options that affect the file
  2423. mode, like fsGroup, and the result can be other mode bits set.
  2424. format: int32
  2425. type: integer
  2426. path:
  2427. description: 'Required: Path is the relative
  2428. path name of the file to be created. Must
  2429. not be absolute or contain the ''..'' path.
  2430. Must be utf-8 encoded. The first item of
  2431. the relative path must not start with ''..'''
  2432. type: string
  2433. resourceFieldRef:
  2434. description: |-
  2435. Selects a resource of the container: only resources limits and requests
  2436. (limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.
  2437. properties:
  2438. containerName:
  2439. description: 'Container name: required
  2440. for volumes, optional for env vars'
  2441. type: string
  2442. divisor:
  2443. anyOf:
  2444. - type: integer
  2445. - type: string
  2446. description: Specifies the output format
  2447. of the exposed resources, defaults to
  2448. "1"
  2449. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  2450. x-kubernetes-int-or-string: true
  2451. resource:
  2452. description: 'Required: resource to select'
  2453. type: string
  2454. required:
  2455. - resource
  2456. type: object
  2457. x-kubernetes-map-type: atomic
  2458. required:
  2459. - path
  2460. type: object
  2461. type: array
  2462. x-kubernetes-list-type: atomic
  2463. type: object
  2464. emptyDir:
  2465. description: |-
  2466. emptyDir represents a temporary directory that shares a pod's lifetime.
  2467. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir
  2468. properties:
  2469. medium:
  2470. description: |-
  2471. medium represents what type of storage medium should back this directory.
  2472. The default is "" which means to use the node's default medium.
  2473. Must be an empty string (default) or Memory.
  2474. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir
  2475. type: string
  2476. sizeLimit:
  2477. anyOf:
  2478. - type: integer
  2479. - type: string
  2480. description: |-
  2481. sizeLimit is the total amount of local storage required for this EmptyDir volume.
  2482. The size limit is also applicable for memory medium.
  2483. The maximum usage on memory medium EmptyDir would be the minimum value between
  2484. the SizeLimit specified here and the sum of memory limits of all containers in a pod.
  2485. The default is nil which means that the limit is undefined.
  2486. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir
  2487. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  2488. x-kubernetes-int-or-string: true
  2489. type: object
  2490. ephemeral:
  2491. description: |-
  2492. ephemeral represents a volume that is handled by a cluster storage driver.
  2493. The volume's lifecycle is tied to the pod that defines it - it will be created before the pod starts,
  2494. and deleted when the pod is removed.
  2495. Use this if:
  2496. a) the volume is only needed while the pod runs,
  2497. b) features of normal volumes like restoring from snapshot or capacity
  2498. tracking are needed,
  2499. c) the storage driver is specified through a storage class, and
  2500. d) the storage driver supports dynamic volume provisioning through
  2501. a PersistentVolumeClaim (see EphemeralVolumeSource for more
  2502. information on the connection between this volume type
  2503. and PersistentVolumeClaim).
  2504. Use PersistentVolumeClaim or one of the vendor-specific
  2505. APIs for volumes that persist for longer than the lifecycle
  2506. of an individual pod.
  2507. Use CSI for light-weight local ephemeral volumes if the CSI driver is meant to
  2508. be used that way - see the documentation of the driver for
  2509. more information.
  2510. A pod can use both types of ephemeral volumes and
  2511. persistent volumes at the same time.
  2512. properties:
  2513. volumeClaimTemplate:
  2514. description: |-
  2515. Will be used to create a stand-alone PVC to provision the volume.
  2516. The pod in which this EphemeralVolumeSource is embedded will be the
  2517. owner of the PVC, i.e. the PVC will be deleted together with the
  2518. pod. The name of the PVC will be `<pod name>-<volume name>` where
  2519. `<volume name>` is the name from the `PodSpec.Volumes` array
  2520. entry. Pod validation will reject the pod if the concatenated name
  2521. is not valid for a PVC (for example, too long).
  2522. An existing PVC with that name that is not owned by the pod
  2523. will *not* be used for the pod to avoid using an unrelated
  2524. volume by mistake. Starting the pod is then blocked until
  2525. the unrelated PVC is removed. If such a pre-created PVC is
  2526. meant to be used by the pod, the PVC has to updated with an
  2527. owner reference to the pod once the pod exists. Normally
  2528. this should not be necessary, but it may be useful when
  2529. manually reconstructing a broken cluster.
  2530. This field is read-only and no changes will be made by Kubernetes
  2531. to the PVC after it has been created.
  2532. Required, must not be nil.
  2533. properties:
  2534. metadata:
  2535. description: |-
  2536. May contain labels and annotations that will be copied into the PVC
  2537. when creating it. No other fields are allowed and will be rejected during
  2538. validation.
  2539. type: object
  2540. spec:
  2541. description: |-
  2542. The specification for the PersistentVolumeClaim. The entire content is
  2543. copied unchanged into the PVC that gets created from this
  2544. template. The same fields as in a PersistentVolumeClaim
  2545. are also valid here.
  2546. properties:
  2547. accessModes:
  2548. description: |-
  2549. accessModes contains the desired access modes the volume should have.
  2550. More info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
  2551. items:
  2552. type: string
  2553. type: array
  2554. x-kubernetes-list-type: atomic
  2555. dataSource:
  2556. description: |-
  2557. dataSource field can be used to specify either:
  2558. * An existing VolumeSnapshot object (snapshot.storage.k8s.io/VolumeSnapshot)
  2559. * An existing PVC (PersistentVolumeClaim)
  2560. If the provisioner or an external controller can support the specified data source,
  2561. it will create a new volume based on the contents of the specified data source.
  2562. When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef,
  2563. and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified.
  2564. If the namespace is specified, then dataSourceRef will not be copied to dataSource.
  2565. properties:
  2566. apiGroup:
  2567. description: |-
  2568. APIGroup is the group for the resource being referenced.
  2569. If APIGroup is not specified, the specified Kind must be in the core API group.
  2570. For any other third-party types, APIGroup is required.
  2571. type: string
  2572. kind:
  2573. description: Kind is the type of resource
  2574. being referenced
  2575. type: string
  2576. name:
  2577. description: Name is the name of resource
  2578. being referenced
  2579. type: string
  2580. required:
  2581. - kind
  2582. - name
  2583. type: object
  2584. x-kubernetes-map-type: atomic
  2585. dataSourceRef:
  2586. description: |-
  2587. dataSourceRef specifies the object from which to populate the volume with data, if a non-empty
  2588. volume is desired. This may be any object from a non-empty API group (non
  2589. core object) or a PersistentVolumeClaim object.
  2590. When this field is specified, volume binding will only succeed if the type of
  2591. the specified object matches some installed volume populator or dynamic
  2592. provisioner.
  2593. This field will replace the functionality of the dataSource field and as such
  2594. if both fields are non-empty, they must have the same value. For backwards
  2595. compatibility, when namespace isn't specified in dataSourceRef,
  2596. both fields (dataSource and dataSourceRef) will be set to the same
  2597. value automatically if one of them is empty and the other is non-empty.
  2598. When namespace is specified in dataSourceRef,
  2599. dataSource isn't set to the same value and must be empty.
  2600. There are three important differences between dataSource and dataSourceRef:
  2601. * While dataSource only allows two specific types of objects, dataSourceRef
  2602. allows any non-core object, as well as PersistentVolumeClaim objects.
