mirror of
https://github.com/YuzuZensai/netbird-kubernetes-operator.git
synced 2026-09-13 18:59:09 +00:00
c858d03cf1
Bumps [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) from 0.23.3 to 0.24.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/kubernetes-sigs/controller-runtime/releases">sigs.k8s.io/controller-runtime's releases</a>.</em></p> <blockquote> <h2>v0.24.0</h2> <h2>⚠️ Breaking Changes</h2> <ul> <li>Dependencies: Update to k8s.io/* v1.36 (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3506">#3506</a> <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3462">#3462</a> <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3486">#3486</a> <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3450">#3450</a>)</li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li>Cache: Fix IndexField blocking until informer is synced (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3445">#3445</a>)</li> <li>Cache: Wait for cache sync when ReaderFailOnMissingInformer is true (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3425">#3425</a>)</li> <li>Client: Update typed ApplyConfigurations with server response (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3475">#3475</a>)</li> <li>Fakeclient: Fix SSA status patch resource version check (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3443">#3443</a>)</li> <li>Fakeclient: Fix panic when using CRs with embedded pointer structs (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3431">#3431</a>)</li> <li>Fakeclient: Fix status apply if existing object has managedFields set (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3430">#3430</a>)</li> <li>Fakeclient: Retry GenerateName on AlreadyExists collisions (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3498">#3498</a>)</li> <li>HTTP servers: Wire up base context into http servers (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3452">#3452</a>)</li> </ul> <h2>🌱 Others</h2> <ul> <li>Builder/Webhooks: Remove deprecated custom path function (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3465">#3465</a>)</li> <li>Cache: Test cache reader waits for cache sync (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3434">#3434</a>)</li> <li>Certwatcher: Deflake certwatcher tests (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3457">#3457</a>)</li> <li>Dependencies: Use forked version of btree (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3449">#3449</a>)</li> <li>Envtest: Ensure envtest stops the whole process group (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3447">#3447</a>)</li> <li>Logging: Add missing space in zap-log-level flag description (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3492">#3492</a>)</li> <li>Misc: Adopt new(x) over ptr.To(x) and re-enable newexpr lint (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3489">#3489</a>)</li> <li>Owners: Cleanup (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3453">#3453</a>)</li> <li>Recorder: Add logger into context for structured logging (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3454">#3454</a>)</li> <li>Recorder: Switch to <code>StartLogging</code> for event debug logs (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3451">#3451</a>)</li> <li>Scheme: Deprecate the scheme builder (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3461">#3461</a>)</li> <li>Source/Kind: Improve logging for dynamic type kind source (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3494">#3494</a>)</li> <li>Webhooks: Reduce memory usage of default webhooks (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3463">#3463</a> <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3468">#3468</a>)</li> </ul> <h2>🌱 CI & linters</h2> <ul> <li>Chore: Update golangci-lint version to v2.8.0 (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3448">#3448</a>)</li> <li>Chore: Update golangci-lint version to v2.10.1 (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3470">#3470</a>)</li> <li>Chore: Update golangci-lint version to v2.11.3 (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3482">#3482</a>)</li> <li>Migrate away from custom GitHub action approval workflow (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3491">#3491</a>)</li> <li>Release: Auto-create git tags for the <code>tools/setup-envtest</code> submodule (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3476">#3476</a>)</li> </ul> <p>📖 Additionally, there has been 1 contribution to our documentation. (<a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3477">#3477</a>)</p> <h2>Dependencies</h2> <h3>Added</h3> <ul> <li>github.com/cenkalti/backoff/v5: <a href="https://github.com/cenkalti/backoff/tree/v5.0.3">v5.0.3</a></li> <li>gonum.org/v1/gonum: v0.16.0</li> <li>k8s.io/streaming: v0.36.0</li> </ul> <h3>Changed</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/d3eaef3ab45410342c30528d1eaab982137c4d5a"><code>d3eaef3</code></a> Merge pull request <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3475">#3475</a> from alvaroaleman/fixfix</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/3296f32e58d6e578aa1932dc5584411c5f25c3db"><code>3296f32</code></a> 🐛 Update typed Applyconfigurations with server response</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/c8b4b9d61fbddd8924c1075ec2face3aa7a5f768"><code>c8b4b9d</code></a> Merge pull request <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3506">#3506</a> from troy0820/troy0820/update-deps-k8s</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/557c3147e26a62272c87db88e3aadda9890931f1"><code>557c314</code></a> update to k8s.io v1.36.0</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/e4a998cc6b09afaf5f2d7f30b6a9b728f21918a3"><code>e4a998c</code></a> Merge pull request <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3499">#3499</a> from kubernetes-sigs/dependabot/github_actions/all-g...</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/1a31c56032fa26cd09de18a6c64b1ba86614f4a4"><code>1a31c56</code></a> Merge pull request <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3498">#3498</a> from vieux/fix-fake-client-generatename-retry</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/80bc294688dda063f418bb38e72089ab9f857cc0"><code>80bc294</code></a> fakeclient: retry GenerateName on AlreadyExists collisions (match K8s 1.32 be...</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/77b730ab1c9b09af172b67a336886558211b493a"><code>77b730a</code></a> 🌱 Bump the all-github-actions group with 2 updates</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/6210f847b2c1df3f28e5be34a4b1458f03896c73"><code>6210f84</code></a> Merge pull request <a href="https://redirect.github.com/kubernetes-sigs/controller-runtime/issues/3494">#3494</a> from erikgb/improve-kind-source-logging</li> <li><a href="https://github.com/kubernetes-sigs/controller-runtime/commit/6f89e1d9d45867133034b829fb1a3e3563b5065d"><code>6f89e1d</code></a> Improve logging for dynamic type kind source</li> <li>Additional commits viewable in <a href="https://github.com/kubernetes-sigs/controller-runtime/compare/v0.23.3...v0.24.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Philip Laine <philip.laine@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
551 lines
30 KiB
YAML
551 lines
30 KiB
YAML
---
|
|
apiVersion: apiextensions.k8s.io/v1
|
|
kind: CustomResourceDefinition
|
|
metadata:
|
|
annotations:
|
|
controller-gen.kubebuilder.io/version: v0.20.1
|
|
name: sidecarprofiles.netbird.io
|
|
spec:
|
|
group: netbird.io
|
|
names:
|
|
kind: SidecarProfile
|
|
listKind: SidecarProfileList
|
|
plural: sidecarprofiles
|
|
singular: sidecarprofile
|
|
scope: Namespaced
|
|
versions:
|
|
- name: v1alpha1
|
|
schema:
|
|
openAPIV3Schema:
|
|
description: SidecarProfile is the Schema for the sidecarprofiles API.
|
|
properties:
|
|
apiVersion:
|
|
description: |-
|
|
APIVersion defines the versioned schema of this representation of an object.
|
|
Servers should convert recognized schemas to the latest internal value, and
|
|
may reject unrecognized values.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
kind:
|
|
description: |-
|
|
Kind is a string value representing the REST resource this object represents.
|
|
Servers may infer this from the endpoint the client submits requests to.
|
|
Cannot be updated.
|
|
In CamelCase.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
type: object
|
|
spec:
|
|
description: SidecarProfileSpec defines the desired state of SidecarProfile.
|
|
properties:
|
|
containerOverride:
|
|
properties:
|
|
env:
|
|
items:
|
|
description: EnvVar represents an environment variable present
|
|
in a Container.
|
|
properties:
|
|
name:
|
|
description: |-
|
|
Name of the environment variable.
|
|
May consist of any printable ASCII characters except '='.
|
|
type: string
|
|
value:
|
|
description: |-
|
|
Variable references $(VAR_NAME) are expanded
|
|
using the previously defined environment variables in the container and
|
|
any service environment variables. If a variable cannot be resolved,
|
|
the reference in the input string will be unchanged. Double $$ are reduced
|
|
to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.