  2603. * While dataSource ignores disallowed values (dropping them), dataSourceRef
  2604. preserves all values, and generates an error if a disallowed value is
  2605. specified.
  2606. * While dataSource only allows local objects, dataSourceRef allows objects
  2607. in any namespaces.
  2608. (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled.
  2609. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled.
  2610. properties:
  2611. apiGroup:
  2612. description: |-
  2613. APIGroup is the group for the resource being referenced.
  2614. If APIGroup is not specified, the specified Kind must be in the core API group.
  2615. For any other third-party types, APIGroup is required.
  2616. type: string
  2617. kind:
  2618. description: Kind is the type of resource
  2619. being referenced
  2620. type: string
  2621. name:
  2622. description: Name is the name of resource
  2623. being referenced
  2624. type: string
  2625. namespace:
  2626. description: |-
  2627. Namespace is the namespace of resource being referenced
  2628. Note that when a namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is required in the referent namespace to allow that namespace's owner to accept the reference. See the ReferenceGrant documentation for details.
  2629. (Alpha) This field requires the CrossNamespaceVolumeDataSource feature gate to be enabled.
  2630. type: string
  2631. required:
  2632. - kind
  2633. - name
  2634. type: object
  2635. resources:
  2636. description: |-
  2637. resources represents the minimum resources the volume should have.
  2638. Users are allowed to specify resource requirements
  2639. that are lower than previous value but must still be higher than capacity recorded in the
  2640. status field of the claim.
  2641. More info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources
  2642. properties:
  2643. limits:
  2644. additionalProperties:
  2645. anyOf:
  2646. - type: integer
  2647. - type: string
  2648. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  2649. x-kubernetes-int-or-string: true
  2650. description: |-
  2651. Limits describes the maximum amount of compute resources allowed.
  2652. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
  2653. type: object
  2654. requests:
  2655. additionalProperties:
  2656. anyOf:
  2657. - type: integer
  2658. - type: string
  2659. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  2660. x-kubernetes-int-or-string: true
  2661. description: |-
  2662. Requests describes the minimum amount of compute resources required.
  2663. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified,
  2664. otherwise to an implementation-defined value. Requests cannot exceed Limits.
  2665. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
  2666. type: object
  2667. type: object
  2668. selector:
  2669. description: selector is a label query over
  2670. volumes to consider for binding.
  2671. properties:
  2672. matchExpressions:
  2673. description: matchExpressions is a list
  2674. of label selector requirements. The
  2675. requirements are ANDed.
  2676. items:
  2677. description: |-
  2678. A label selector requirement is a selector that contains values, a key, and an operator that
  2679. relates the key and values.
  2680. properties:
  2681. key:
  2682. description: key is the label
  2683. key that the selector applies
  2684. to.
  2685. type: string
  2686. operator:
  2687. description: |-
  2688. operator represents a key's relationship to a set of values.
  2689. Valid operators are In, NotIn, Exists and DoesNotExist.
  2690. type: string
  2691. values:
  2692. description: |-
  2693. values is an array of string values. If the operator is In or NotIn,
  2694. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2695. the values array must be empty. This array is replaced during a strategic
  2696. merge patch.
  2697. items:
  2698. type: string
  2699. type: array
  2700. x-kubernetes-list-type: atomic
  2701. required:
  2702. - key
  2703. - operator
  2704. type: object
  2705. type: array
  2706. x-kubernetes-list-type: atomic
  2707. matchLabels:
  2708. additionalProperties:
  2709. type: string
  2710. description: |-
  2711. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2712. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2713. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2714. type: object
  2715. type: object
  2716. x-kubernetes-map-type: atomic
  2717. storageClassName:
  2718. description: |-
  2719. storageClassName is the name of the StorageClass required by the claim.
  2720. More info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1
  2721. type: string
  2722. volumeAttributesClassName:
  2723. description: |-
  2724. volumeAttributesClassName may be used to set the VolumeAttributesClass used by this claim.
  2725. If specified, the CSI driver will create or update the volume with the attributes defined
  2726. in the corresponding VolumeAttributesClass. This has a different purpose than storageClassName,
  2727. it can be changed after the claim is created. An empty string or nil value indicates that no
  2728. VolumeAttributesClass will be applied to the claim. If the claim enters an Infeasible error state,
  2729. this field can be reset to its previous value (including nil) to cancel the modification.
  2730. If the resource referred to by volumeAttributesClass does not exist, this PersistentVolumeClaim will be
  2731. set to a Pending state, as reflected by the modifyVolumeStatus field, until such as a resource
  2732. exists.
  2733. More info: https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/
  2734. type: string
  2735. volumeMode:
  2736. description: |-
  2737. volumeMode defines what type of volume is required by the claim.
  2738. Value of Filesystem is implied when not included in claim spec.
  2739. type: string
  2740. volumeName:
  2741. description: volumeName is the binding reference
  2742. to the PersistentVolume backing this claim.
  2743. type: string
  2744. type: object
  2745. required:
  2746. - spec
  2747. type: object
  2748. type: object
  2749. fc:
  2750. description: fc represents a Fibre Channel resource
  2751. that is attached to a kubelet's host machine and then
  2752. exposed to the pod.
  2753. properties:
  2754. fsType:
  2755. description: |-
  2756. fsType is the filesystem type to mount.
  2757. Must be a filesystem type supported by the host operating system.
  2758. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  2759. type: string
  2760. lun:
  2761. description: 'lun is Optional: FC target lun number'
  2762. format: int32
  2763. type: integer
  2764. readOnly:
  2765. description: |-
  2766. readOnly is Optional: Defaults to false (read/write). ReadOnly here will force
  2767. the ReadOnly setting in VolumeMounts.
  2768. type: boolean
  2769. targetWWNs:
  2770. description: 'targetWWNs is Optional: FC target
  2771. worldwide names (WWNs)'
  2772. items:
  2773. type: string
  2774. type: array
  2775. x-kubernetes-list-type: atomic
  2776. wwids:
  2777. description: |-
  2778. wwids Optional: FC volume world wide identifiers (wwids)
  2779. Either wwids or combination of targetWWNs and lun must be set, but not both simultaneously.
  2780. items:
  2781. type: string
  2782. type: array
  2783. x-kubernetes-list-type: atomic
  2784. type: object
  2785. flexVolume:
  2786. description: |-
  2787. flexVolume represents a generic volume resource that is
  2788. provisioned/attached using an exec based plugin.
  2789. Deprecated: FlexVolume is deprecated. Consider using a CSIDriver instead.
  2790. properties:
  2791. driver:
  2792. description: driver is the name of the driver to
  2793. use for this volume.
  2794. type: string
  2795. fsType:
  2796. description: |-
  2797. fsType is the filesystem type to mount.
  2798. Must be a filesystem type supported by the host operating system.
  2799. Ex. "ext4", "xfs", "ntfs". The default filesystem depends on FlexVolume script.
  2800. type: string
  2801. options:
  2802. additionalProperties:
  2803. type: string
  2804. description: 'options is Optional: this field holds
  2805. extra command options if any.'
  2806. type: object
  2807. readOnly:
  2808. description: |-
  2809. readOnly is Optional: defaults to false (read/write). ReadOnly here will force
  2810. the ReadOnly setting in VolumeMounts.