|
|
"$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)".
|
|
Escaped references will never be expanded, regardless of whether the variable
|
|
exists or not.
|
|
Defaults to "".
|
|
type: string
|
|
valueFrom:
|
|
description: Source for the environment variable's value.
|
|
Cannot be used if value is not empty.
|
|
properties:
|
|
configMapKeyRef:
|
|
description: Selects a key of a ConfigMap.
|
|
properties:
|
|
key:
|
|
description: The key to select.
|
|
type: string
|
|
name:
|
|
default: ""
|
|
description: |-
|
|
Name of the referent.
|
|
This field is effectively required, but due to backwards compatibility is
|
|
allowed to be empty. Instances of this type with an empty value here are
|
|
almost certainly wrong.
|
|
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
|
|
type: string
|
|
optional:
|
|
description: Specify whether the ConfigMap or its
|
|
key must be defined
|
|
type: boolean
|
|
required:
|
|
- key
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
fieldRef:
|
|
description: |-
|
|
Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`,
|
|
spec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
|
|
properties:
|
|
apiVersion:
|
|
description: Version of the schema the FieldPath
|
|
is written in terms of, defaults to "v1".
|
|
type: string
|
|
fieldPath:
|
|
description: Path of the field to select in the
|
|
specified API version.
|
|
type: string
|
|
required:
|
|
- fieldPath
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
fileKeyRef:
|
|
description: |-
|
|
FileKeyRef selects a key of the env file.
|
|
Requires the EnvFiles feature gate to be enabled.
|
|
properties:
|
|
key:
|
|
description: |-
|
|
The key within the env file. An invalid key will prevent the pod from starting.
|
|
The keys defined within a source may consist of any printable ASCII characters except '='.
|
|
During Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.
|
|
type: string
|
|
optional:
|
|
default: false
|
|
description: |-
|
|
Specify whether the file or its key must be defined. If the file or key
|
|
does not exist, then the env var is not published.
|
|
If optional is set to true and the specified key does not exist,
|
|
the environment variable will not be set in the Pod's containers.
|
|
|
|
If optional is set to false and the specified key does not exist,
|
|
an error will be returned during Pod creation.
|
|
type: boolean
|
|
path:
|
|
description: |-
|
|
The path within the volume from which to select the file.
|
|
Must be relative and may not contain the '..' path or start with '..'.
|
|
type: string
|
|
volumeName:
|
|
description: The name of the volume mount containing
|
|
the env file.
|
|
type: string
|
|
required:
|
|
- key
|
|
- path
|
|
- volumeName
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
resourceFieldRef:
|
|
description: |-
|
|
Selects a resource of the container: only resources limits and requests
|
|
(limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.
|
|
properties:
|
|
containerName:
|
|
description: 'Container name: required for volumes,
|
|
optional for env vars'
|
|
type: string
|
|
divisor:
|
|
anyOf:
|
|
- type: integer
|
|
- type: string
|
|
description: Specifies the output format of the
|
|
exposed resources, defaults to "1"
|
|
pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
|
|
x-kubernetes-int-or-string: true
|
|
resource:
|
|
description: 'Required: resource to select'
|
|
type: string
|
|
required:
|
|
- resource
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
secretKeyRef:
|
|
description: Selects a key of a secret in the pod's
|
|
namespace
|
|
properties:
|
|
key:
|
|
description: The key of the secret to select from. Must
|
|
be a valid secret key.
|
|
type: string
|
|
name:
|
|
default: ""
|
|
description: |-
|
|
Name of the referent.
|
|
This field is effectively required, but due to backwards compatibility is
|
|
allowed to be empty. Instances of this type with an empty value here are
|
|
almost certainly wrong.
|
|
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
|
|
type: string
|
|
optional:
|
|
description: Specify whether the Secret or its key
|
|
must be defined
|
|
type: boolean
|
|
required:
|
|
- key
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
type: object
|
|
required:
|
|
- name
|
|
type: object
|
|
type: array
|
|
image:
|
|
description: Image overrides the image used by the client.