  2811. type: boolean
  2812. secretRef:
  2813. description: |-
  2814. secretRef is Optional: secretRef is reference to the secret object containing
  2815. sensitive information to pass to the plugin scripts. This may be
  2816. empty if no secret object is specified. If the secret object
  2817. contains more than one secret, all secrets are passed to the plugin
  2818. scripts.
  2819. properties:
  2820. name:
  2821. default: ""
  2822. description: |-
  2823. Name of the referent.
  2824. This field is effectively required, but due to backwards compatibility is
  2825. allowed to be empty. Instances of this type with an empty value here are
  2826. almost certainly wrong.
  2827. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  2828. type: string
  2829. type: object
  2830. x-kubernetes-map-type: atomic
  2831. required:
  2832. - driver
  2833. type: object
  2834. flocker:
  2835. description: |-
  2836. flocker represents a Flocker volume attached to a kubelet's host machine. This depends on the Flocker control service being running.
  2837. Deprecated: Flocker is deprecated and the in-tree flocker type is no longer supported.
  2838. properties:
  2839. datasetName:
  2840. description: |-
  2841. datasetName is Name of the dataset stored as metadata -> name on the dataset for Flocker
  2842. should be considered as deprecated
  2843. type: string
  2844. datasetUUID:
  2845. description: datasetUUID is the UUID of the dataset.
  2846. This is unique identifier of a Flocker dataset
  2847. type: string
  2848. type: object
  2849. gcePersistentDisk:
  2850. description: |-
  2851. gcePersistentDisk represents a GCE Disk resource that is attached to a
  2852. kubelet's host machine and then exposed to the pod.
  2853. Deprecated: GCEPersistentDisk is deprecated. All operations for the in-tree
  2854. gcePersistentDisk type are redirected to the pd.csi.storage.gke.io CSI driver.
  2855. More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
  2856. properties:
  2857. fsType:
  2858. description: |-
  2859. fsType is filesystem type of the volume that you want to mount.
  2860. Tip: Ensure that the filesystem type is supported by the host operating system.
  2861. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  2862. More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
  2863. type: string
  2864. partition:
  2865. description: |-
  2866. partition is the partition in the volume that you want to mount.
  2867. If omitted, the default is to mount by volume name.
  2868. Examples: For volume /dev/sda1, you specify the partition as "1".
  2869. Similarly, the volume partition for /dev/sda is "0" (or you can leave the property empty).
  2870. More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
  2871. format: int32
  2872. type: integer
  2873. pdName:
  2874. description: |-
  2875. pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.
  2876. More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
  2877. type: string
  2878. readOnly:
  2879. description: |-
  2880. readOnly here will force the ReadOnly setting in VolumeMounts.
  2881. Defaults to false.
  2882. More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
  2883. type: boolean
  2884. required:
  2885. - pdName
  2886. type: object
  2887. gitRepo:
  2888. description: |-
  2889. gitRepo represents a git repository at a particular revision.
  2890. Deprecated: GitRepo is deprecated. To provision a container with a git repo, mount an
  2891. EmptyDir into an InitContainer that clones the repo using git, then mount the EmptyDir
  2892. into the Pod's container.
  2893. properties:
  2894. directory:
  2895. description: |-
  2896. directory is the target directory name.
  2897. Must not contain or start with '..'. If '.' is supplied, the volume directory will be the
  2898. git repository. Otherwise, if specified, the volume will contain the git repository in
  2899. the subdirectory with the given name.
  2900. type: string
  2901. repository:
  2902. description: repository is the URL
  2903. type: string
  2904. revision:
  2905. description: revision is the commit hash for the
  2906. specified revision.
  2907. type: string
  2908. required:
  2909. - repository
  2910. type: object
  2911. glusterfs:
  2912. description: |-
  2913. glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.
  2914. Deprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer supported.
  2915. properties:
  2916. endpoints:
  2917. description: endpoints is the endpoint name that
  2918. details Glusterfs topology.
  2919. type: string
  2920. path:
  2921. description: |-
  2922. path is the Glusterfs volume path.
  2923. More info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
  2924. type: string
  2925. readOnly:
  2926. description: |-
  2927. readOnly here will force the Glusterfs volume to be mounted with read-only permissions.
  2928. Defaults to false.
  2929. More info: https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
  2930. type: boolean
  2931. required:
  2932. - endpoints
  2933. - path
  2934. type: object
  2935. hostPath:
  2936. description: |-
  2937. hostPath represents a pre-existing file or directory on the host
  2938. machine that is directly exposed to the container. This is generally
  2939. used for system agents or other privileged things that are allowed
  2940. to see the host machine. Most containers will NOT need this.
  2941. More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath
  2942. properties:
  2943. path:
  2944. description: |-
  2945. path of the directory on the host.
  2946. If the path is a symlink, it will follow the link to the real path.
  2947. More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath
  2948. type: string
  2949. type:
  2950. description: |-
  2951. type for HostPath Volume
  2952. Defaults to ""
  2953. More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath
  2954. type: string
  2955. required:
  2956. - path
  2957. type: object
  2958. image:
  2959. description: |-
  2960. image represents an OCI object (a container image or artifact) pulled and mounted on the kubelet's host machine.
  2961. The volume is resolved at pod startup depending on which PullPolicy value is provided:
  2962. - Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.
  2963. - Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.
  2964. - IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.
  2965. The volume gets re-resolved if the pod gets deleted and recreated, which means that new remote content will become available on pod recreation.
  2966. A failure to resolve or pull the image during pod startup will block containers from starting and may add significant latency. Failures will be retried using normal volume backoff and will be reported on the pod reason and message.
  2967. The types of objects that may be mounted by this volume are defined by the container runtime implementation on a host machine and at minimum must include all valid types supported by the container image field.
  2968. The OCI object gets mounted in a single directory (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same way as for container images.
  2969. The volume will be mounted read-only (ro) and non-executable files (noexec).
  2970. Sub path mounts for containers are not supported (spec.containers[*].volumeMounts.subpath) before 1.33.
  2971. The field spec.securityContext.fsGroupChangePolicy has no effect on this volume type.
  2972. properties:
  2973. pullPolicy:
  2974. description: |-
  2975. Policy for pulling OCI objects. Possible values are:
  2976. Always: the kubelet always attempts to pull the reference. Container creation will fail If the pull fails.
  2977. Never: the kubelet never pulls the reference and only uses a local image or artifact. Container creation will fail if the reference isn't present.
  2978. IfNotPresent: the kubelet pulls if the reference isn't already present on disk. Container creation will fail if the reference isn't present and the pull fails.
  2979. Defaults to Always if :latest tag is specified, or IfNotPresent otherwise.
  2980. type: string
  2981. reference:
  2982. description: |-
  2983. Required: Image or artifact reference to be used.
  2984. Behaves in the same way as pod.spec.containers[*].image.
  2985. Pull secrets will be assembled in the same way as for the container image by looking up node credentials, SA image pull secrets, and pod spec image pull secrets.
  2986. More info: https://kubernetes.io/docs/concepts/containers/images
  2987. This field is optional to allow higher level config management to default or override
  2988. container images in workload controllers like Deployments and StatefulSets.
  2989. type: string
  2990. type: object
  2991. iscsi:
  2992. description: |-
  2993. iscsi represents an ISCSI Disk resource that is attached to a
  2994. kubelet's host machine and then exposed to the pod.