|
|
type: string
|
|
securityContext:
|
|
description: |-
|
|
SecurityContext holds security configuration that will be applied to a container.
|
|
Some fields are present in both SecurityContext and PodSecurityContext. When both
|
|
are set, the values in SecurityContext take precedence.
|
|
properties:
|
|
allowPrivilegeEscalation:
|
|
description: |-
|
|
AllowPrivilegeEscalation controls whether a process can gain more
|
|
privileges than its parent process. This bool directly controls if
|
|
the no_new_privs flag will be set on the container process.
|
|
AllowPrivilegeEscalation is true always when the container is:
|
|
1) run as Privileged
|
|
2) has CAP_SYS_ADMIN
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
type: boolean
|
|
appArmorProfile:
|
|
description: |-
|
|
appArmorProfile is the AppArmor options to use by this container. If set, this profile
|
|
overrides the pod's appArmorProfile.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
properties:
|
|
localhostProfile:
|
|
description: |-
|
|
localhostProfile indicates a profile loaded on the node that should be used.
|
|
The profile must be preconfigured on the node to work.
|
|
Must match the loaded name of the profile.
|
|
Must be set if and only if type is "Localhost".
|
|
type: string
|
|
type:
|
|
description: |-
|
|
type indicates which kind of AppArmor profile will be applied.
|
|
Valid options are:
|
|
Localhost - a profile pre-loaded on the node.
|
|
RuntimeDefault - the container runtime's default profile.
|
|
Unconfined - no AppArmor enforcement.
|
|
type: string
|
|
required:
|
|
- type
|
|
type: object
|
|
capabilities:
|
|
description: |-
|
|
The capabilities to add/drop when running containers.
|
|
Defaults to the default set of capabilities granted by the container runtime.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
properties:
|
|
add:
|
|
description: Added capabilities
|
|
items:
|
|
description: Capability represent POSIX capabilities
|
|
type
|
|
type: string
|
|
type: array
|
|
x-kubernetes-list-type: atomic
|
|
drop:
|
|
description: Removed capabilities
|
|
items:
|
|
description: Capability represent POSIX capabilities
|
|
type
|
|
type: string
|
|
type: array
|
|
x-kubernetes-list-type: atomic
|
|
type: object
|
|
privileged:
|
|
description: |-
|
|
Run container in privileged mode.
|
|
Processes in privileged containers are essentially equivalent to root on the host.
|
|
Defaults to false.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
type: boolean
|
|
procMount:
|
|
description: |-
|
|
procMount denotes the type of proc mount to use for the containers.
|
|
The default value is Default which uses the container runtime defaults for
|
|
readonly paths and masked paths.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
type: string
|
|
readOnlyRootFilesystem:
|
|
description: |-
|
|
Whether this container has a read-only root filesystem.
|
|
Default is false.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
type: boolean
|
|
runAsGroup:
|
|
description: |-
|
|
The GID to run the entrypoint of the container process.
|
|
Uses runtime default if unset.
|
|
May also be set in PodSecurityContext. If set in both SecurityContext and
|
|
PodSecurityContext, the value specified in SecurityContext takes precedence.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
format: int64
|
|
type: integer
|
|
runAsNonRoot:
|
|
description: |-
|
|
Indicates that the container must run as a non-root user.
|
|
If true, the Kubelet will validate the image at runtime to ensure that it
|
|
does not run as UID 0 (root) and fail to start the container if it does.
|
|
If unset or false, no such validation will be performed.
|
|
May also be set in PodSecurityContext. If set in both SecurityContext and
|
|
PodSecurityContext, the value specified in SecurityContext takes precedence.
|
|
type: boolean
|
|
runAsUser:
|
|
description: |-
|
|
The UID to run the entrypoint of the container process.
|
|
Defaults to user specified in image metadata if unspecified.