  2995. More info: https://kubernetes.io/docs/concepts/storage/volumes/#iscsi
  2996. properties:
  2997. chapAuthDiscovery:
  2998. description: chapAuthDiscovery defines whether support
  2999. iSCSI Discovery CHAP authentication
  3000. type: boolean
  3001. chapAuthSession:
  3002. description: chapAuthSession defines whether support
  3003. iSCSI Session CHAP authentication
  3004. type: boolean
  3005. fsType:
  3006. description: |-
  3007. fsType is the filesystem type of the volume that you want to mount.
  3008. Tip: Ensure that the filesystem type is supported by the host operating system.
  3009. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  3010. More info: https://kubernetes.io/docs/concepts/storage/volumes#iscsi
  3011. type: string
  3012. initiatorName:
  3013. description: |-
  3014. initiatorName is the custom iSCSI Initiator Name.
  3015. If initiatorName is specified with iscsiInterface simultaneously, new iSCSI interface
  3016. <target portal>:<volume name> will be created for the connection.
  3017. type: string
  3018. iqn:
  3019. description: iqn is the target iSCSI Qualified Name.
  3020. type: string
  3021. iscsiInterface:
  3022. default: default
  3023. description: |-
  3024. iscsiInterface is the interface Name that uses an iSCSI transport.
  3025. Defaults to 'default' (tcp).
  3026. type: string
  3027. lun:
  3028. description: lun represents iSCSI Target Lun number.
  3029. format: int32
  3030. type: integer
  3031. portals:
  3032. description: |-
  3033. portals is the iSCSI Target Portal List. The portal is either an IP or ip_addr:port if the port
  3034. is other than default (typically TCP ports 860 and 3260).
  3035. items:
  3036. type: string
  3037. type: array
  3038. x-kubernetes-list-type: atomic
  3039. readOnly:
  3040. description: |-
  3041. readOnly here will force the ReadOnly setting in VolumeMounts.
  3042. Defaults to false.
  3043. type: boolean
  3044. secretRef:
  3045. description: secretRef is the CHAP Secret for iSCSI
  3046. target and initiator authentication
  3047. properties:
  3048. name:
  3049. default: ""
  3050. description: |-
  3051. Name of the referent.
  3052. This field is effectively required, but due to backwards compatibility is
  3053. allowed to be empty. Instances of this type with an empty value here are
  3054. almost certainly wrong.
  3055. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3056. type: string
  3057. type: object
  3058. x-kubernetes-map-type: atomic
  3059. targetPortal:
  3060. description: |-
  3061. targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if the port
  3062. is other than default (typically TCP ports 860 and 3260).
  3063. type: string
  3064. required:
  3065. - iqn
  3066. - lun
  3067. - targetPortal
  3068. type: object
  3069. name:
  3070. description: |-
  3071. name of the volume.
  3072. Must be a DNS_LABEL and unique within the pod.
  3073. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3074. type: string
  3075. nfs:
  3076. description: |-
  3077. nfs represents an NFS mount on the host that shares a pod's lifetime
  3078. More info: https://kubernetes.io/docs/concepts/storage/volumes#nfs
  3079. properties:
  3080. path:
  3081. description: |-
  3082. path that is exported by the NFS server.
  3083. More info: https://kubernetes.io/docs/concepts/storage/volumes#nfs
  3084. type: string
  3085. readOnly:
  3086. description: |-
  3087. readOnly here will force the NFS export to be mounted with read-only permissions.
  3088. Defaults to false.
  3089. More info: https://kubernetes.io/docs/concepts/storage/volumes#nfs
  3090. type: boolean
  3091. server:
  3092. description: |-
  3093. server is the hostname or IP address of the NFS server.
  3094. More info: https://kubernetes.io/docs/concepts/storage/volumes#nfs
  3095. type: string
  3096. required:
  3097. - path
  3098. - server
  3099. type: object
  3100. persistentVolumeClaim:
  3101. description: |-
  3102. persistentVolumeClaimVolumeSource represents a reference to a
  3103. PersistentVolumeClaim in the same namespace.
  3104. More info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
  3105. properties:
  3106. claimName:
  3107. description: |-
  3108. claimName is the name of a PersistentVolumeClaim in the same namespace as the pod using this volume.
  3109. More info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
  3110. type: string
  3111. readOnly:
  3112. description: |-
  3113. readOnly Will force the ReadOnly setting in VolumeMounts.
  3114. Default false.
  3115. type: boolean
  3116. required:
  3117. - claimName
  3118. type: object
  3119. photonPersistentDisk:
  3120. description: |-
  3121. photonPersistentDisk represents a PhotonController persistent disk attached and mounted on kubelets host machine.
  3122. Deprecated: PhotonPersistentDisk is deprecated and the in-tree photonPersistentDisk type is no longer supported.
  3123. properties:
  3124. fsType:
  3125. description: |-
  3126. fsType is the filesystem type to mount.
  3127. Must be a filesystem type supported by the host operating system.
  3128. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  3129. type: string
  3130. pdID:
  3131. description: pdID is the ID that identifies Photon
  3132. Controller persistent disk
  3133. type: string
  3134. required:
  3135. - pdID
  3136. type: object
  3137. portworxVolume:
  3138. description: |-
  3139. portworxVolume represents a portworx volume attached and mounted on kubelets host machine.
  3140. Deprecated: PortworxVolume is deprecated. All operations for the in-tree portworxVolume type
  3141. are redirected to the pxd.portworx.com CSI driver when the CSIMigrationPortworx feature-gate
  3142. is on.
  3143. properties:
  3144. fsType:
  3145. description: |-
  3146. fSType represents the filesystem type to mount
  3147. Must be a filesystem type supported by the host operating system.
  3148. Ex. "ext4", "xfs". Implicitly inferred to be "ext4" if unspecified.
  3149. type: string
  3150. readOnly:
  3151. description: |-
  3152. readOnly defaults to false (read/write). ReadOnly here will force
  3153. the ReadOnly setting in VolumeMounts.
  3154. type: boolean
  3155. volumeID:
  3156. description: volumeID uniquely identifies a Portworx
  3157. volume
  3158. type: string
  3159. required:
  3160. - volumeID
  3161. type: object
  3162. projected:
  3163. description: projected items for all in one resources
  3164. secrets, configmaps, and downward API
  3165. properties:
  3166. defaultMode:
  3167. description: |-
  3168. defaultMode are the mode bits used to set permissions on created files by default.
  3169. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  3170. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  3171. Directories within the path are not affected by this setting.
  3172. This might be in conflict with other options that affect the file
  3173. mode, like fsGroup, and the result can be other mode bits set.
  3174. format: int32
  3175. type: integer
  3176. sources:
  3177. description: |-
  3178. sources is the list of volume projections. Each entry in this list
  3179. handles one source.
  3180. items:
  3181. description: |-
  3182. Projection that may be projected along with other supported volume types.
  3183. Exactly one of these fields must be set.
  3184. properties:
  3185. clusterTrustBundle:
  3186. description: |-
  3187. ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field
  3188. of ClusterTrustBundle objects in an auto-updating file.
  3189. Alpha, gated by the ClusterTrustBundleProjection feature gate.
  3190. ClusterTrustBundle objects can either be selected by name, or by the
  3191. combination of signer name and a label selector.
  3192. Kubelet performs aggressive normalization of the PEM contents written
  3193. into the pod filesystem. Esoteric PEM features such as inter-block
  3194. comments and block headers are stripped. Certificates are deduplicated.
  3195. The ordering of certificates within the file is arbitrary, and Kubelet
  3196. may change the order over time.
  3197. properties:
  3198. labelSelector:
  3199. description: |-
  3200. Select all ClusterTrustBundles that match this label selector. Only has
  3201. effect if signerName is set. Mutually-exclusive with name. If unset,
  3202. interpreted as "match nothing". If set but empty, interpreted as "match
  3203. everything".
  3204. properties:
  3205. matchExpressions:
  3206. description: matchExpressions is a
  3207. list of label selector requirements.
  3208. The requirements are ANDed.
  3209. items:
  3210. description: |-
  3211. A label selector requirement is a selector that contains values, a key, and an operator that
  3212. relates the key and values.
  3213. properties:
  3214. key:
  3215. description: key is the label
  3216. key that the selector applies
  3217. to.
  3218. type: string
  3219. operator:
  3220. description: |-
  3221. operator represents a key's relationship to a set of values.
  3222. Valid operators are In, NotIn, Exists and DoesNotExist.
  3223. type: string
  3224. values:
  3225. description: |-
  3226. values is an array of string values. If the operator is In or NotIn,
  3227. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  3228. the values array must be empty. This array is replaced during a strategic
  3229. merge patch.
  3230. items:
  3231. type: string
  3232. type: array
  3233. x-kubernetes-list-type: atomic
  3234. required:
  3235. - key
  3236. - operator
  3237. type: object
  3238. type: array
  3239. x-kubernetes-list-type: atomic
  3240. matchLabels:
  3241. additionalProperties:
  3242. type: string
  3243. description: |-
  3244. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  3245. map is equivalent to an element of matchExpressions, whose key field is "key", the
  3246. operator is "In", and the values array contains only "value". The requirements are ANDed.
  3247. type: object
  3248. type: object
  3249. x-kubernetes-map-type: atomic
  3250. name:
  3251. description: |-
  3252. Select a single ClusterTrustBundle by object name. Mutually-exclusive
  3253. with signerName and labelSelector.
  3254. type: string
  3255. optional:
  3256. description: |-
  3257. If true, don't block pod startup if the referenced ClusterTrustBundle(s)
  3258. aren't available. If using name, then the named ClusterTrustBundle is
  3259. allowed not to exist. If using signerName, then the combination of
  3260. signerName and labelSelector is allowed to match zero
  3261. ClusterTrustBundles.
  3262. type: boolean
  3263. path:
  3264. description: Relative path from the volume
  3265. root to write the bundle.
  3266. type: string
  3267. signerName:
  3268. description: |-
  3269. Select all ClusterTrustBundles that match this signer name.
  3270. Mutually-exclusive with name. The contents of all selected
  3271. ClusterTrustBundles will be unified and deduplicated.
  3272. type: string
  3273. required:
  3274. - path
  3275. type: object
  3276. configMap:
  3277. description: configMap information about the
  3278. configMap data to project
  3279. properties:
  3280. items:
  3281. description: |-
  3282. items if unspecified, each key-value pair in the Data field of the referenced
  3283. ConfigMap will be projected into the volume as a file whose name is the
  3284. key and content is the value. If specified, the listed keys will be
  3285. projected into the specified paths, and unlisted keys will not be
  3286. present. If a key is specified which is not present in the ConfigMap,
  3287. the volume setup will error unless it is marked optional. Paths must be
  3288. relative and may not contain the '..' path or start with '..'.
  3289. items:
  3290. description: Maps a string key to a
  3291. path within a volume.
  3292. properties:
  3293. key:
  3294. description: key is the key to project.
  3295. type: string
  3296. mode:
  3297. description: |-
  3298. mode is Optional: mode bits used to set permissions on this file.
  3299. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  3300. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  3301. If not specified, the volume defaultMode will be used.
  3302. This might be in conflict with other options that affect the file
  3303. mode, like fsGroup, and the result can be other mode bits set.
  3304. format: int32
  3305. type: integer
  3306. path:
  3307. description: |-
  3308. path is the relative path of the file to map the key to.
  3309. May not be an absolute path.
  3310. May not contain the path element '..'.
  3311. May not start with the string '..'.
  3312. type: string
  3313. required:
  3314. - key
  3315. - path
  3316. type: object
  3317. type: array
  3318. x-kubernetes-list-type: atomic
  3319. name:
  3320. default: ""
  3321. description: |-
  3322. Name of the referent.
  3323. This field is effectively required, but due to backwards compatibility is
  3324. allowed to be empty. Instances of this type with an empty value here are
  3325. almost certainly wrong.
  3326. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3327. type: string
  3328. optional:
  3329. description: optional specify whether
  3330. the ConfigMap or its keys must be defined
  3331. type: boolean
  3332. type: object
  3333. x-kubernetes-map-type: atomic
  3334. downwardAPI:
  3335. description: downwardAPI information about
  3336. the downwardAPI data to project
  3337. properties:
  3338. items:
  3339. description: Items is a list of DownwardAPIVolume
  3340. file
  3341. items:
  3342. description: DownwardAPIVolumeFile represents
  3343. information to create the file containing
  3344. the pod field
  3345. properties:
  3346. fieldRef:
  3347. description: 'Required: Selects
  3348. a field of the pod: only annotations,
  3349. labels, name, namespace and uid
  3350. are supported.'
  3351. properties:
  3352. apiVersion:
  3353. description: Version of the
  3354. schema the FieldPath is written
  3355. in terms of, defaults to "v1".
  3356. type: string
  3357. fieldPath:
  3358. description: Path of the field
  3359. to select in the specified
  3360. API version.
  3361. type: string
  3362. required:
  3363. - fieldPath
  3364. type: object
  3365. x-kubernetes-map-type: atomic
  3366. mode:
  3367. description: |-
  3368. Optional: mode bits used to set permissions on this file, must be an octal value
  3369. between 0000 and 0777 or a decimal value between 0 and 511.
  3370. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  3371. If not specified, the volume defaultMode will be used.
  3372. This might be in conflict with other options that affect the file
  3373. mode, like fsGroup, and the result can be other mode bits set.
  3374. format: int32
  3375. type: integer
  3376. path:
  3377. description: 'Required: Path is the
  3378. relative path name of the file
  3379. to be created. Must not be absolute
  3380. or contain the ''..'' path. Must
  3381. be utf-8 encoded. The first item
  3382. of the relative path must not
  3383. start with ''..'''
  3384. type: string
  3385. resourceFieldRef:
  3386. description: |-
  3387. Selects a resource of the container: only resources limits and requests
  3388. (limits.cpu, limits.memory, requests.cpu and requests.memory) are currently supported.
  3389. properties:
  3390. containerName:
  3391. description: 'Container name:
  3392. required for volumes, optional
  3393. for env vars'
  3394. type: string
  3395. divisor:
  3396. anyOf:
  3397. - type: integer
  3398. - type: string
  3399. description: Specifies the output
  3400. format of the exposed resources,
  3401. defaults to "1"
  3402. pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
  3403. x-kubernetes-int-or-string: true
  3404. resource:
  3405. description: 'Required: resource
  3406. to select'
  3407. type: string
  3408. required:
  3409. - resource
  3410. type: object
  3411. x-kubernetes-map-type: atomic
  3412. required:
  3413. - path
  3414. type: object
  3415. type: array
  3416. x-kubernetes-list-type: atomic
  3417. type: object
  3418. podCertificate:
  3419. description: |-
  3420. Projects an auto-rotating credential bundle (private key and certificate
  3421. chain) that the pod can use either as a TLS client or server.