|
|
May also be set in PodSecurityContext. If set in both SecurityContext and
|
|
PodSecurityContext, the value specified in SecurityContext takes precedence.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
format: int64
|
|
type: integer
|
|
seLinuxOptions:
|
|
description: |-
|
|
The SELinux context to be applied to the container.
|
|
If unspecified, the container runtime will allocate a random SELinux context for each
|
|
container. May also be set in PodSecurityContext. If set in both SecurityContext and
|
|
PodSecurityContext, the value specified in SecurityContext takes precedence.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
properties:
|
|
level:
|
|
description: Level is SELinux level label that applies
|
|
to the container.
|
|
type: string
|
|
role:
|
|
description: Role is a SELinux role label that applies
|
|
to the container.
|
|
type: string
|
|
type:
|
|
description: Type is a SELinux type label that applies
|
|
to the container.
|
|
type: string
|
|
user:
|
|
description: User is a SELinux user label that applies
|
|
to the container.
|
|
type: string
|
|
type: object
|
|
seccompProfile:
|
|
description: |-
|
|
The seccomp options to use by this container. If seccomp options are
|
|
provided at both the pod & container level, the container options
|
|
override the pod options.
|
|
Note that this field cannot be set when spec.os.name is windows.
|
|
properties:
|
|
localhostProfile:
|
|
description: |-
|
|
localhostProfile indicates a profile defined in a file on the node should be used.
|
|
The profile must be preconfigured on the node to work.
|
|
Must be a descending path, relative to the kubelet's configured seccomp profile location.
|
|
Must be set if type is "Localhost". Must NOT be set for any other type.
|
|
type: string
|
|
type:
|
|
description: |-
|
|
type indicates which kind of seccomp profile will be applied.
|
|
Valid options are:
|
|
|
|
Localhost - a profile defined in a file on the node should be used.
|
|
RuntimeDefault - the container runtime default profile should be used.
|
|
Unconfined - no profile should be applied.
|
|
type: string
|
|
required:
|
|
- type
|
|
type: object
|
|
windowsOptions:
|
|
description: |-
|
|
The Windows specific settings applied to all containers.
|
|
If unspecified, the options from the PodSecurityContext will be used.
|
|
If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence.
|
|
Note that this field cannot be set when spec.os.name is linux.
|
|
properties:
|
|
gmsaCredentialSpec:
|
|
description: |-
|
|
GMSACredentialSpec is where the GMSA admission webhook
|
|
(https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the
|
|
GMSA credential spec named by the GMSACredentialSpecName field.
|
|
type: string
|
|
gmsaCredentialSpecName:
|
|
description: GMSACredentialSpecName is the name of the
|
|
GMSA credential spec to use.
|
|
type: string
|
|
hostProcess:
|
|
description: |-
|
|
HostProcess determines if a container should be run as a 'Host Process' container.
|
|
All of a Pod's containers must have the same effective HostProcess value
|
|
(it is not allowed to have a mix of HostProcess containers and non-HostProcess containers).
|
|
In addition, if HostProcess is true then HostNetwork must also be set to true.
|
|
type: boolean
|
|
runAsUserName:
|
|
description: |-
|
|
The UserName in Windows to run the entrypoint of the container process.
|
|
Defaults to the user specified in image metadata if unspecified.
|
|
May also be set in PodSecurityContext. If set in both SecurityContext and
|
|
PodSecurityContext, the value specified in SecurityContext takes precedence.
|
|
type: string
|
|
type: object
|
|
type: object
|
|
type: object
|
|
extraDNSLabels:
|
|
description: ExtraDNSLabels assigns additional DNS names to peers
|
|
beyond their default hostname.
|
|
items:
|
|
type: string
|
|
type: array
|
|
injectionMode:
|
|
default: Sidecar
|
|
description: InjectionMode defines whether the sidecar is injected
|
|
as a native Kubernetes sidecar container or as a regular container.
|
|
enum:
|
|
- Sidecar
|
|
- Container
|
|
type: string
|
|
podSelector:
|
|
description: |-
|
|
PodSelector determines which pods the profile should apply to.