  3422. Kubelet generates a private key and uses it to send a
  3423. PodCertificateRequest to the named signer. Once the signer approves the
  3424. request and issues a certificate chain, Kubelet writes the key and
  3425. certificate chain to the pod filesystem. The pod does not start until
  3426. certificates have been issued for each podCertificate projected volume
  3427. source in its spec.
  3428. Kubelet will begin trying to rotate the certificate at the time indicated
  3429. by the signer using the PodCertificateRequest.Status.BeginRefreshAt
  3430. timestamp.
  3431. Kubelet can write a single file, indicated by the credentialBundlePath
  3432. field, or separate files, indicated by the keyPath and
  3433. certificateChainPath fields.
  3434. The credential bundle is a single file in PEM format. The first PEM
  3435. entry is the private key (in PKCS#8 format), and the remaining PEM
  3436. entries are the certificate chain issued by the signer (typically,
  3437. signers will return their certificate chain in leaf-to-root order).
  3438. Prefer using the credential bundle format, since your application code
  3439. can read it atomically. If you use keyPath and certificateChainPath,
  3440. your application must make two separate file reads. If these coincide
  3441. with a certificate rotation, it is possible that the private key and leaf
  3442. certificate you read may not correspond to each other. Your application
  3443. will need to check for this condition, and re-read until they are
  3444. consistent.
  3445. The named signer controls chooses the format of the certificate it
  3446. issues; consult the signer implementation's documentation to learn how to
  3447. use the certificates it issues.
  3448. properties:
  3449. certificateChainPath:
  3450. description: |-
  3451. Write the certificate chain at this path in the projected volume.
  3452. Most applications should use credentialBundlePath. When using keyPath
  3453. and certificateChainPath, your application needs to check that the key
  3454. and leaf certificate are consistent, because it is possible to read the
  3455. files mid-rotation.
  3456. type: string
  3457. credentialBundlePath:
  3458. description: |-
  3459. Write the credential bundle at this path in the projected volume.
  3460. The credential bundle is a single file that contains multiple PEM blocks.
  3461. The first PEM block is a PRIVATE KEY block, containing a PKCS#8 private
  3462. key.
  3463. The remaining blocks are CERTIFICATE blocks, containing the issued
  3464. certificate chain from the signer (leaf and any intermediates).
  3465. Using credentialBundlePath lets your Pod's application code make a single
  3466. atomic read that retrieves a consistent key and certificate chain. If you
  3467. project them to separate files, your application code will need to
  3468. additionally check that the leaf certificate was issued to the key.
  3469. type: string
  3470. keyPath:
  3471. description: |-
  3472. Write the key at this path in the projected volume.
  3473. Most applications should use credentialBundlePath. When using keyPath
  3474. and certificateChainPath, your application needs to check that the key
  3475. and leaf certificate are consistent, because it is possible to read the
  3476. files mid-rotation.
  3477. type: string
  3478. keyType:
  3479. description: |-
  3480. The type of keypair Kubelet will generate for the pod.
  3481. Valid values are "RSA3072", "RSA4096", "ECDSAP256", "ECDSAP384",
  3482. "ECDSAP521", and "ED25519".
  3483. type: string
  3484. maxExpirationSeconds:
  3485. description: |-
  3486. maxExpirationSeconds is the maximum lifetime permitted for the
  3487. certificate.
  3488. Kubelet copies this value verbatim into the PodCertificateRequests it
  3489. generates for this projection.
  3490. If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver
  3491. will reject values shorter than 3600 (1 hour). The maximum allowable
  3492. value is 7862400 (91 days).
  3493. The signer implementation is then free to issue a certificate with any
  3494. lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600
  3495. seconds (1 hour). This constraint is enforced by kube-apiserver.
  3496. `kubernetes.io` signers will never issue certificates with a lifetime
  3497. longer than 24 hours.
  3498. format: int32
  3499. type: integer
  3500. signerName:
  3501. description: Kubelet's generated CSRs
  3502. will be addressed to this signer.
  3503. type: string
  3504. userAnnotations:
  3505. additionalProperties:
  3506. type: string
  3507. description: |-
  3508. userAnnotations allow pod authors to pass additional information to
  3509. the signer implementation. Kubernetes does not restrict or validate this
  3510. metadata in any way.
  3511. These values are copied verbatim into the `spec.unverifiedUserAnnotations` field of
  3512. the PodCertificateRequest objects that Kubelet creates.
  3513. Entries are subject to the same validation as object metadata annotations,
  3514. with the addition that all keys must be domain-prefixed. No restrictions
  3515. are placed on values, except an overall size limitation on the entire field.
  3516. Signers should document the keys and values they support. Signers should
  3517. deny requests that contain keys they do not recognize.
  3518. type: object
  3519. required:
  3520. - keyType
  3521. - signerName
  3522. type: object
  3523. secret:
  3524. description: secret information about the
  3525. secret data to project
  3526. properties:
  3527. items:
  3528. description: |-
  3529. items if unspecified, each key-value pair in the Data field of the referenced
  3530. Secret will be projected into the volume as a file whose name is the
  3531. key and content is the value. If specified, the listed keys will be
  3532. projected into the specified paths, and unlisted keys will not be
  3533. present. If a key is specified which is not present in the Secret,
  3534. the volume setup will error unless it is marked optional. Paths must be
  3535. relative and may not contain the '..' path or start with '..'.
  3536. items:
  3537. description: Maps a string key to a
  3538. path within a volume.
  3539. properties:
  3540. key:
  3541. description: key is the key to project.
  3542. type: string
  3543. mode:
  3544. description: |-
  3545. mode is Optional: mode bits used to set permissions on this file.
  3546. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  3547. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  3548. If not specified, the volume defaultMode will be used.
  3549. This might be in conflict with other options that affect the file
  3550. mode, like fsGroup, and the result can be other mode bits set.
  3551. format: int32
  3552. type: integer
  3553. path:
  3554. description: |-
  3555. path is the relative path of the file to map the key to.
  3556. May not be an absolute path.
  3557. May not contain the path element '..'.
  3558. May not start with the string '..'.
  3559. type: string
  3560. required:
  3561. - key
  3562. - path
  3563. type: object
  3564. type: array
  3565. x-kubernetes-list-type: atomic
  3566. name:
  3567. default: ""
  3568. description: |-
  3569. Name of the referent.
  3570. This field is effectively required, but due to backwards compatibility is
  3571. allowed to be empty. Instances of this type with an empty value here are
  3572. almost certainly wrong.
  3573. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3574. type: string
  3575. optional:
  3576. description: optional field specify whether
  3577. the Secret or its key must be defined
  3578. type: boolean
  3579. type: object
  3580. x-kubernetes-map-type: atomic
  3581. serviceAccountToken:
  3582. description: serviceAccountToken is information
  3583. about the serviceAccountToken data to project
  3584. properties:
  3585. audience:
  3586. description: |-
  3587. audience is the intended audience of the token. A recipient of a token
  3588. must identify itself with an identifier specified in the audience of the
  3589. token, and otherwise should reject the token. The audience defaults to the
  3590. identifier of the apiserver.
  3591. type: string
  3592. expirationSeconds:
  3593. description: |-
  3594. expirationSeconds is the requested duration of validity of the service
  3595. account token. As the token approaches expiration, the kubelet volume
  3596. plugin will proactively rotate the service account token. The kubelet will
  3597. start trying to rotate the token if the token is older than 80 percent of
  3598. its time to live or if the token is older than 24 hours.Defaults to 1 hour
  3599. and must be at least 10 minutes.
  3600. format: int64
  3601. type: integer
  3602. path:
  3603. description: |-
  3604. path is the path relative to the mount point of the file to project the
  3605. token into.
  3606. type: string
  3607. required:
  3608. - path
  3609. type: object
  3610. type: object
  3611. type: array
  3612. x-kubernetes-list-type: atomic
  3613. type: object
  3614. quobyte:
  3615. description: |-
  3616. quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
  3617. Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer supported.
  3618. properties:
  3619. group:
  3620. description: |-
  3621. group to map volume access to
  3622. Default is no group
  3623. type: string
  3624. readOnly:
  3625. description: |-
  3626. readOnly here will force the Quobyte volume to be mounted with read-only permissions.
  3627. Defaults to false.
  3628. type: boolean
  3629. registry:
  3630. description: |-
  3631. registry represents a single or multiple Quobyte Registry services
  3632. specified as a string as host:port pair (multiple entries are separated with commas)
  3633. which acts as the central registry for volumes
  3634. type: string
  3635. tenant:
  3636. description: |-
  3637. tenant owning the given Quobyte volume in the Backend
  3638. Used with dynamically provisioned Quobyte volumes, value is set by the plugin
  3639. type: string
  3640. user:
  3641. description: |-
  3642. user to map volume access to
  3643. Defaults to serivceaccount user
  3644. type: string
  3645. volume:
  3646. description: volume is a string that references
  3647. an already created Quobyte volume by name.
  3648. type: string
  3649. required:
  3650. - registry
  3651. - volume
  3652. type: object
  3653. rbd:
  3654. description: |-
  3655. rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.
  3656. Deprecated: RBD is deprecated and the in-tree rbd type is no longer supported.
  3657. properties:
  3658. fsType:
  3659. description: |-
  3660. fsType is the filesystem type of the volume that you want to mount.
  3661. Tip: Ensure that the filesystem type is supported by the host operating system.
  3662. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  3663. More info: https://kubernetes.io/docs/concepts/storage/volumes#rbd
  3664. type: string
  3665. image:
  3666. description: |-
  3667. image is the rados image name.
  3668. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3669. type: string
  3670. keyring:
  3671. default: /etc/ceph/keyring
  3672. description: |-
  3673. keyring is the path to key ring for RBDUser.
  3674. Default is /etc/ceph/keyring.
  3675. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3676. type: string
  3677. monitors:
  3678. description: |-
  3679. monitors is a collection of Ceph monitors.
  3680. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3681. items:
  3682. type: string
  3683. type: array
  3684. x-kubernetes-list-type: atomic
  3685. pool:
  3686. default: rbd
  3687. description: |-
  3688. pool is the rados pool name.
  3689. Default is rbd.
  3690. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3691. type: string
  3692. readOnly:
  3693. description: |-
  3694. readOnly here will force the ReadOnly setting in VolumeMounts.
  3695. Defaults to false.
  3696. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3697. type: boolean
  3698. secretRef:
  3699. description: |-
  3700. secretRef is name of the authentication secret for RBDUser. If provided
  3701. overrides keyring.
  3702. Default is nil.
  3703. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3704. properties:
  3705. name:
  3706. default: ""
  3707. description: |-
  3708. Name of the referent.
  3709. This field is effectively required, but due to backwards compatibility is
  3710. allowed to be empty. Instances of this type with an empty value here are
  3711. almost certainly wrong.
  3712. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3713. type: string
  3714. type: object
  3715. x-kubernetes-map-type: atomic
  3716. user:
  3717. default: admin
  3718. description: |-
  3719. user is the rados user name.
  3720. Default is admin.
  3721. More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
  3722. type: string
  3723. required:
  3724. - image
  3725. - monitors
  3726. type: object
  3727. scaleIO:
  3728. description: |-
  3729. scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes nodes.
  3730. Deprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer supported.
  3731. properties:
  3732. fsType:
  3733. default: xfs
  3734. description: |-
  3735. fsType is the filesystem type to mount.
  3736. Must be a filesystem type supported by the host operating system.
  3737. Ex. "ext4", "xfs", "ntfs".
  3738. Default is "xfs".
  3739. type: string
  3740. gateway:
  3741. description: gateway is the host address of the
  3742. ScaleIO API Gateway.
  3743. type: string
  3744. protectionDomain:
  3745. description: protectionDomain is the name of the
  3746. ScaleIO Protection Domain for the configured storage.
  3747. type: string
  3748. readOnly:
  3749. description: |-
  3750. readOnly Defaults to false (read/write). ReadOnly here will force
  3751. the ReadOnly setting in VolumeMounts.
  3752. type: boolean
  3753. secretRef:
  3754. description: |-
  3755. secretRef references to the secret for ScaleIO user and other
  3756. sensitive information. If this is not provided, Login operation will fail.
  3757. properties:
  3758. name:
  3759. default: ""
  3760. description: |-
  3761. Name of the referent.
  3762. This field is effectively required, but due to backwards compatibility is
  3763. allowed to be empty. Instances of this type with an empty value here are
  3764. almost certainly wrong.
  3765. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3766. type: string
  3767. type: object
  3768. x-kubernetes-map-type: atomic
  3769. sslEnabled:
  3770. description: sslEnabled Flag enable/disable SSL
  3771. communication with Gateway, default false
  3772. type: boolean
  3773. storageMode:
  3774. default: ThinProvisioned
  3775. description: |-
  3776. storageMode indicates whether the storage for a volume should be ThickProvisioned or ThinProvisioned.
  3777. Default is ThinProvisioned.
  3778. type: string
  3779. storagePool:
  3780. description: storagePool is the ScaleIO Storage
  3781. Pool associated with the protection domain.
  3782. type: string
  3783. system:
  3784. description: system is the name of the storage system
  3785. as configured in ScaleIO.
  3786. type: string
  3787. volumeName:
  3788. description: |-
  3789. volumeName is the name of a volume already created in the ScaleIO system
  3790. that is associated with this volume source.
  3791. type: string
  3792. required:
  3793. - gateway
  3794. - secretRef
  3795. - system
  3796. type: object
  3797. secret:
  3798. description: |-
  3799. secret represents a secret that should populate this volume.
  3800. More info: https://kubernetes.io/docs/concepts/storage/volumes#secret
  3801. properties:
  3802. defaultMode:
  3803. description: |-
  3804. defaultMode is Optional: mode bits used to set permissions on created files by default.
  3805. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  3806. YAML accepts both octal and decimal values, JSON requires decimal values
  3807. for mode bits. Defaults to 0644.
  3808. Directories within the path are not affected by this setting.
  3809. This might be in conflict with other options that affect the file
  3810. mode, like fsGroup, and the result can be other mode bits set.
  3811. format: int32
  3812. type: integer
  3813. items:
  3814. description: |-
  3815. items If unspecified, each key-value pair in the Data field of the referenced
  3816. Secret will be projected into the volume as a file whose name is the
  3817. key and content is the value. If specified, the listed keys will be
  3818. projected into the specified paths, and unlisted keys will not be
  3819. present. If a key is specified which is not present in the Secret,
  3820. the volume setup will error unless it is marked optional. Paths must be
  3821. relative and may not contain the '..' path or start with '..'.
  3822. items:
  3823. description: Maps a string key to a path within
  3824. a volume.