|
|
An empty slector means the profile will apply to all pods in the namespace.
|
|
properties:
|
|
matchExpressions:
|
|
description: matchExpressions is a list of label selector requirements.
|
|
The requirements are ANDed.
|
|
items:
|
|
description: |-
|
|
A label selector requirement is a selector that contains values, a key, and an operator that
|
|
relates the key and values.
|
|
properties:
|
|
key:
|
|
description: key is the label key that the selector applies
|
|
to.
|
|
type: string
|
|
operator:
|
|
description: |-
|
|
operator represents a key's relationship to a set of values.
|
|
Valid operators are In, NotIn, Exists and DoesNotExist.
|
|
type: string
|
|
values:
|
|
description: |-
|
|
values is an array of string values. If the operator is In or NotIn,
|
|
the values array must be non-empty. If the operator is Exists or DoesNotExist,
|
|
the values array must be empty. This array is replaced during a strategic
|
|
merge patch.
|
|
items:
|
|
type: string
|
|
type: array
|
|
x-kubernetes-list-type: atomic
|
|
required:
|
|
- key
|
|
- operator
|
|
type: object
|
|
type: array
|
|
x-kubernetes-list-type: atomic
|
|
matchLabels:
|
|
additionalProperties:
|
|
type: string
|
|
description: |-
|
|
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
|
|
map is equivalent to an element of matchExpressions, whose key field is "key", the
|
|
operator is "In", and the values array contains only "value". The requirements are ANDed.
|
|
type: object
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
setupKeyRef:
|
|
description: SetupKeyRef is the reference to the setup key used in
|
|
the client.
|
|
properties:
|
|
name:
|
|
default: ""
|
|
description: |-
|
|
Name of the referent.
|
|
This field is effectively required, but due to backwards compatibility is
|
|
allowed to be empty. Instances of this type with an empty value here are
|
|
almost certainly wrong.
|
|
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
|
|
type: string
|
|
type: object
|
|
x-kubernetes-map-type: atomic
|
|
required:
|
|
- setupKeyRef
|
|
type: object
|
|
status:
|
|
default: {}
|
|
description: SidecarProfileStatus defines the observed state of SidecarProfile.
|
|
properties:
|
|
conditions:
|
|
description: Conditions holds the conditions for the SidecarProfile.
|
|
items:
|
|
description: Condition contains details for one aspect of the current
|
|
state of this API Resource.
|
|
properties:
|
|
lastTransitionTime:
|
|
description: |-
|
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
|
format: date-time
|
|
type: string
|
|
message:
|
|
description: |-
|
|
message is a human readable message indicating details about the transition.
|
|
This may be an empty string.
|
|
maxLength: 32768
|
|
type: string
|
|
observedGeneration:
|
|
description: |-
|
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
|
with respect to the current state of the instance.
|
|
format: int64
|
|
minimum: 0
|
|
type: integer
|
|
reason:
|
|
description: |-
|
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
|
Producers of specific condition types may define expected values and meanings for this field,
|
|
and whether the values are considered a guaranteed API.
|
|
The value should be a CamelCase string.
|
|
This field may not be empty.
|
|
maxLength: 1024
|
|
minLength: 1
|
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
|
type: string
|
|
status:
|
|
description: status of the condition, one of True, False, Unknown.
|
|
enum:
|
|
- "True"
|
|
- "False"
|
|
- Unknown
|
|
type: string
|
|
type:
|
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
|
maxLength: 316
|
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
|
type: string
|
|
required:
|
|
- lastTransitionTime
|
|
- message
|
|
- reason
|
|
- status
|
|
- type
|
|
type: object
|
|
type: array
|
|
x-kubernetes-list-map-keys:
|
|
- type
|
|
x-kubernetes-list-type: map
|
|
type: object
|
|
required:
|
|
- spec
|
|
type: object
|
|
served: true
|
|
storage: true
|
|
subresources:
|
|
status: {}
|