  3825. properties:
  3826. key:
  3827. description: key is the key to project.
  3828. type: string
  3829. mode:
  3830. description: |-
  3831. mode is Optional: mode bits used to set permissions on this file.
  3832. Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
  3833. YAML accepts both octal and decimal values, JSON requires decimal values for mode bits.
  3834. If not specified, the volume defaultMode will be used.
  3835. This might be in conflict with other options that affect the file
  3836. mode, like fsGroup, and the result can be other mode bits set.
  3837. format: int32
  3838. type: integer
  3839. path:
  3840. description: |-
  3841. path is the relative path of the file to map the key to.
  3842. May not be an absolute path.
  3843. May not contain the path element '..'.
  3844. May not start with the string '..'.
  3845. type: string
  3846. required:
  3847. - key
  3848. - path
  3849. type: object
  3850. type: array
  3851. x-kubernetes-list-type: atomic
  3852. optional:
  3853. description: optional field specify whether the
  3854. Secret or its keys must be defined
  3855. type: boolean
  3856. secretName:
  3857. description: |-
  3858. secretName is the name of the secret in the pod's namespace to use.
  3859. More info: https://kubernetes.io/docs/concepts/storage/volumes#secret
  3860. type: string
  3861. type: object
  3862. storageos:
  3863. description: |-
  3864. storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.
  3865. Deprecated: StorageOS is deprecated and the in-tree storageos type is no longer supported.
  3866. properties:
  3867. fsType:
  3868. description: |-
  3869. fsType is the filesystem type to mount.
  3870. Must be a filesystem type supported by the host operating system.
  3871. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  3872. type: string
  3873. readOnly:
  3874. description: |-
  3875. readOnly defaults to false (read/write). ReadOnly here will force
  3876. the ReadOnly setting in VolumeMounts.
  3877. type: boolean
  3878. secretRef:
  3879. description: |-
  3880. secretRef specifies the secret to use for obtaining the StorageOS API
  3881. credentials. If not specified, default values will be attempted.
  3882. properties:
  3883. name:
  3884. default: ""
  3885. description: |-
  3886. Name of the referent.
  3887. This field is effectively required, but due to backwards compatibility is
  3888. allowed to be empty. Instances of this type with an empty value here are
  3889. almost certainly wrong.
  3890. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  3891. type: string
  3892. type: object
  3893. x-kubernetes-map-type: atomic
  3894. volumeName:
  3895. description: |-
  3896. volumeName is the human-readable name of the StorageOS volume. Volume
  3897. names are only unique within a namespace.
  3898. type: string
  3899. volumeNamespace:
  3900. description: |-
  3901. volumeNamespace specifies the scope of the volume within StorageOS. If no
  3902. namespace is specified then the Pod's namespace will be used. This allows the
  3903. Kubernetes name scoping to be mirrored within StorageOS for tighter integration.
  3904. Set VolumeName to any name to override the default behaviour.
  3905. Set to "default" if you are not using namespaces within StorageOS.
  3906. Namespaces that do not pre-exist within StorageOS will be created.
  3907. type: string
  3908. type: object
  3909. vsphereVolume:
  3910. description: |-
  3911. vsphereVolume represents a vSphere volume attached and mounted on kubelets host machine.
  3912. Deprecated: VsphereVolume is deprecated. All operations for the in-tree vsphereVolume type
  3913. are redirected to the csi.vsphere.vmware.com CSI driver.
  3914. properties:
  3915. fsType:
  3916. description: |-
  3917. fsType is filesystem type to mount.
  3918. Must be a filesystem type supported by the host operating system.
  3919. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified.
  3920. type: string
  3921. storagePolicyID:
  3922. description: storagePolicyID is the storage Policy
  3923. Based Management (SPBM) profile ID associated
  3924. with the StoragePolicyName.
  3925. type: string
  3926. storagePolicyName:
  3927. description: storagePolicyName is the storage Policy
  3928. Based Management (SPBM) profile name.
  3929. type: string
  3930. volumePath:
  3931. description: volumePath is the path that identifies
  3932. vSphere volume vmdk
  3933. type: string
  3934. required:
  3935. - volumePath
  3936. type: object
  3937. required:
  3938. - name
  3939. type: object
  3940. type: array
  3941. type: object
  3942. required:
  3943. - name
  3944. type: object
  3945. toolName:
  3946. description: toolName is the logical name for this tool as seen by
  3947. the gateway and agents.
  3948. type: string
  3949. transport:
  3950. default: http
  3951. description: transport is the MCP transport protocol spoken by the
  3952. managed server.
  3953. enum:
  3954. - sse
  3955. - http
  3956. type: string
  3957. required:
  3958. - toolName
  3959. type: object
  3960. status:
  3961. description: status defines the observed state of ManagedTool
  3962. properties:
  3963. conditions:
  3964. description: |-
  3965. conditions represent the current state of the ManagedTool resource.
  3966. Each condition has a unique type and reflects the status of a specific aspect of the resource.
  3967. Standard condition types include:
  3968. - "Available": the resource is fully functional
  3969. - "Progressing": the resource is being created or updated
  3970. - "Degraded": the resource failed to reach or maintain its desired state
  3971. The status of each condition is one of True, False, or Unknown.
  3972. items:
  3973. description: Condition contains details for one aspect of the current
  3974. state of this API Resource.
  3975. properties:
  3976. lastTransitionTime:
  3977. description: |-
  3978. lastTransitionTime is the last time the condition transitioned from one status to another.
  3979. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
  3980. format: date-time
  3981. type: string
  3982. message:
  3983. description: |-
  3984. message is a human readable message indicating details about the transition.
  3985. This may be an empty string.
  3986. maxLength: 32768
  3987. type: string
  3988. observedGeneration:
  3989. description: |-
  3990. observedGeneration represents the .metadata.generation that the condition was set based upon.
  3991. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
  3992. with respect to the current state of the instance.
  3993. format: int64
  3994. minimum: 0
  3995. type: integer
  3996. reason:
  3997. description: |-
  3998. reason contains a programmatic identifier indicating the reason for the condition's last transition.
  3999. Producers of specific condition types may define expected values and meanings for this field,
  4000. and whether the values are considered a guaranteed API.
  4001. The value should be a CamelCase string.
  4002. This field may not be empty.
  4003. maxLength: 1024
  4004. minLength: 1
  4005. pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
  4006. type: string
  4007. status:
  4008. description: status of the condition, one of True, False, Unknown.
  4009. enum:
  4010. - "True"
  4011. - "False"
  4012. - Unknown
  4013. type: string
  4014. type:
  4015. description: type of condition in CamelCase or in foo.example.com/CamelCase.
  4016. maxLength: 316
  4017. pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
  4018. type: string
  4019. required:
  4020. - lastTransitionTime
  4021. - message
  4022. - reason
  4023. - status
  4024. - type
  4025. type: object
  4026. type: array
  4027. x-kubernetes-list-map-keys:
  4028. - type
  4029. x-kubernetes-list-type: map
  4030. endpoint:
  4031. description: endpoint is the URL where the tool can be accessed for
  4032. MCP requests.
  4033. type: string
  4034. observedGeneration:
  4035. description: observedGeneration is the .metadata.generation last reconciled.
  4036. format: int64
  4037. type: integer
  4038. type: object
  4039. required:
  4040. - spec
  4041. type: object
  4042. served: true
  4043. storage: true
  4044. subresources:
  4045. status: {}